SlideShare ist ein Scribd-Unternehmen logo
1 von 39
Protection of Patient
Data in EU vs. US
ERIK RANSCHAERT MD, PHD
ETZ TILBURG, NETHERLANDS
erik.ranschaert@gmail.com
@eranrad
Learning Objectives
1. Knowledge of the patient privacy issues involved in using AI
applications
2. Knowledge of principles of the European privacy regulation
3. Knowledge of potential ethical and social issues that can be
encountered by using AI applications
Regulations and framework
A.I. is 1 of the few things we
should regulated proactively
in stead of reactively
If we regulate A.I.
reactively then it’s too
late
Relevance of protecting Health Data
• “FastMRI” partnership between NYU (CAI2R) and FacebookA.I. Research to make MRI
scans 10x faster
• Combination of domain-specific expertise from different fields and industries
• Train artificial neural nets to recognize underlying structures and construct MR-images
with less data
• NYU provides FAIR with 3 million MR-images (knee, brain, liver)
https://www.healthimaging.com/topics/artificial-intelligence/facebook-nyu-collaborate-make-mri-faster-ai
Security measures
• The MR images used for this project have to be scrubbed of any
potential distinguishing features.
• Approved by NYU Langone’s Institutional Review Board,
following policies and procedures for human subjects research
protection
• No Facebook data of any kind will be used in the project.
• Fully HIPAA compliant (Health Insuranc Portability and
AccountabilityAct)
How are patient data protected in the EU vs US?
General Data Protection Regulation
• EU law that came into effect on
May 25, 2018.
• Main purpose: to define and
update the basic rights of data
subjects regarding control of and
access to personal data
EU Regulation
• As opposed to a directive, a regulation
is directly applicable in all EU Member
States.
• National authorities can define
exceptions and derogations from
certain obligations by means of
national law.
What are Personal Data?
• Any information related to an
identified or identifiable natural
person (data subject)
• Also Health Data!
1. Data concerning physical/mental
health
2. Genetic data
3. Biometric data
NEW
The Goals of the GDPR
Protect
• EU citizen’s
personal data
Control
• To data subjects
over their
processed data
Unify
• The duties and
responsabilities
of controllers
and processors
Simplify
• The means of
data collection
and processing
Economical purpose
Any organization that processes EU citizens’ data,
even if the company isn’t located in the EU,
has to ensure GDPR compliance.
Handling of personal data: 3 players
Data subject Data controller Data processor
1. Collection
2. Encryption & storage
3. Forwarding
4. Processing
GDPR in Healthcare
• Facilitates free flow of patient data within EU.
• Personal data can only be collected under strict conditions and for
legitimate purposes.
• Data controller (hospital, HCP) has to respect rights of data subject
• Data processor must protect information it handles, processes and
stores on behalf of data controller
Opportunities for HC created by GDPR
1. Improving the sharing and interoperability of health
data
2. Helps HC organisations to build consumer trust
• Mitigate negative sentiments generated from recent data
breaches (Cambridge Analytica/FB saga)
3. Spur adoption of alternative modes of data
management (e.g. blockchain)
• Single source of trusted information, reducing redundancy and
administrative costs
Sharing
Trust
Costs
• GDPR concerns EVERY piece of information
that can identify a person, not limited to HC
• HIPAA only governs protected health
information (PHI)
Governance
HIPAA vs. GDPR
Position of ESR
• The GDPR is welcomed by the ESR
Meaning for Radiology
Received: 20 March 2017 / Accepted: 21 March 2017 / Published online: 24 April 2017
GDPR
Key
Elements
Clear Consent
Erasure
(right to be
forgotten)
Rectification
Portability
Notification of
data breach
Demonstration
of Compliance
Data
Protection
Officer (DPO)
Derogations
and exceptions
2
3
4
1
5
6
7
1. Clear Consent
• Explicit consent of data subject
prior to data processing
• Explicit consent prior to
communication of imaging data
1
• HIPAA only governs protected health information
(PHI)
• GDPR concerns EVERY piece of information that can
identify a person, not limited to HC
Governance
• HIPAA does not require consent from patient to
release health data for third parties (e.g. for insurance
company)
• GDPR needs explicit consent for any interaction with
PHI other than direct patient care
Consent
HIPAA vs. GDPR
2. Erasure and Rectification
• Destruction of data if storage is
no longer necessary for the initial
purpose
• Withdrawal of consent possible,
“the right to be forgotten”
• The right to obtain rectification of
his/her data
2
3. Portability of health data
• Data subject has the right to
transfer personal data to another
service provider
• Hospitals and other HCPs have to
provide electronic data in an
appropriate format to a patient
upon request – free of charge
https://www.himss.eu/himss-blog/data-portability-and-sharing-personal-health-data-across-national-borders
3
• HIPAA only governs protected health information (PHI)
• GDPR concerns EVERY piece of information that can
identify a person, not limited to HC
Governance
• HIPAA does not require consent from patient to release
health data for third parties (e.g. For insurance company)
• GDPR needs explicit consent for any interaction with PHI
other than direct patient care
Consent
• HIPAA grants right to a copy of PHI, not for free
• GDPR grants right to copy of health data for free, and
even to rectify and erase data
Privacy
HIPAA vs. GDPR
4. Data Breach
• Breach or hacking of Personal Data
• Notification within 72 hrs to
Supervisory Authority
• Communication to data subject
• Larger institutions: DPO needed
4
• HIPAA only governs protected health information (PHI)
