1. Digital Health
1.1 What is the general definition of “digital health” in your jurisdiction?
Lithuanian law does not provide a general definition of “digital health”. However, it does provide a definition of an “e-health system”, which is a set of measures designed to promote healthcare through the use of information and communication technologies.[i]
In addition to this, the Minister of Health has set the objectives for the development of the digital health system. These objectives aim to increase the effectiveness and efficiency of the healthcare system by integrating health information resources into an ecosystem based on uniform principles, modernising electronic health elements, introducing new digital technologies that enable healthcare providers, patients and decision-makers to strive for better accessibility, quality and innovation of healthcare services.[ii]
Based on this objective, it can be concluded that digital health in Lithuania is a combination of information resources integrated into an ecosystem based on uniform principles, electronic health elements and new digital technologies, enabling better healthcare accessibility.
1.2 What are the key emerging digital health subsectors in your jurisdiction?
Information system (ESPBI IS) – this information system is designed for the centralised collection, storage, and administration of information related to healthcare services provided in Lithuania. This system collects both medical and administrative information related to the providers and recipients of these services. This information system also has, inter alia, the following subsystems: (i) e-prescription subsystem designed for the issuance, storage, and implementation of electronic prescriptions for medicines and medical aids in pharmacies; (ii) the Remote Sales of Prescription Medicines and Medical Devices Subsystem (NPRVP IS), designed for initiating and executing remote sales of prescription medicines and/or medical devices; and (iii) the e-health mobile app that allows users to monitor their health data, view e-prescriptions and medical history, register with doctors, and view referrals and other documents provided by doctors.
The Advance Patient Registration System (IPR IS) is an information system that allows patients to find all their appointments with doctors in one place, reserve appointment times, receive notifications and reminders about scheduled visits to the doctor, cancel visits to the doctor, and monitor the history of all their planned and completed visits online.
Artificial intelligence (AI) – the Ministry of Health highlights that AI has broad potential in personal healthcare, including disease diagnosis, patient data management, support for treatment planning, assessment of patient needs, and clinical consultations.
Telemedicine – key priorities include developing a centralised platform, establishing security and confidentiality standards, ensuring integration with the IPR IS, and enabling clinicians to access relevant information from patients’ electronic health records.[iii]
1.3 What is the digital health market size for your jurisdiction?
There are currently no official statistics available that would provide a clear overview on this matter. However, Lithuania’s per-capita investment in health information and communications technology in 2023 was EUR 1.5 million per 100,000 residents.[iv]
1.4 What are the five largest (by revenue) digital health companies in your jurisdiction?
It is not possible to make a blanket statement in this regard. However, we note that the notable players in the Lithuanian market are Kilo grupė, Medical Score, Mano Daktaras, Skaitmeninės Lankos and Nortal.
1.5 What are the five fastest growing (by revenue) digital health companies in your jurisdiction?
See our response to question 1.4.
2. Regulatory
2.1 What are the principal regulatory authorities charged with enforcing regulatory schemes related to digital health in your jurisdiction? What is each authority’s scope of enforcement?
The Ministry of Health is the main institution responsible for developing and implementing legislation related to digital health in Lithuania. It coordinates and supervises the implementation of the ESPBI IS information system, adopts plans for the development of digital health in Lithuania, etc.
The State Accreditation Service for Health Care Activities under the Ministry of Health (State Accreditation Service) is an institution that supervises, licenses, and controls healthcare activities in Lithuania, including medical devices.
National Health Insurance Fund under the Ministry of Health is the main institution in Lithuania that administers the Compulsory Health Insurance Fund and ensures that insured persons are reimbursed for healthcare services, medical devices and medicinal products.
The State Data Protection Inspectorate is an independent personal data protection supervisory authority that supervises the application of the General Data Protection Regulation (EU) 2016/679 (GDPR) and other privacy laws.
2.2 For these authorities, what are the core healthcare regulatory schemes related to digital health in your jurisdiction (e.g., medical devices/AI/generative AI/SaaS/SaMD/combination product regulatory approval, data privacy, data compliance, anti-kickback, national security, etc.)?
Digital health products often qualify as medical devices or in vitro diagnostics and, therefore, fall within the scope of the Regulation (EU) 2017/745 on medical devices (MDR) or Regulation (EU) 2017/746 on in vitro diagnostics (IVDR). As EU regulations, the MDR and IVDR are directly applicable in Lithuania and do not have to be transposed into national law. The regulations are complemented by the Law on the Health System of the Republic of Lithuania and its implementing legal acts.
Also, GDPR and the Law on Legal Protection of Personal Data of the Republic of Lithuania (Law on Legal Protection of Personal Data) are highly relevant to digital health products and services. Digital health companies must ensure that patient data are processed in compliance with these legal frameworks and safeguarded against unauthorised third-party access.
