NCBI Bookshelf. A service of the National Library of Medicine, National Institutes of Health.
Solaiman B, Cohen IG, editors. Research Handbook on Health, AI and the Law. Cheltenham, UK: Edward Elgar Publishing Ltd; 2024 Jul 16. doi: 10.4337/9781802205657.ch07
Privacy is a key issue in AI regulation, especially in a sensitive area such as healthcare. The United States (US) has taken a sectoral approach to protecting privacy that presents limitations when it comes to AI. Privacy protections in clinical contexts, research arenas, commercial and consumer contexts and public health all vary. AI relies on vast quantities of data that travel from one context to the other, draws inferences that were never present in the data and can be used in unforeseen ways. Further, even the sectoral approach has its limitations – for example, in the public health sphere, private entities that lead the AI ecosystem are left unregulated, while in the commercial context, AI privacy regulation relies on policies that companies write themselves. A better approach would focus on protections that rely on the nature of the data involved.
1. Introduction
In the United States (US), privacy protections are fragmented into different regimes. To a large degree, the protections depend on the use to which health data are applied. We separate protections into four categories: clinical, research, public health and commercial uses. We then describe the protections that apply to each context in the US.
First, AI can be used in various ways at the clinical level. AI can be used at the data collection phase, for example, by using facial recognition technology to determine whether a patient is feeling pain. Such technology can also be used to ‘measure heart rate, blood pressure and stress levels’.1 AI produces lower error rates when used in imaging analysis compared to human error rates. The data collection phase blends into the diagnostic phase. AI can analyse collected data to identify appropriate treatments, consistent with patient profiles, insurance access, drug adherence and broader socio-economic factors.2 Finally, at the treatment phase, AI can assist with various therapies, drug adherence and other tasks such as ‘keeping an elderly person company in their home’.3 The data here is largely governed by federal statutes. Yet, AI and the large datasets on which it relies present complications under this federal regime.
The second category involves research, where data can be used in controlled trials for generating drugs and devices. AI can be used in various ways. For example, ‘it is difficult for the human brain to interrogate the vast number of relevant organic reactions available in the literature’. AI can thus be used in early stages of drug identification, to ‘predict the on- and off-target effects and in vivo safety profile of compounds before they are synthesised’.4 Similarly, AI can be used to identify the appropriate biomarkers required to recruit patients for trials, predict patient dropout, ensure quality assurance, guide the production cycle, create appropriate drug classifications and probe datasets of polypharmacological effects.5 Data in this context is governed by a range of federal statutes. Many of these statutes have been modified as the complications that AI presents have become clearer.
Third, AI is used commercially by companies for profit. However, data can also be used for profit. Most prominently, AI can be used for identifying the kind of information that would affect consumer decisions, matching consumer profiles to information most effectively, and disseminating the information. Such information receives only limited privacy protection, depending on the privacy policies that companies advertise at the point of collection. Later transmission and use for AI purposes is only minimally regulated.
Similar limitations exist in the public health sphere. AI can be used to analyse tweets to predict prescription medication abuse.6 Some studies suggest that electronic health records (EHRs), Twitter and climate data from the US National Aeronautics and Space Administration (NASA) could be used to predict epidemics of infectious diseases such as influenza and malaria. Other studies involved surveillance of non-infectious phenomena, such as traffic crashes, which were paired with a municipal crash intervention service. Other research has linked high blood pressure to seasonal variation, and has analysed tweets to predict where and when public health service officials should anticipate negative vaccine sentiment.
To limit its scope, this chapter does not consider information protection in healthcare contexts where patient information is not involved. For example, the data that may be relied upon for automated manufacturing, data regarding employee absences or other employee performance data that do not implicate information related to patient outcomes are not addressed in this chapter.7 We also only consider rules and regulations issued by governmental or quasi-governmental bodies. Our analysis of these rules is necessarily simplified and focuses only on key regulations. Finally, the focus of this chapter is on privacy rather than security regulations, which means that we do not consider the technological steps required to keep data secure, including encryption, data breach regulations and secure communications.8
Health data privacy protections usually apply differently depending on what entities are involved, how they acquired the data and what uses the data serve. This approach, often referred to as ‘sectoral’ privacy, presents significant complexity. The chapter examines privacy protections in four contexts – clinical, research, public health and commercial – building on the examples provided above. While the analysis is focused on US law, this chapter is intended to provide a foundation for other researchers to explore these issues from alternate legal dimensions.