• GDPR concerns EVERY piece of information that can identify a
person, not limited to HC
Governance
• HIPAA does not require consent from patient to release health
data for third parties (e.g. For insurance company)
• GDPR needs explicit consent for any interaction with PHI other
than direct patient care
Consent
• HIPAA grants right to copy of PHI, not for free
• GDPR grants right to copy of health data for free, and even to
rectify and erase data
Privacy
• Both require absolute secure measures to ensure confidentiality
• HIPAA breach notification is 60d vs 72h for GDPR (including
communication to data subject)
Security
5. Demonstration of Compliance
• All organisations processing personal data must be able to
prove that they comply with the rules
• Hospitals and HCPs need to define their lawful basis for
processing health data and demonstrate their compliance
with GDPR
• e.g. for access to databases such as EPR and PACS
5
Stringent Penalties
• Failure to comply with the new data protection rules can result in
different types of sanctions from controllers, ranging from
• a warning,
• a reprimand,
• to a temporary or definitive ban on processing data,
• and a fine of up to €20 million or 4% of the business’s total annual worldwide
turnover
• HIPAA only governs protected health information (PHI)
• GDPR concerns EVERY piece of information that can identify a person, not limited
to HC
Governance
• HIPAA does not require consent from patient to release health data for third
parties (e.g. For insurance company)
• GDPR needs explicit consent for any interaction with PHI other than direct patient
care
Consent
• HIPAA grants right to copy of PHI, not for free
• GDPR grants right to copy of health data for free, and even to rectify and erase
data
Privacy
• Both require absolute secure measures to ensure confidentiality
• HIPAA breach notification 60d vs 72h, including data subjectSecurity
• Any organisation violating regulations is liable to be prosecuted
• HIPAA: prosecution is related to “significant harm” caused by violation
• HIPAA penalties go up to 1.5 million USD, GDPR is much higher
Penalties
6. DPO
• Data Protection Officer is mandatory for
those companies and organisations that
systematically monitor data subjects on
large scale of sensitive data
• According to Art. 29Working Party (WP29)
processing of patient data by hospital is “large
scale”
• The DPO is in contact with the national data
protection authorities (Security Authority)
6
Derogations and exceptions
• Often conflicting objectives:
• Ensure privacy rights for personal
data vs.
• Providing adequate access to such
data for research & healthcare
purposes, e.g. for developing or
training A.I.
• Therefore the GDPR provides
several derogations regarding
health data
7
What is Scientific Research?
• Only broad definition in the GDPR
• Not clear how far the research
exemption extends, especially as
regards research activities with a
commercial goal
• For clinical trials: processing of data
should also comply with other relevant
legislation, policies, ethical standards
ESR opinion on Data for Research
• GDPR proposes technical and organisational measures such as
1. Anonymisation
2. Pseudo-anonymisation
3. Encryption
• Remove personally identifiable information
where it is not needed
• e.g. Name of patient, institution, date of exam
on images, DICOM metadata
Anonymisation
• Replace personally identifiable material with
artificial identifiers
• Data can no longer be attributed to individual
without additional information
Pseudonymisation
• Encoding of messages that can only be read
by authorised persons.
• Can only be done with anonymised or
pseudonymised data
Encryption
Image-based information
• Absolute confidentiality cannot be
guaranteed in case of image-
based information
• Matching by digital robotic
algorithms of organs and
pathologies could possibly allow
re-identification
What to do with Research Data?
• Key question: what is the purpose of using the data?
• Procedures to be followed:
• Adhere to ethical standards
• Use the right safeguards such as anonymisation, pseudonymisation,
encryption
• Pseudonymisation is generally recommended
• Exemptions are provided under certain conditions
• These should not result in PD being processed for other
purposes by third parties, e.g. employers, insurance or banking
companies, commercial enterprises
Exemptions for Scientifc research
• The purposes may override 3 basic rights in the following
conditions:
1. The right to information: if the provision of information involves a
“disproportionate effort”
2. The right to the processing: if it’s likely to render impossible or
seriously impact the achievement of the objectives of the processing
3. The right to be forgotten: if the processing is necessary for the
performance of a task carried out for reasons of public interest
GDPR and Ethical question
• Some AI algorithms are “impenetrable”, certainly those
constructed by unsupervised learning, creating a so-called
“black box”.
• If the subject has the legal right to information following the
GDPR, how can decisions concerning a person made by anAI
expert system that is not transparant be fulfilled?
Peter Rinck:Why radiology must take care when it comes to AI
https://www.auntminnieeurope.com/index.aspx?sec=sup&sub=aic&pag=dis&ItemID=616410
Take Home Messages
• Many ethical, legal and issues are involved with the development
and implementation of A.I.
• The GDPR regulates all personal data, including health data
• Use of health data for A.I. development is strictly regulated for all EU
inhabitants
• The GDPR is relevant to the development and usage of A.I. apps.
• Certain derogations are applicable to data for scientific research.
• Several A.I.-related ethical questions still need to be answered.
Erik Ranschaert, MD, PhD
erik.ranschaert@gmail.com
@eranrad
Thank you!