In addition, certain issues related to digital health are regulated by Regulation (EU) 2023/2854 (Data Act), Regulation (EU) 2024/1689 (AI Act), Regulation (EU) 2022/2065 (Digital Services Act) and Regulation (EU) 2022/868 (Data Governance Act).
2.3 What are the (i) key, and (ii) emerging areas of enforcement when it comes to digital health?
Lithuania’s digital health enforcement landscape is mainly shaped by EU regulatory convergence, national digitalisation priorities, and growing cybersecurity obligations.
Key areas cluster around eHealth governance, GDPR/health data protections, medicines information systems, and operational oversight by state authorities.
Emerging areas reflect EU‑level regulatory expansion (NIS2, DORA, eIDAS), modernisation of state information systems, and rising supervision of AI, cloud, and digital infrastructure providers.
The topic of medical devices – particularly those incorporating AI software – remains a key and emerging area, especially with respect to determining whether a product should be classified as a medical device or not.
2.4 What regulations (and corresponding authority(ies)) apply to software as a medical device and its approval for clinical use?
If the software were to be considered a medical device, it would have to comply with the requirements of the MDR or IVDR. State supervision of medical devices is carried out by the State Accreditation Service.
2.5 What regulations (and corresponding authority(ies)) apply to AI/ML-powered digital health devices or software solutions and their approval for clinical use?
Lithuanian lawmakers have not yet adopted legislation specifically regulating products powered by AI or ML technologies. However, AI/ML-powered medical devices are subject to the same regulations as any other medical device. This means they must comply with the MDR or IVDR for safety, while also complying with data protection and cybersecurity laws.
Depending on the nature of the solution, the AI Act might also be applicable for such devices/software.
2.6 How, if at all, are these authorities evolving, or planning to evolve, their static approval scheme to handle the dynamic nature of AI/ML-based digital health solutions?
In its digital health development plan, the Ministry of Health of the Republic of Lithuania expresses its intention to implement innovative solutions using AI in order to have a positive impact on healthcare institutions, healthcare professionals and patients. The Ministry of Health already sees and recognises the benefits of AI/ML in optimising the work of medical professionals.
However, in terms of legal regulation, medical devices developed using AI/ML technology are not viewed in isolation in Lithuania and related issues will be addressed together with other pressing AI/ML issues.
2.7 How, if at all, does clinical validation data play a part in regulatory considerations for AI/ML-based digital health solutions?
When AI/ML systems act as medical devices, the MDR/IVDR demand strict clinical evaluation and solid validation data.
2.8 How, if at all, are digital health products and solutions being differentially regulated by the State/Regional and Federal/Country level regulatory authorities in your jurisdiction?
Such products are predominantly regulated on an EU level with certain national-level laws ensuring the implementation of EU legislation.
2.9 How, if at all, are regulatory enforcement actions being tailored to regulate digital health products and solutions in your jurisdiction?
As of the time of writing, enforcement actions are not being specifically tailored to digital health products and solutions and general regulation principles apply.
3. Digital Health Technologies
3.1 What are the core legal and regulatory issues that apply to the following digital health technologies?
- Telemedicine/Virtual Care
The protection of patients’ personal data while providing telemedicine services (including prevention of data breaches). - Robotics
Robotics are machines capable of partially substituting healthcare professionals and will, in most cases, qualify as medical devices. - Wearables
Wearables, such as smartwatches or smart glasses, often have multiple functions and their primary purpose may not be medical. However, when wearables include health-related features, they may qualify as medical devices and require CE certification. - Virtual Assistants (e.g. Alexa)
Virtual assistants are generally not designed with health-specific functionalities and are therefore not considered medical devices. - Mobile Apps
Mobile apps with health-related features can be classified as medical devices and thus may fall under the regulations of medical devices. - Software as a Medical Device
In case software is considered as a medical device, it is subject to the regulations of medical devices. - Clinical Decision Support Software
In case software is considered as a medical device, it is subject to the regulations of medical devices. - Artificial Intelligence/Machine Learning-Powered Digital Health Solutions
A key challenge of such health solution is the protection of patients’ personal data while providing solution with real-world evidence. - IoT (Internet of Things) and Connected Devices
Connected devices in most cases are considered as medical devices and thus require CE certification. - 3D Printing/Bioprinting
The use of 3D templates for prosthetics and tissues can cause intellectual property (IP) and licensing issues. - Digital Therapeutics
Depending on the solution, such therapeutics can fall under the legal category of medical devices. - Digital Diagnostics
Depending on the solution, such diagnostics can fall under the legal category of medical devices. - Electronic Medical Record Management Solutions
The protection of patients’ personal data while providing healthcare services (including the prevention of data breaches). - Big Data Analytics
The protection of patients’ personal data while using big data analytics (including the prevention of data breaches). - Blockchain-based Healthcare Data Sharing Solutions
The current e-health infrastructure is not based on blockchain technology but instead relies on traditional solutions. - Natural Language Processing
The protection of patients’ personal data while using natural language processing (including the prevention of data breaches).
