Federated Health-AI Readiness Check
A structured self-assessment for teams planning or running federated learning projects on health data. It walks through the six phases of a peer-reviewed EU roadmap and checks the ethical, legal, technical and administrative groundwork, then points out the gaps and red flags worth attention.
Built from Kommusaar et al. 2026, developed with experts and stakeholders across the Nordic and Baltic countries. Your answers stay in your browser while you work: they are stored only on this device, so you can return and finish later. Nothing is sent anywhere unless you choose to contribute your anonymised results to research at the end. The check also forms part of a research study at the University of Eastern Finland; the explains what taking part involves.
Phase I
Planning
Create a competent team with an agreed goal for the algorithm, a solid research plan and a funding application.
The phase concludes with the funding decision that moves the project from planning to execution.
Our project team is diverse and covers the key fields: data science, healthcare, ethics, law and project management, with distinct sub-teams where needed.
Key stakeholders (patients, healthcare providers, researchers, policymakers, industry partners) are identified, with a structured engagement strategy to inform planning and build support.
All partners share an agreed intended purpose and objectives for the algorithm, with clear roles, decision-making authority and conflict resolution arrangements.
Draft contracts define the terms of collaboration: confidentiality, data sharing, intellectual property, patents, publication rights and each partner's key deliverables.
We have assessed whether the algorithm counts as an AI system under the AI Act and, where relevant, a medical device under the Medical Device Regulation, with a preliminary regulatory strategy if commercialisation is in scope.
GDPR compliance, data access rights, security measures and mechanisms to maintain data integrity are outlined in the plan.
A comprehensive project plan sets out goals, milestones, deliverables, deadlines, resource allocation, dependencies and systems for monitoring progress and risk.
A sustainability plan outlines long-term goals beyond the funding period, and a realistic funding path has been identified or secured.
Phase II
Execution refinement
Create a clear, actionable execution plan for developing the federated learning platform and algorithm.
The phase concludes when ethics committee and administrative data access approvals are secured.
Governance structures are implemented: defined roles, responsibilities and decision-making frameworks, held together by a strong central coordinating team.
Partner institutions' data policies have been reviewed, data-sharing agreements formalised, and the rules on secondary use of health data understood for each node's jurisdiction.
Ethical guidelines are established covering protection of human rights, fairness and explicability, with mitigation strategies for fundamental-rights risks and channels for external feedback.
A comprehensive preliminary risk assessment covers ethical, legal, technical and operational challenges, feeding a quality management system with defined measures and performance indicators.
An initial Data Protection Impact Assessment has been conducted for the platform and algorithm.
Ethics committee and data access applications are drafted and coordinated across nodes, rather than submitted in isolation.
The types and sources of data required are specified, with a data acquisition plan and a data governance policy set for the federated organisation.
The necessary technical infrastructure is identified (federated learning framework, software, communication protocols, hardware) and a common data model is designed to harmonise the data sources.
Phase III
Data
Collect, process and standardise raw data from multiple sources while maintaining accuracy, privacy and interoperability.
The phase concludes with a harmonised, privacy-preserving dataset ready for federated model training.
Clear data collection protocols cover the necessary data types, sources and formats, with extraction and accreditation procedures that verify dataset integrity before modelling.
Data quality measures actively identify anomalies, inconsistencies and errors, minimising potential biases and improving the reliability of outcomes.
All datasets are preprocessed and standardised against the agreed common data model, so results are consistent and comparable across nodes.
GDPR-compliant, harmonised anonymisation and encryption techniques are implemented at every node.
Legal questions around cross-border data transfer, and the associated data-sharing agreements, are addressed where applicable.
Privacy-enhancing technologies and risk assessment methods are harmonised at the federated level to prevent re-identification of patient data.
Protocols governing data access and usage are defined, with a risk assessment framework that continuously monitors threats to security and compliance.
The Data Protection Impact Assessment is revised as the data landscape evolves.
Phase IV
Federated learning platform
Develop and test the federated learning platform.
The phase concludes with the decision on whether to proceed to full-scale deployment.
The platform choice is deliberate: an off-the-shelf framework (such as Flower or FedML) or a bespoke build, with technical requirements frozen, including privacy strategy, architecture, central-server location and node roles.
The deployment mode is chosen (simulation, proof-of-concept or production) and the operational environment standardised (operating systems, software stacks, firewall rules, container runtime), with step-by-step node setup instructions.
Supported workflows and architecture are documented (topologies, horizontal and vertical partition modes) and secure federated network protocols established (VPN, or gRPC/HTTPS with TLS certificates).
Privacy technology is integrated into the core: differential privacy parameters, secure aggregation and encrypted model-update channels, selectable per job.
A role-based access model controls who may submit, cancel or inspect jobs, and node registration includes verification of data processing agreements, GDPR validation, security assessment and incident response coordination.
Human oversight mechanisms are in place, biases in data are identified and mitigated, and there are processes for ethical concerns, conflicts and potential attacks or misuse.
The patentability of innovations in the technical solution has been assessed.
The platform is tested first with non-sensitive data, refined with feedback from clinicians, data stewards and DevOps teams, and monitored until key metrics meet acceptance thresholds.