Weitere ähnliche Inhalte

Was ist angesagt?

ISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP AlignmentISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP AlignmentMohammed J. Khan
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitjoshquarrie
 
HIPAA and Privacy for Researchers
HIPAA and Privacy for ResearchersHIPAA and Privacy for Researchers
HIPAA and Privacy for ResearchersJason Karn
 
Information governance
Information governanceInformation governance
Information governanceGerardo Medina
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Happiest Minds Technologies
 
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Michael Adamberry
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Michael Adamberry
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterBrowne Jacobson LLP
 
GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization  GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization Vishnuvarthanan Moorthy
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR PresentationLuke Kyte
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security PresentationRebecca Norman
 
Confidentiality and Data Protection in Health Care
Confidentiality and Data Protection in Health CareConfidentiality and Data Protection in Health Care
Confidentiality and Data Protection in Health CareVaileth Mdete
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analyticsbrunomase
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRNupur Samaddar
 
Data Management Protection Acts
Data Management Protection ActsData Management Protection Acts
Data Management Protection ActsJoseph White MPA CPM
 

Was ist angesagt? (20)

ISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP AlignmentISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP Alignment
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
 
HIPAA and Privacy for Researchers
HIPAA and Privacy for ResearchersHIPAA and Privacy for Researchers
HIPAA and Privacy for Researchers
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Information governance
Information governanceInformation governance
Information governance
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
GDPR and Research Data Management
GDPR and Research Data ManagementGDPR and Research Data Management
GDPR and Research Data Management
 
Data Protection & GDPR Health Check Service Overview
Data Protection & GDPR Health Check Service OverviewData Protection & GDPR Health Check Service Overview
Data Protection & GDPR Health Check Service Overview
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization  GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security Presentation
 
Data privacy and digital strategy
Data privacy and digital strategyData privacy and digital strategy
Data privacy and digital strategy
 
Confidentiality and Data Protection in Health Care
Confidentiality and Data Protection in Health CareConfidentiality and Data Protection in Health Care
Confidentiality and Data Protection in Health Care
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analytics
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPR
 
Data Management Protection Acts
Data Management Protection ActsData Management Protection Acts
Data Management Protection Acts
 

Ă„hnlich wie Patient Data Protection in EU and US Healthcare

Data Privacy and Security in Clinical Trials: Safeguarding Patient Information
Data Privacy and Security in Clinical Trials: Safeguarding Patient InformationData Privacy and Security in Clinical Trials: Safeguarding Patient Information
Data Privacy and Security in Clinical Trials: Safeguarding Patient InformationClinosolIndia
 
EU data protection and security update COCIR annual meeting 2016
EU data protection and security update COCIR annual meeting 2016EU data protection and security update COCIR annual meeting 2016
EU data protection and security update COCIR annual meeting 2016Erik Vollebregt
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .ClinosolIndia
 
Master thesis defence Merve ĹžimĹźek
Master thesis defence Merve ĹžimĹźekMaster thesis defence Merve ĹžimĹźek
Master thesis defence Merve ĹžimĹźekMIPLM
 
Governance And Data Protection In The Health Sector - Billy Hawkes
Governance And Data Protection In The Health Sector - Billy HawkesGovernance And Data Protection In The Health Sector - Billy Hawkes
Governance And Data Protection In The Health Sector - Billy Hawkeshealthcareisi
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
Ethical Considerations for Healthcare Analytics Data Disposal.pdf
Ethical Considerations for Healthcare Analytics Data Disposal.pdfEthical Considerations for Healthcare Analytics Data Disposal.pdf
Ethical Considerations for Healthcare Analytics Data Disposal.pdfAlex860662
 
Medical device data protection and security
Medical device data protection and security Medical device data protection and security
Medical device data protection and security Erik Vollebregt
 
GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)Erik Vollebregt
 
Annual environment and health conference 2018 fionnuala donohue hse epa data ...
Annual environment and health conference 2018 fionnuala donohue hse epa data ...Annual environment and health conference 2018 fionnuala donohue hse epa data ...
Annual environment and health conference 2018 fionnuala donohue hse epa data ...Environmental Protection Agency, Ireland
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
Data protection and data integrity
 Data protection and data integrity Data protection and data integrity
Data protection and data integrityAxon Lawyers
 
eHealth and mhealth presentation
eHealth and mhealth presentationeHealth and mhealth presentation
eHealth and mhealth presentationErik Vollebregt
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
'Connected healthcare - connected to legality?'
'Connected healthcare - connected to legality?''Connected healthcare - connected to legality?'
'Connected healthcare - connected to legality?'Lucy Woods
 
Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018amirhannan
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
Anne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for ResearchersAnne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for Researcherskclcompbio
 

Ă„hnlich wie Patient Data Protection in EU and US Healthcare (20)

Data Privacy and Security in Clinical Trials: Safeguarding Patient Information
Data Privacy and Security in Clinical Trials: Safeguarding Patient InformationData Privacy and Security in Clinical Trials: Safeguarding Patient Information
Data Privacy and Security in Clinical Trials: Safeguarding Patient Information
 
EU data protection and security update COCIR annual meeting 2016
EU data protection and security update COCIR annual meeting 2016EU data protection and security update COCIR annual meeting 2016
EU data protection and security update COCIR annual meeting 2016
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .
 
