Skip to content
← All tools
Live tool

Federated Health-AI Readiness Check

A structured self-assessment for teams planning or running federated learning projects on health data. It walks through the six phases of a peer-reviewed EU roadmap and checks the ethical, legal, technical and administrative groundwork, then points out the gaps and red flags worth attention.

Built from Kommusaar et al. 2026, developed with experts and stakeholders across the Nordic and Baltic countries. Your answers stay in your browser while you work: they are stored only on this device, so you can return and finish later. Nothing is sent anywhere unless you choose to contribute your anonymised results to research at the end. The check also forms part of a research study at the University of Eastern Finland; the explains what taking part involves.

46 checks 6 phases 10–15 minutes Free · no sign-up Runs in your browser Part of a UEF study

Phase I

Planning

Create a competent team with an agreed goal for the algorithm, a solid research plan and a funding application.

The phase concludes with the funding decision that moves the project from planning to execution.

01 Administrative

Our project team is diverse and covers the key fields: data science, healthcare, ethics, law and project management, with distinct sub-teams where needed.

02 Administrative

Key stakeholders (patients, healthcare providers, researchers, policymakers, industry partners) are identified, with a structured engagement strategy to inform planning and build support.

03 Administrative

All partners share an agreed intended purpose and objectives for the algorithm, with clear roles, decision-making authority and conflict resolution arrangements.

04 Legal

Draft contracts define the terms of collaboration: confidentiality, data sharing, intellectual property, patents, publication rights and each partner's key deliverables.

05 Legal

We have assessed whether the algorithm counts as an AI system under the AI Act and, where relevant, a medical device under the Medical Device Regulation, with a preliminary regulatory strategy if commercialisation is in scope.

06 Legal

GDPR compliance, data access rights, security measures and mechanisms to maintain data integrity are outlined in the plan.

07 Administrative

A comprehensive project plan sets out goals, milestones, deliverables, deadlines, resource allocation, dependencies and systems for monitoring progress and risk.

08 Administrative

A sustainability plan outlines long-term goals beyond the funding period, and a realistic funding path has been identified or secured.

Phase II

Execution refinement

Create a clear, actionable execution plan for developing the federated learning platform and algorithm.

The phase concludes when ethics committee and administrative data access approvals are secured.

09 Administrative

Governance structures are implemented: defined roles, responsibilities and decision-making frameworks, held together by a strong central coordinating team.

10 Legal

Partner institutions' data policies have been reviewed, data-sharing agreements formalised, and the rules on secondary use of health data understood for each node's jurisdiction.

11 Ethical

Ethical guidelines are established covering protection of human rights, fairness and explicability, with mitigation strategies for fundamental-rights risks and channels for external feedback.

12 Administrative

A comprehensive preliminary risk assessment covers ethical, legal, technical and operational challenges, feeding a quality management system with defined measures and performance indicators.

13 Legal

An initial Data Protection Impact Assessment has been conducted for the platform and algorithm.

14 Ethical

Ethics committee and data access applications are drafted and coordinated across nodes, rather than submitted in isolation.

15 Technical

The types and sources of data required are specified, with a data acquisition plan and a data governance policy set for the federated organisation.

16 Technical

The necessary technical infrastructure is identified (federated learning framework, software, communication protocols, hardware) and a common data model is designed to harmonise the data sources.

Phase III

Data

Collect, process and standardise raw data from multiple sources while maintaining accuracy, privacy and interoperability.

The phase concludes with a harmonised, privacy-preserving dataset ready for federated model training.

17 Technical

Clear data collection protocols cover the necessary data types, sources and formats, with extraction and accreditation procedures that verify dataset integrity before modelling.

18 Technical

Data quality measures actively identify anomalies, inconsistencies and errors, minimising potential biases and improving the reliability of outcomes.

19 Technical

All datasets are preprocessed and standardised against the agreed common data model, so results are consistent and comparable across nodes.

20 Legal

GDPR-compliant, harmonised anonymisation and encryption techniques are implemented at every node.

21 Legal

Legal questions around cross-border data transfer, and the associated data-sharing agreements, are addressed where applicable.

22 Ethical

Privacy-enhancing technologies and risk assessment methods are harmonised at the federated level to prevent re-identification of patient data.

23 Administrative

Protocols governing data access and usage are defined, with a risk assessment framework that continuously monitors threats to security and compliance.

24 Legal

The Data Protection Impact Assessment is revised as the data landscape evolves.

Phase IV

Federated learning platform

Develop and test the federated learning platform.

The phase concludes with the decision on whether to proceed to full-scale deployment.