2. Clinical Contexts
The key set of privacy protections in clinical contexts are those laid out by the Privacy Rule of the Health Insurance Portability and Affordability Act (HIPAA). This Rule forms the baseline for health data protection in clinical contexts, upon which certain other regulations, such as state laws, build.9
AI presents a range of questions under HIPAA. First, there is the question of when HIPAA applies. HIPAA applies to so-called covered entities, that is, ‘health plan[s], [. . .] health care clearinghouse[s], [and] [. . .] health care provider[s] who transmit[] any health information in electronic form’.10 It also applies equally to their contractors, known as ‘business associates’.11 But what about standalone AI-based technology that provides advice, which could be construed as clinical, to patients?
The US Department of Health and Human Services (HHS) released guidance in 2016 that offers a fairly restrictive interpretation of HIPAA’s coverage in the context of mobile applications. It explains that app development carried out as an employee or business associate of a HIPAA-covered entity would invite HIPAA protections.12 Extrapolating this more generally, AI developed on behalf of a covered entity is covered by HIPAA.
Even though non-HIPAA-covered AI remains subject to general consumer privacy law, described below, AI’s exclusion from HIPAA presents regulatory inconsistency. As commentators – both in this book and elsewhere – explain, AI has the potential to replace many functions currently carried out by doctors, where it has not done so already.13 For example, Ada, an app that identifies itself as ‘[t]he world’s trusted partner for clinically driven AI’, boasts more than 13 million users.14 It helps users identify their conditions and suggests solutions to address those conditions.15 One study of various digital symptom assessment apps, including Ada, found that in terms of ‘coverage, accuracy and safety’, ‘some came close’ to the performance of general practitioners, with Ada at the high end of performance. Further, ‘the nature of iterative improvements to software offers scalable improvements to care’.16 While Ada complies with HIPAA and partners with medical professionals,17 it is unclear whether the law compels it to do so.
Even when it is clear that AI is subject to HIPAA regulation, AI complicates questions of compliance. HIPAA’s Privacy Rule states that ‘[a] covered entity or business associate may not use or disclose protected health information’ (PHI) in ways not authorised by the Rule. PHI, in turn, is defined as individually identifiable health information that relates to the health of an individual or to the provision or payment of care, which can be used to identify an individual.18 Where disclosure is authorised, ‘a covered entity or business associate must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request’.19 But does conveying information to an AI algorithm count as a use or a disclosure? Existing authority suggests that the answer is no. During the notice and comment period of the promulgation of the original Privacy Rule in 2000, a commentator noted:
the definition [of ‘use’] could encompass the processing of data by computers to execute queries. It was argued that this would be highly problematic because computers are routinely used to identify subsets of data sets. It was explained that in performing this function, computers examine each record in the data set and return only those records in the data set that meet specific criteria. Consequently, a human being will see only the subset of data that the computer returns. Thus, the commenter stated that it is only this subset that could be used or disclosed.20
HHS responded: ‘We interpret “use” to mean only the uses of the product of the computer processing, not the internal computer processing that generates the product.’21 Under this approach, sending the data to a computer does not count as a use under HIPAA – only the diagnosis or conclusion that the computer provides is subject to regulation – and such data transmission would not be subject, for example, to the ‘minimum necessary’ standard.
That said, this guidance does not bind the agency – the agency’s position may well have changed given the AI processing of data and the expansion of data networks that we have seen in the subsequent decades. While HHS has not updated this commentary, in other contexts it suggests that access by a computer system constitutes a use. For example, in guidance regarding ransomware, HHS has explained that ‘[w]hen [PHI] [. . .] is encrypted as the result of a ransomware attack’ there has been ‘a “disclosure” not permitted under the HIPAA Privacy Rule’.22 Further, as one practice expert notes: ‘a regulator or court could distinguish between search queries – which do not identify data that do not meet search parameters – and AI, which arguably is using all of the data to “learn”.’23
Assuming that transmitting information to AI counts as a ‘use’ of data, the Privacy Rule then lays out a series of exceptions with decreasing authorisation required from the individual: for example, sales or marketing requires a ‘valid authorization’,24 other uses require only notice and an opportunity to object,25 while information can be released for treatment, payment or healthcare operations,26 or to certain public entities – for public health or criminal justice purposes, for example – without permission.27 Several of these uses are discussed in later sections.