Master thesis defence Merve ĹžimĹźek
Master thesis defence Merve ĹžimĹźekMaster thesis defence Merve ĹžimĹźek
Master thesis defence Merve ĹžimĹźek
 
Governance And Data Protection In The Health Sector - Billy Hawkes
Governance And Data Protection In The Health Sector - Billy HawkesGovernance And Data Protection In The Health Sector - Billy Hawkes
Governance And Data Protection In The Health Sector - Billy Hawkes
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Ethical Considerations for Healthcare Analytics Data Disposal.pdf
Ethical Considerations for Healthcare Analytics Data Disposal.pdfEthical Considerations for Healthcare Analytics Data Disposal.pdf
Ethical Considerations for Healthcare Analytics Data Disposal.pdf
 
Medical device data protection and security
Medical device data protection and security Medical device data protection and security
Medical device data protection and security
 
GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)GDPR and eHealth for the pharma industry (VFenR presentation)
GDPR and eHealth for the pharma industry (VFenR presentation)
 
Annual environment and health conference 2018 fionnuala donohue hse epa data ...
Annual environment and health conference 2018 fionnuala donohue hse epa data ...Annual environment and health conference 2018 fionnuala donohue hse epa data ...
Annual environment and health conference 2018 fionnuala donohue hse epa data ...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Data protection and data integrity
 Data protection and data integrity Data protection and data integrity
Data protection and data integrity
 
eHealth and mhealth presentation
eHealth and mhealth presentationeHealth and mhealth presentation
eHealth and mhealth presentation
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
'Connected healthcare - connected to legality?'
'Connected healthcare - connected to legality?''Connected healthcare - connected to legality?'
'Connected healthcare - connected to legality?'
 
Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Marcus Comiter, "Data Policy for Internet of Things Healthcare Devices: Align...
Marcus Comiter, "Data Policy for Internet of Things Healthcare Devices: Align...Marcus Comiter, "Data Policy for Internet of Things Healthcare Devices: Align...
Marcus Comiter, "Data Policy for Internet of Things Healthcare Devices: Align...
 
Anne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for ResearchersAnne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for Researchers
 

Mehr von Erik R. Ranschaert, MD, PhD

Social Networks and Collaborative Platforms for Data Sharing in Radiology
Social Networks and Collaborative Platforms for Data Sharing in RadiologySocial Networks and Collaborative Platforms for Data Sharing in Radiology
Social Networks and Collaborative Platforms for Data Sharing in RadiologyErik R. Ranschaert, MD, PhD
 
Security and ethical issues of mobile device technology
Security and ethical issues of mobile device technologySecurity and ethical issues of mobile device technology
Security and ethical issues of mobile device technologyErik R. Ranschaert, MD, PhD
 
Automated image analysis: rescue for diffusion-MRI of threat to radiologists?
Automated image analysis: rescue for diffusion-MRI of threat to radiologists?Automated image analysis: rescue for diffusion-MRI of threat to radiologists?
Automated image analysis: rescue for diffusion-MRI of threat to radiologists?Erik R. Ranschaert, MD, PhD
 
Information Technology and Radiology: challenges and future perspectives
Information Technology and Radiology: challenges and future perspectivesInformation Technology and Radiology: challenges and future perspectives
Information Technology and Radiology: challenges and future perspectivesErik R. Ranschaert, MD, PhD
 
The impact of Information Technology on Radiology Services
The impact of Information Technology on Radiology ServicesThe impact of Information Technology on Radiology Services
The impact of Information Technology on Radiology ServicesErik R. Ranschaert, MD, PhD
 
Comparison of ESR & ACR Teleradiology White Papers
Comparison of ESR & ACR Teleradiology White PapersComparison of ESR & ACR Teleradiology White Papers
Comparison of ESR & ACR Teleradiology White PapersErik R. Ranschaert, MD, PhD
 
iPad for (tele)radiology, a critical appraisal
iPad for (tele)radiology, a critical appraisaliPad for (tele)radiology, a critical appraisal
iPad for (tele)radiology, a critical appraisalErik R. Ranschaert, MD, PhD
 
State-of-the-art Cardiac CT of the coronary arteries
State-of-the-art Cardiac CT of the coronary arteriesState-of-the-art Cardiac CT of the coronary arteries
State-of-the-art Cardiac CT of the coronary arteriesErik R. Ranschaert, MD, PhD
 

Mehr von Erik R. Ranschaert, MD, PhD (20)

Les réseaux sociaux en radiologie
Les réseaux sociaux en radiologieLes réseaux sociaux en radiologie
Les réseaux sociaux en radiologie
 
A.I. in Radiology: Hype or Hope?
A.I. in Radiology: Hype or Hope?A.I. in Radiology: Hype or Hope?
A.I. in Radiology: Hype or Hope?
 
Social Networks and Collaborative Platforms for Data Sharing in Radiology
Social Networks and Collaborative Platforms for Data Sharing in RadiologySocial Networks and Collaborative Platforms for Data Sharing in Radiology
Social Networks and Collaborative Platforms for Data Sharing in Radiology
 
Wat betekent A.I. voor de radiologie?
Wat betekent A.I. voor de radiologie?Wat betekent A.I. voor de radiologie?
Wat betekent A.I. voor de radiologie?
 