Phase V
Federated learning experiment
Develop and evaluate the algorithm for the federated learning task.
The phase concludes with a transition decision based on the chosen outcome metrics.
Research tasks and objectives are refined and aligned with actual data availability, with a sketch of participating sites and how their data will be partitioned.
Data scientists and clinicians jointly verify that each site's dataset meets agreed quality thresholds, with consistent labelling and a finalised client-level data distribution plan.
The learning algorithm and training workflow are selected (FedAvg, FedOpt, FedProx or a bespoke method), with the optimiser, learning-rate schedule, validation protocol and aggregation rule fixed.
Pilot dry-runs on a small, representative subset validate the preprocessing pipelines, privacy-preserving measures and the logging and monitoring stack before full-scale processing.
Model performance, system latency, bandwidth and client availability are monitored each round, with alerts for failed or slow clients and adaptive tuning until targets are met.
Every data provider reviews and accepts the task specification before implementation, and approvals are logged both locally and centrally.
Transparency and accountability are promoted in data sharing and research findings, and clinical insight is embedded so outputs stay relevant and valid in the real world.
A robust quality system validates the function and impact of the experiment against the chosen outcome metrics.
Phase VI
Dissemination
Communicate the results and raise awareness.
The phase concludes with the decision to close the project, amend it for further development, or initiate commercialisation.
Results, lessons learned and project documentation are systematically recorded and meet regulatory, ethical and funder requirements.
A data retention policy is implemented.
Legal arrangements for intellectual property transfer or licensing are agreed, where commercialisation is pursued.
Arrangements are in place for transferring the algorithm into a regulated manufacturing process (AI Act, Medical Device Regulation), where this is pursued.
Communication is tailored to each audience (scientific reporting, stakeholder engagement, public outreach) and prepared for sensitive or controversial findings.
A transition decision is defined: close the project, amend it for further development, or initiate commercialisation.
Readiness
Phases
Domains
Red flags raised
Warnings from the roadmap that match your "not yet" answers. Each one can delay or derail a project if left open.
Priorities to address
Items you marked "not yet", starting with those the roadmap treats as red-flag risks.
Contribute to research
Add your results to the evidence
We are studying how ready health data projects are for federated learning, and what holds them back. If you choose to contribute, the background details below and your answers to the 46 checks are submitted anonymously, analysed by Laura-Maria Peltonen's research team and reported only in aggregate, for example in a scientific journal article. Contributing is voluntary and does not affect your use of the tool.
Thank you. Your anonymised results have been received and will only ever be reported in aggregate.
You chose to use the tool without taking part in the study.
About this tool
The check condenses the phase-by-phase considerations and critical red flags of a roadmap developed through expert surveys, a stakeholder workshop and expert panel validation within a Baltic-Nordic collaboration, 2023 to 2025. Scores offer structured self-reflection for project teams. They are not a certification, an audit or legal advice, and readiness will always depend on your data, institutions and jurisdictions. If you choose to contribute your results, they feed an ongoing study of federated learning readiness in health and are reported only in aggregate.
Source: Kommusaar J, Elunurm S, Chomutare T, Kangasniemi M, Salanterä S, Peltonen LM. A roadmap for federated learning projects using health data to guide sustainable artificial intelligence development in the European Union. International Journal of Medical Informatics 2026;208:106242. doi:10.1016/j.ijmedinf.2025.106242. Open access.
Want to embed this check on your own site, or adapt it for your organisation? Get in touch.
Research study
This tool is part of a study at the University of Eastern Finland
We study how ready health organisations are to run federated learning projects on health data, and what stands in their way. The study is led by Associate Professor Laura-Maria Peltonen at the University of Eastern Finland (UEF).
You are free to use the tool without taking part in the study. Taking part means sending us your answers anonymously at the end, together with a few background questions. Nothing is sent before you choose to send it.
Participant information
What is the study about?
We study how ready health organisations are to run federated learning projects on health data, and what stands in their way. The findings will be published in scientific journals and used to improve guidance for such projects. Results are reported only in summarised form.
Who conducts the study?
The study is led by Associate Professor Laura-Maria Peltonen at the University of Eastern Finland (UEF). You can contact the research team at laura-maria.peltonen@uef.fi.
What does taking part involve?
You complete the readiness check on this page, which takes about 10 to 15 minutes. At the end, you answer five short background questions, for example about your type of organisation and country. You then send your answers by clicking the contribute button. There is no other contact, and taking part happens entirely on this page.
What information is collected?
We receive your answers to the 46 checks, the scores calculated from them and your background answers. If you describe an obstacle in the free-text box, we receive that too. We do not ask for your name or contact details, and we cannot identify you from what you send. Please do not write names or other identifying details in the free-text box.
Is taking part voluntary?
Yes. You can use the tool without taking part, and nothing is sent unless you click the contribute button. Not taking part has no consequences for you.
Can I withdraw?
You can stop at any point before sending; in that case nothing reaches us. Because the answers are anonymous, we cannot find and delete your answers after you have sent them.
How are the data handled?
The research team stores the submitted answers securely and uses them only for research. Findings are published in summarised form, so that no single person, organisation or project can be recognised.
You can change your choice at any time from the participant information link on this page. Taking part only happens if you send your answers at the end.