HBI Deals+Insights / Digital and AI

Are we too precious about health data?

We are currently putting together a Special Report on big regulatory changes for healthcare technology that are about to come into effect in Europe.

There are three big pieces of EU technology regulation about to come into effect which are particularly noteworthy for healthcare providers: the EU AI Act, the European Health Data Space and the Cyber Resilience Act (coming into force on Tuesday December 10th).

The European Health Data Space is specifically designed to facilitate data sharing between healthcare providers and researchers and across the borders between EU member states.

The Cyber Resilience Act is intended to do just what the name suggests, i.e. make healthcare providers and medical devices more resilient to cyberattacks, or illegal data breaches.

The EU AI Act is the world’s first attempt at a comprehensive regulatory framework for AI.

The common theme linking all three of these is data.

All three regulatory changes are taking place in the shadow of GDPR (The General Data Protection Regulation), which came into force in 2018.

According to GDPR, all personal data should be processed lawfully, fairly, and transparently. This means individuals should always be informed about how their personal data is being collected and used, and only the minimum amount of data that is required to provide a service should be collected.

This focus on prioritising the security of personal data and minimising its use creates a tension for healthcare, according to a digital health expert we spoke to:

“A big part of regulation is the fostering of trust. We should be talking more with the public writ large about what they expect to see in order for them to trust their health data is being used effectively, efficiently and appropriately.

“I recently heard a UK-based person say: ‘don’t tell me how you’re protecting my data; tell me how you’re using it to improve health services and overall health in the community and assure me that it is being protected’.”

The expert argued that the design of these frameworks would be fundamentally different if there was a recognition from the outset that there are certain scenarios where health data must be shared (in particular in matters of public health), as opposed to being designed entirely around consent and protection.

“Data of course needs to be protected, but if it is being protected at the expense of it being used for the benefit of people’s health, whether that’s in primary use within healthcare provision or in health research, that is still breaking trust.”

The European Health Data Space may provide a bit of a countervailing force to the other pieces of regulation, as it is specifically designed to facilitate data sharing. Most notably, patients will have to opt-out rather than opt-in for their data to be used for both primary (healthcare provision) and secondary (research) purposes.

We would welcome your thoughts on this story. Email your views to Martin De Benito Gellner or call 0207 183 3779.