What's in WhatsApp for Radiologists?
What's in WhatsApp for Radiologists?What's in WhatsApp for Radiologists?
What's in WhatsApp for Radiologists?
 
IT en Radiologie
IT en RadiologieIT en Radiologie
IT en Radiologie
 
Security and ethical issues of mobile device technology
Security and ethical issues of mobile device technologySecurity and ethical issues of mobile device technology
Security and ethical issues of mobile device technology
 
Automated image analysis: rescue for diffusion-MRI of threat to radiologists?
Automated image analysis: rescue for diffusion-MRI of threat to radiologists?Automated image analysis: rescue for diffusion-MRI of threat to radiologists?
Automated image analysis: rescue for diffusion-MRI of threat to radiologists?
 
Information Technology and Radiology: challenges and future perspectives
Information Technology and Radiology: challenges and future perspectivesInformation Technology and Radiology: challenges and future perspectives
Information Technology and Radiology: challenges and future perspectives
 
IT changes communication for radiologists
IT changes communication for radiologistsIT changes communication for radiologists
IT changes communication for radiologists
 
The impact of Information Technology on Radiology Services
The impact of Information Technology on Radiology ServicesThe impact of Information Technology on Radiology Services
The impact of Information Technology on Radiology Services
 
Use of Social Media in Radiology
Use of Social Media in RadiologyUse of Social Media in Radiology
Use of Social Media in Radiology
 
Mobile (tele)radiology
Mobile (tele)radiologyMobile (tele)radiology
Mobile (tele)radiology
 
Comparison of ESR & ACR Teleradiology White Papers
Comparison of ESR & ACR Teleradiology White PapersComparison of ESR & ACR Teleradiology White Papers
Comparison of ESR & ACR Teleradiology White Papers
 
iPad for (tele)radiology, a critical appraisal
iPad for (tele)radiology, a critical appraisaliPad for (tele)radiology, a critical appraisal
iPad for (tele)radiology, a critical appraisal
 
Teleradiology White Paper
Teleradiology White PaperTeleradiology White Paper
Teleradiology White Paper
 
State-of-the-art Cardiac CT of the coronary arteries
State-of-the-art Cardiac CT of the coronary arteriesState-of-the-art Cardiac CT of the coronary arteries
State-of-the-art Cardiac CT of the coronary arteries
 
Radiologie anno 2012
Radiologie anno 2012Radiologie anno 2012
Radiologie anno 2012
 
Radiologie in 2012: hollen of stilstaan?
Radiologie in 2012: hollen of stilstaan?Radiologie in 2012: hollen of stilstaan?
Radiologie in 2012: hollen of stilstaan?
 
Teleradiology, European perspective
Teleradiology, European perspectiveTeleradiology, European perspective
Teleradiology, European perspective
 

KĂĽrzlich hochgeladen

Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...narwatsonia7
 
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original PhotosCall Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original Photosnarwatsonia7
 
Glomerular Filtration and determinants of glomerular filtration .pptx
Glomerular Filtration and  determinants of glomerular filtration .pptxGlomerular Filtration and  determinants of glomerular filtration .pptx
Glomerular Filtration and determinants of glomerular filtration .pptxDr.Nusrat Tariq
 
Air-Hostess Call Girls Madambakkam - Phone No 7001305949 For Ultimate Sexual ...
Air-Hostess Call Girls Madambakkam - Phone No 7001305949 For Ultimate Sexual ...Air-Hostess Call Girls Madambakkam - Phone No 7001305949 For Ultimate Sexual ...
Air-Hostess Call Girls Madambakkam - Phone No 7001305949 For Ultimate Sexual ...Ahmedabad Escorts
 
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdf
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdfHemostasis Physiology and Clinical correlations by Dr Faiza.pdf
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdfMedicoseAcademics
 
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceCollege Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceNehru place Escorts
 
9873777170 Full Enjoy @24/7 Call Girls In North Avenue Delhi Ncr
9873777170 Full Enjoy @24/7 Call Girls In North Avenue Delhi Ncr9873777170 Full Enjoy @24/7 Call Girls In North Avenue Delhi Ncr
9873777170 Full Enjoy @24/7 Call Girls In North Avenue Delhi NcrDelhi Call Girls
 
Hematology and Immunology - Leukocytes Functions
Hematology and Immunology - Leukocytes FunctionsHematology and Immunology - Leukocytes Functions
Hematology and Immunology - Leukocytes FunctionsMedicoseAcademics
 
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...narwatsonia7
 
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...narwatsonia7
 
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Call Girls Hsr Layout Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hsr Layout Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hsr Layout Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hsr Layout Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
call girls in paharganj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in paharganj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in paharganj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in paharganj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
Call Girls Viman Nagar 7001305949 All Area Service COD available Any Time
Call Girls Viman Nagar 7001305949 All Area Service COD available Any TimeCall Girls Viman Nagar 7001305949 All Area Service COD available Any Time
Call Girls Viman Nagar 7001305949 All Area Service COD available Any Timevijaych2041
 
97111 47426 Call Girls In Delhi MUNIRKAA
97111 47426 Call Girls In Delhi MUNIRKAA97111 47426 Call Girls In Delhi MUNIRKAA
97111 47426 Call Girls In Delhi MUNIRKAAjennyeacort
 