25 Technical

The platform choice is deliberate: an off-the-shelf framework (such as Flower or FedML) or a bespoke build, with technical requirements frozen, including privacy strategy, architecture, central-server location and node roles.

26 Technical

The deployment mode is chosen (simulation, proof-of-concept or production) and the operational environment standardised (operating systems, software stacks, firewall rules, container runtime), with step-by-step node setup instructions.

27 Technical

Supported workflows and architecture are documented (topologies, horizontal and vertical partition modes) and secure federated network protocols established (VPN, or gRPC/HTTPS with TLS certificates).

28 Technical

Privacy technology is integrated into the core: differential privacy parameters, secure aggregation and encrypted model-update channels, selectable per job.

29 Administrative

A role-based access model controls who may submit, cancel or inspect jobs, and node registration includes verification of data processing agreements, GDPR validation, security assessment and incident response coordination.

30 Ethical

Human oversight mechanisms are in place, biases in data are identified and mitigated, and there are processes for ethical concerns, conflicts and potential attacks or misuse.

31 Legal

The patentability of innovations in the technical solution has been assessed.

32 Technical

The platform is tested first with non-sensitive data, refined with feedback from clinicians, data stewards and DevOps teams, and monitored until key metrics meet acceptance thresholds.

Phase V

Federated learning experiment

Develop and evaluate the algorithm for the federated learning task.

The phase concludes with a transition decision based on the chosen outcome metrics.

33 Administrative

Research tasks and objectives are refined and aligned with actual data availability, with a sketch of participating sites and how their data will be partitioned.

34 Technical

Data scientists and clinicians jointly verify that each site's dataset meets agreed quality thresholds, with consistent labelling and a finalised client-level data distribution plan.

35 Technical

The learning algorithm and training workflow are selected (FedAvg, FedOpt, FedProx or a bespoke method), with the optimiser, learning-rate schedule, validation protocol and aggregation rule fixed.

36 Technical

Pilot dry-runs on a small, representative subset validate the preprocessing pipelines, privacy-preserving measures and the logging and monitoring stack before full-scale processing.

37 Technical

Model performance, system latency, bandwidth and client availability are monitored each round, with alerts for failed or slow clients and adaptive tuning until targets are met.

38 Administrative

Every data provider reviews and accepts the task specification before implementation, and approvals are logged both locally and centrally.

39 Ethical

Transparency and accountability are promoted in data sharing and research findings, and clinical insight is embedded so outputs stay relevant and valid in the real world.

40 Administrative

A robust quality system validates the function and impact of the experiment against the chosen outcome metrics.

Phase VI

Dissemination

Communicate the results and raise awareness.

The phase concludes with the decision to close the project, amend it for further development, or initiate commercialisation.

41 Administrative

Results, lessons learned and project documentation are systematically recorded and meet regulatory, ethical and funder requirements.

42 Legal

A data retention policy is implemented.

43 Legal

Legal arrangements for intellectual property transfer or licensing are agreed, where commercialisation is pursued.

44 Legal

Arrangements are in place for transferring the algorithm into a regulated manufacturing process (AI Act, Medical Device Regulation), where this is pursued.

45 Ethical

Communication is tailored to each audience (scientific reporting, stakeholder engagement, public outreach) and prepared for sensitive or controversial findings.

46 Administrative

A transition decision is defined: close the project, amend it for further development, or initiate commercialisation.

Readiness

/ 100
Awaiting answers
Answered 0 / 46

Phases

I
II
III
IV
V
VI

Domains

Administrative
Technical
Ethical
Legal

Contribute to research

Add your results to the evidence

We are studying how ready health data projects are for federated learning, and what holds them back. If you choose to contribute, the background details below and your answers to the 46 checks are submitted anonymously, analysed by Laura-Maria Peltonen's research team and reported only in aggregate, for example in a scientific journal article. Contributing is voluntary and does not affect your use of the tool.

About this tool

The check condenses the phase-by-phase considerations and critical red flags of a roadmap developed through expert surveys, a stakeholder workshop and expert panel validation within a Baltic-Nordic collaboration, 2023 to 2025. Scores offer structured self-reflection for project teams. They are not a certification, an audit or legal advice, and readiness will always depend on your data, institutions and jurisdictions. If you choose to contribute your results, they feed an ongoing study of federated learning readiness in health and are reported only in aggregate.

Source: Kommusaar J, Elunurm S, Chomutare T, Kangasniemi M, Salanterä S, Peltonen LM. A roadmap for federated learning projects using health data to guide sustainable artificial intelligence development in the European Union. International Journal of Medical Informatics 2026;208:106242. doi:10.1016/j.ijmedinf.2025.106242. Open access.

Want to embed this check on your own site, or adapt it for your organisation? Get in touch.