3.2 What are the key legal and regulatory issues for digital platform providers in the digital health space?
Digital platform providers must ensure compliance with GDPR, i.e. patients’ health and other personal data should be processed in accordance with GDPR principles and requirements.
Compliance with cybersecurity regulations is also crucial to ensure the protection of sensitive health data from hacking, unauthorised access or cyberattacks.
Also, the unclarity remains whether international telemedicine services can be provided in Lithuania; specifically, when foreign companies provide telemedicine services to Lithuanian hospitals (for example, radiology), since only Lithuanian established companies can receive access to the ESPBI IS system, which is mandatory for the health data exchange between the service provider and service recipient.
4. Data Use
4.1 What are the key legal or regulatory issues, and corresponding laws/regulations, to consider in your jurisdiction for use of personal health data, including laws/regulations that are agnostic and not necessarily specific to healthcare technologies?
Under the GDPR, health data is considered a special category and its processing is prohibited unless lawful bases under Articles 6 and 9 exist. Moreover, the entity responsible for the processing is subject to the following requirements:
- inform the individuals how their data is processed;
- maintain records of processing activities;
- ensure rights of data subjects;
- apply enhanced technical and organisational safeguards; and
- when necessary, conduct data protection impact assessments – this will often apply to digital health applications that involve health data and new technologies.
Where health data is anonymised in a manner that irreversibly prevents the identification of individuals, GDPR no longer applies, though organisations must ensure that anonymisation is robust and reidentification risks remain low.
Pseudonymised health data continues to be treated as personal data, meaning that all obligations remain in force, although pseudonymisation is encouraged as a risk-reduction measure.
4.2 How, if at all, is personal health data use being differentially regulated by the State/Regional and Federal/Country level regulatory authorities in your jurisdiction?
Protection of health data is primarily regulated by the GDPR and it is supplemented by the local Law on Legal Protection of Personal Data.
4.3 How do such considerations change depending on the nature of the entities, or nature of the data (e.g., personal health data), involved?
Healthcare providers (like hospitals and clinics) are usually data controllers and must comply with strict GDPR rules for processing special categories of data. Cybersecurity requirements are also crucial.
Public authorities and state health information systems must follow both GDPR and specific Lithuanian legislation on state information systems, cybersecurity, which impose additional obligations on security, and institutional data exchange.
Private digital health and AI solution providers may hold both roles, i.e., if entities operate on behalf of healthcare institutions and follow their instructions, they will be considered data processors, and if health data is needed for the development of the entities’ own products or for the provision of their services, they will act as data controllers. Accordingly, depending on the role, particular GDPR requirements will apply. In all cases, it is critically important to comply with cybersecurity requirements.
As personal health data is a special category under GDPR, its processing is prohibited by default unless lawful bases under Articles 6 and 9 exist.
4.4 How do the regulations define the scope of personal health data use?
Under the GDPR, “processing” means any operation that is performed on personal data, including health data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
4.5 To help ensure comprehensive rights for personal health data use and data collection, what are the key contractual terms to consider in abiding by your jurisdiction’s laws and regulations related to personal health data use and data collection?
It is essential to define the roles of the parties with respect to the processing of personal data:
- Where one party processes personal data on behalf of another, a data processing agreement must be concluded in accordance with Article 28 of the GDPR.
- Where two or more parties jointly determine the purposes and means of processing, they are required to enter into a joint controller arrangement pursuant to Article 26 of the GDPR.
- In scenarios involving independent controllers, the GDPR does not mandate specific contractual provisions; however, contractual limitations on data reuse may be appropriate to mitigate the risk of non-compliance.
If personal health data is being transferred outside the EEA, such transfers can take place only if the conditions laid down in Chapter V of the GDPR are complied with, e.g. standard data protection clauses adopted by the Commission should be signed by parties.
Liability and indemnification are key contractual considerations in all cases and warrant particular attention where health data is processed, given the increased exposure to significant administrative fines under the GDPR.
4.6 How are issues with personal health data inaccuracy, bias and/or discrimination addressed by the regulatory authorities in your jurisdiction?
At present, data accuracy is not a primary enforcement priority for the data protection authority. Moreover, given the restrictions imposed by the GDPR on automated decision-making, the risk of bias or discriminatory outcomes arising from profiling and data use remains comparatively low.
4.7 What laws or initiatives exist regarding standards for using and collecting personal health data in your jurisdiction?
- GDPR.
- Regulation (EU) 2025/327.
- Law on Legal Protection of Personal Data.
- Law on the Reuse of Health Data of the Republic of Lithuania.
- Law on the Rights of Patients and Compensation for the Damage to Their Health (Law on the Rights of Patients).
Read the full publication here.