Call Girls Service Noida Maya 9711199012 Independent Escort Service Noida
Call Girls Service Noida Maya 9711199012 Independent Escort Service NoidaCall Girls Service Noida Maya 9711199012 Independent Escort Service Noida
Call Girls Service Noida Maya 9711199012 Independent Escort Service NoidaPooja Gupta
 
Russian Call Girls Gunjur Mugalur Road : 7001305949 High Profile Model Escort...
Russian Call Girls Gunjur Mugalur Road : 7001305949 High Profile Model Escort...Russian Call Girls Gunjur Mugalur Road : 7001305949 High Profile Model Escort...
Russian Call Girls Gunjur Mugalur Road : 7001305949 High Profile Model Escort...narwatsonia7
 
Call Girls Service Nandiambakkam | 7001305949 At Low Cost Cash Payment Booking
Call Girls Service Nandiambakkam | 7001305949 At Low Cost Cash Payment BookingCall Girls Service Nandiambakkam | 7001305949 At Low Cost Cash Payment Booking
Call Girls Service Nandiambakkam | 7001305949 At Low Cost Cash Payment BookingNehru place Escorts
 
Pharmaceutical Marketting: Unit-5, Pricing
Pharmaceutical Marketting: Unit-5, PricingPharmaceutical Marketting: Unit-5, Pricing
Pharmaceutical Marketting: Unit-5, PricingArunagarwal328757
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 

KĂĽrzlich hochgeladen (20)

Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
 
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original PhotosCall Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
 
Glomerular Filtration and determinants of glomerular filtration .pptx
Glomerular Filtration and  determinants of glomerular filtration .pptxGlomerular Filtration and  determinants of glomerular filtration .pptx
Glomerular Filtration and determinants of glomerular filtration .pptx
 
Air-Hostess Call Girls Madambakkam - Phone No 7001305949 For Ultimate Sexual ...
Air-Hostess Call Girls Madambakkam - Phone No 7001305949 For Ultimate Sexual ...Air-Hostess Call Girls Madambakkam - Phone No 7001305949 For Ultimate Sexual ...
Air-Hostess Call Girls Madambakkam - Phone No 7001305949 For Ultimate Sexual ...
 
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdf
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdfHemostasis Physiology and Clinical correlations by Dr Faiza.pdf
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdf
 
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceCollege Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
 
9873777170 Full Enjoy @24/7 Call Girls In North Avenue Delhi Ncr
9873777170 Full Enjoy @24/7 Call Girls In North Avenue Delhi Ncr9873777170 Full Enjoy @24/7 Call Girls In North Avenue Delhi Ncr
9873777170 Full Enjoy @24/7 Call Girls In North Avenue Delhi Ncr
 
Hematology and Immunology - Leukocytes Functions
Hematology and Immunology - Leukocytes FunctionsHematology and Immunology - Leukocytes Functions
Hematology and Immunology - Leukocytes Functions
 
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
 
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
 
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
 
Call Girls Hsr Layout Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hsr Layout Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hsr Layout Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hsr Layout Just Call 7001305949 Top Class Call Girl Service Available
 
call girls in paharganj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in paharganj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in paharganj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in paharganj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
Call Girls Viman Nagar 7001305949 All Area Service COD available Any Time
Call Girls Viman Nagar 7001305949 All Area Service COD available Any TimeCall Girls Viman Nagar 7001305949 All Area Service COD available Any Time
Call Girls Viman Nagar 7001305949 All Area Service COD available Any Time
 
97111 47426 Call Girls In Delhi MUNIRKAA
97111 47426 Call Girls In Delhi MUNIRKAA97111 47426 Call Girls In Delhi MUNIRKAA
97111 47426 Call Girls In Delhi MUNIRKAA
 
Call Girls Service Noida Maya 9711199012 Independent Escort Service Noida
Call Girls Service Noida Maya 9711199012 Independent Escort Service NoidaCall Girls Service Noida Maya 9711199012 Independent Escort Service Noida
Call Girls Service Noida Maya 9711199012 Independent Escort Service Noida
 
Russian Call Girls Gunjur Mugalur Road : 7001305949 High Profile Model Escort...
Russian Call Girls Gunjur Mugalur Road : 7001305949 High Profile Model Escort...Russian Call Girls Gunjur Mugalur Road : 7001305949 High Profile Model Escort...
Russian Call Girls Gunjur Mugalur Road : 7001305949 High Profile Model Escort...
 
Call Girls Service Nandiambakkam | 7001305949 At Low Cost Cash Payment Booking
Call Girls Service Nandiambakkam | 7001305949 At Low Cost Cash Payment BookingCall Girls Service Nandiambakkam | 7001305949 At Low Cost Cash Payment Booking
Call Girls Service Nandiambakkam | 7001305949 At Low Cost Cash Payment Booking
 
Pharmaceutical Marketting: Unit-5, Pricing
Pharmaceutical Marketting: Unit-5, PricingPharmaceutical Marketting: Unit-5, Pricing
Pharmaceutical Marketting: Unit-5, Pricing
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
 

Patient Data Protection in EU and US Healthcare

  • 1. Protection of Patient Data in EU vs. US ERIK RANSCHAERT MD, PHD ETZ TILBURG, NETHERLANDS erik.ranschaert@gmail.com @eranrad
  • 2. Learning Objectives 1. Knowledge of the patient privacy issues involved in using AI applications 2. Knowledge of principles of the European privacy regulation 3. Knowledge of potential ethical and social issues that can be encountered by using AI applications
  • 3. Regulations and framework A.I. is 1 of the few things we should regulated proactively in stead of reactively If we regulate A.I. reactively then it’s too late
  • 4. Relevance of protecting Health Data • “FastMRI” partnership between NYU (CAI2R) and FacebookA.I. Research to make MRI scans 10x faster • Combination of domain-specific expertise from different fields and industries • Train artificial neural nets to recognize underlying structures and construct MR-images with less data • NYU provides FAIR with 3 million MR-images (knee, brain, liver) https://www.healthimaging.com/topics/artificial-intelligence/facebook-nyu-collaborate-make-mri-faster-ai
  • 5. Security measures • The MR images used for this project have to be scrubbed of any potential distinguishing features. • Approved by NYU Langone’s Institutional Review Board, following policies and procedures for human subjects research protection • No Facebook data of any kind will be used in the project. • Fully HIPAA compliant (Health Insuranc Portability and AccountabilityAct)
  • 6. How are patient data protected in the EU vs US?
  • 7. General Data Protection Regulation • EU law that came into effect on May 25, 2018. • Main purpose: to define and update the basic rights of data subjects regarding control of and access to personal data
  • 8. EU Regulation • As opposed to a directive, a regulation is directly applicable in all EU Member States. • National authorities can define exceptions and derogations from certain obligations by means of national law.
  • 9. What are Personal Data? • Any information related to an identified or identifiable natural person (data subject) • Also Health Data! 1. Data concerning physical/mental health 2. Genetic data 3. Biometric data NEW
  • 10. The Goals of the GDPR Protect • EU citizen’s personal data Control • To data subjects over their processed data Unify • The duties and responsabilities of controllers and processors Simplify • The means of data collection and processing
  • 11. Economical purpose Any organization that processes EU citizens’ data, even if the company isn’t located in the EU, has to ensure GDPR compliance.
  • 12. Handling of personal data: 3 players Data subject Data controller Data processor 1. Collection 2. Encryption & storage 3. Forwarding 4. Processing
  • 13. GDPR in Healthcare • Facilitates free flow of patient data within EU. • Personal data can only be collected under strict conditions and for legitimate purposes. • Data controller (hospital, HCP) has to respect rights of data subject • Data processor must protect information it handles, processes and stores on behalf of data controller
  • 14. Opportunities for HC created by GDPR 1. Improving the sharing and interoperability of health data 2. Helps HC organisations to build consumer trust • Mitigate negative sentiments generated from recent data breaches (Cambridge Analytica/FB saga) 3. Spur adoption of alternative modes of data management (e.g. blockchain) • Single source of trusted information, reducing redundancy and administrative costs Sharing Trust Costs
  • 15. • GDPR concerns EVERY piece of information that can identify a person, not limited to HC • HIPAA only governs protected health information (PHI) Governance HIPAA vs. GDPR
  • 16. Position of ESR • The GDPR is welcomed by the ESR
  • 17. Meaning for Radiology Received: 20 March 2017 / Accepted: 21 March 2017 / Published online: 24 April 2017
  • 18. GDPR Key Elements Clear Consent Erasure (right to be forgotten) Rectification Portability Notification of data breach Demonstration of Compliance Data Protection Officer (DPO) Derogations and exceptions 2 3 4 1 5 6 7
  • 19. 1. Clear Consent • Explicit consent of data subject prior to data processing • Explicit consent prior to communication of imaging data 1
  • 20. • HIPAA only governs protected health information (PHI) • GDPR concerns EVERY piece of information that can identify a person, not limited to HC Governance • HIPAA does not require consent from patient to release health data for third parties (e.g. for insurance company) • GDPR needs explicit consent for any interaction with PHI other than direct patient care Consent HIPAA vs. GDPR
  • 21. 2. Erasure and Rectification • Destruction of data if storage is no longer necessary for the initial purpose • Withdrawal of consent possible, “the right to be forgotten” • The right to obtain rectification of his/her data 2
  • 22. 3. Portability of health data • Data subject has the right to transfer personal data to another service provider • Hospitals and other HCPs have to provide electronic data in an appropriate format to a patient upon request – free of charge https://www.himss.eu/himss-blog/data-portability-and-sharing-personal-health-data-across-national-borders 3
  • 23. • HIPAA only governs protected health information (PHI) • GDPR concerns EVERY piece of information that can identify a person, not limited to HC Governance • HIPAA does not require consent from patient to release health data for third parties (e.g. For insurance company) • GDPR needs explicit consent for any interaction with PHI other than direct patient care Consent • HIPAA grants right to a copy of PHI, not for free • GDPR grants right to copy of health data for free, and even to rectify and erase data Privacy HIPAA vs. GDPR
  • 24. 4. Data Breach • Breach or hacking of Personal Data • Notification within 72 hrs to Supervisory Authority • Communication to data subject • Larger institutions: DPO needed 4
  • 25. • HIPAA only governs protected health information (PHI) • GDPR concerns EVERY piece of information that can identify a person, not limited to HC Governance • HIPAA does not require consent from patient to release health data for third parties (e.g. For insurance company) • GDPR needs explicit consent for any interaction with PHI other than direct patient care Consent • HIPAA grants right to copy of PHI, not for free • GDPR grants right to copy of health data for free, and even to rectify and erase data Privacy • Both require absolute secure measures to ensure confidentiality • HIPAA breach notification is 60d vs 72h for GDPR (including communication to data subject) Security
  • 26. 5. Demonstration of Compliance • All organisations processing personal data must be able to prove that they comply with the rules • Hospitals and HCPs need to define their lawful basis for processing health data and demonstrate their compliance with GDPR • e.g. for access to databases such as EPR and PACS 5
  • 27. Stringent Penalties • Failure to comply with the new data protection rules can result in different types of sanctions from controllers, ranging from • a warning, • a reprimand, • to a temporary or definitive ban on processing data, • and a fine of up to €20 million or 4% of the business’s total annual worldwide turnover
  • 28. • HIPAA only governs protected health information (PHI) • GDPR concerns EVERY piece of information that can identify a person, not limited to HC Governance • HIPAA does not require consent from patient to release health data for third parties (e.g. For insurance company) • GDPR needs explicit consent for any interaction with PHI other than direct patient care Consent • HIPAA grants right to copy of PHI, not for free • GDPR grants right to copy of health data for free, and even to rectify and erase data Privacy • Both require absolute secure measures to ensure confidentiality • HIPAA breach notification 60d vs 72h, including data subjectSecurity • Any organisation violating regulations is liable to be prosecuted • HIPAA: prosecution is related to “significant harm” caused by violation • HIPAA penalties go up to 1.5 million USD, GDPR is much higher Penalties
  • 29. 6. DPO • Data Protection Officer is mandatory for those companies and organisations that systematically monitor data subjects on large scale of sensitive data • According to Art. 29Working Party (WP29) processing of patient data by hospital is “large scale” • The DPO is in contact with the national data protection authorities (Security Authority) 6
  • 30. Derogations and exceptions • Often conflicting objectives: • Ensure privacy rights for personal data vs. • Providing adequate access to such data for research & healthcare purposes, e.g. for developing or training A.I. • Therefore the GDPR provides several derogations regarding health data 7
  • 31. What is Scientific Research? • Only broad definition in the GDPR • Not clear how far the research exemption extends, especially as regards research activities with a commercial goal • For clinical trials: processing of data should also comply with other relevant legislation, policies, ethical standards
  • 32. ESR opinion on Data for Research • GDPR proposes technical and organisational measures such as 1. Anonymisation 2. Pseudo-anonymisation 3. Encryption
  • 33. • Remove personally identifiable information where it is not needed • e.g. Name of patient, institution, date of exam on images, DICOM metadata Anonymisation • Replace personally identifiable material with artificial identifiers • Data can no longer be attributed to individual without additional information Pseudonymisation • Encoding of messages that can only be read by authorised persons. • Can only be done with anonymised or pseudonymised data Encryption
  • 34. Image-based information • Absolute confidentiality cannot be guaranteed in case of image- based information • Matching by digital robotic algorithms of organs and pathologies could possibly allow re-identification
  • 35. What to do with Research Data? • Key question: what is the purpose of using the data? • Procedures to be followed: • Adhere to ethical standards • Use the right safeguards such as anonymisation, pseudonymisation, encryption • Pseudonymisation is generally recommended • Exemptions are provided under certain conditions • These should not result in PD being processed for other purposes by third parties, e.g. employers, insurance or banking companies, commercial enterprises
  • 36. Exemptions for Scientifc research • The purposes may override 3 basic rights in the following conditions: 1. The right to information: if the provision of information involves a “disproportionate effort” 2. The right to the processing: if it’s likely to render impossible or seriously impact the achievement of the objectives of the processing 3. The right to be forgotten: if the processing is necessary for the performance of a task carried out for reasons of public interest
  • 37. GDPR and Ethical question • Some AI algorithms are “impenetrable”, certainly those constructed by unsupervised learning, creating a so-called “black box”. • If the subject has the legal right to information following the GDPR, how can decisions concerning a person made by anAI expert system that is not transparant be fulfilled? Peter Rinck:Why radiology must take care when it comes to AI https://www.auntminnieeurope.com/index.aspx?sec=sup&sub=aic&pag=dis&ItemID=616410
  • 38. Take Home Messages • Many ethical, legal and issues are involved with the development and implementation of A.I. • The GDPR regulates all personal data, including health data • Use of health data for A.I. development is strictly regulated for all EU inhabitants • The GDPR is relevant to the development and usage of A.I. apps. • Certain derogations are applicable to data for scientific research. • Several A.I.-related ethical questions still need to be answered.
  • 39. Erik Ranschaert, MD, PhD erik.ranschaert@gmail.com @eranrad Thank you!

Hinweis der Redaktion

  1. https://code.fb.com/ai-research/facebook-and-nyu-school-of-medicine-launch-research-collaboration-to-improve-mri/ CAI2R = Center for Advanced Imaging Innovation and Research https://med.nyu.edu/research/research-resources/clinical-research/sites/default/files/nyu-som-irb-policies-and-procedures-for-human-subjects-research-protection.pdf
  2. HIPAA Health Insuranc Portability and Accountabiity Act
  3. GDPR wants to protect the rights of the data subject while preserving the benefits of digital image processing for research & public health purposes