Finally, the covered entity may release de-identified data. Data is considered de-identified under HIPAA when 18 identifiers are removed or – in a step that is rarely used – subject to certification by a computer professional.28 The covered entity can also release a limited dataset that is partially de-identified, subject to a data use agreement.29
As one health law scholar notes, ‘Artificial intelligence reduces the already-weak power of de-identification to protect health privacy by making it easier to reidentify patients, either individually or at scale’.30 Some reidentification can happen using the given dataset itself. For example, even if the relevant identifiers, including the patient’s name or date of birth, are extracted from a CT scan, AI can be used to engage in facial reconstruction of the patient solely from the scan itself, thus reidentifying the patient.31
Reidentification mostly happens, however, through what experts refer to as ‘linkage attacks’.32 When a supposedly anonymised dataset is released, data from that set can be linked to another dataset with information regarding identified individuals. Thus, a dataset with anonymised medical records could be linked to another dataset – names of parents and dates and locations of their children’s birth – to identify the records of the parents. AI makes such reidentification even more plausible: even when certain characteristics, such as sex or age, are not present in a released dataset, AI can infer the information and then use it for further data linkage and reidentification. Thus, one paper concluded that 99.98 percent of all Americans can be identified using only 15 identifiers.33
Some scholars argue that, while reidentification risk appears high in research settings, the real-world risk of reidentification of health data is low. As they explain, ‘it is nontrivial for would-be attackers to obtain accurate information about all quasi-identifiers [. . .] Consequently, the amount of alteration applied to a biomedical dataset may be excessive’.34 The Government Accountability Office has found some merit to these claims.35
That said, recent regulation, which has increased the availability of health data and the scope of data collected, changes the landscape. First, in 2016, Congress passed the 21st Century Cures Act, which takes several steps to promote interoperability. Among other provisions, the Act instructed the relevant federal agency to create a ‘trusted exchange framework’.36 The agency worked with a private entity to put together this framework but seeks to ensure the national availability of health data.37 While the details of the network have yet to be finalised, the availability and accumulation of health data increase privacy risk through AI analysis.
Next, the scope of information collection has increased. In the past several years, HHS has taken steps to expand the scope of the data that EHRs hold. In particular, they seek to collect information regarding social determinants of health – that is, information regarding income, housing and employment – that studies show have as much as or more of an effect on long-term health than genetic factors.38 Collecting this information is vital and, if deployed correctly, it can dramatically improve the health of vulnerable communities. At the same time, expanding the scope of information collected increases the number of data points available to AI and increases de-identification risks.
Despite these concerns, just as AI can be used to undermine privacy, it can also be used to protect it. AI techniques can be used to reach optimal levels of de-identification. Amazon, for example, advertises its ‘robust approach to automatically detect and remove PHI in healthcare medical record data using machine learning’.39 Google offers similar services.40 AI can be used to de-identify medical notes, for which automated de-identification can be costly.41
Further, AI techniques can aid data segmentation. Not all medical data is sensitive to the same degree. For example, 42 CFR Part 2 imposes higher protections for patients with substance use disorders. Among other requirements, it sets out strict standards for what constitutes written consent or criminal justice referrals.42 Similarly, several states offer protections to certain kinds of data – such as HIV status – that exceed HIPAA requirements.43 Indeed, some commentators have suggested rating data sensitivity based on patient preferences.44
One technique to ensure that extra-sensitive data is protected is through data segmentation. For example, in 2015, HHS released the ‘data segmentation for privacy’ initiative, which uses metadata to mark certain information as subject to higher privacy standards.45 The standard was envisaged as applying specifically to Part 2 data. AI techniques, however, will render such manual marking obsolete. As one industry publication explains: ‘With AI-based segmentation, we ascertain what attributes of a file point to it being more likely to contain sensitive data after scanning just a small statistical sample of files. This provides us with important information to prioritize our search for high-risk data.’46 AI can therefore offer tools that promote compliance with privacy regulation and its goals. Similarly, as and when data breaches do happen, ‘AI technology has the capability of identifying the breach and responding to threats efficiently’, explains another industry player: ‘The technology is much more efficient than traditional security measures. It constantly monitors the behaviour within the network and proactively flags anomalies as and when detected. Using behavioural modelling, the AI technology helps identify malware and takes automated measures to counter the impact.’47
Companies, therefore, seek to ‘automate compliance’ with HIPAA using various AI tools.48 Indeed, one company tested ChatGPT to write HIPAA-compliant codes to which professionals could refer – the results were impressive but did not meet legal requirements.49 Finally, short of breaches, AI also offers tools that help with compliance with other aspects of HIPAA.50 HIPAA gives individuals the right to dispute the accuracy of their information and to seek an accounting of their information disclosures, all of which can be assisted using AI techniques.51 The use of AI in this context, in turn, presents various questions of liability in cases of non-compliance.
3. Research
AI has changed the way medical research is done. ‘Until the nineteenth century, research mostly occurred informally in the course of treating a patient and observing outcomes’; ‘the clinical trial became the staple of medical research in the twentieth century’.52 But with the advent of AI, research increasingly takes the form of ‘informational’ or ‘secondary’ research. This research involves data collected for purposes other than a particular study. This includes data collected in clinical contexts regarding patients, data collected during the course of previous studies, including troves of biospecimens and genetic data, and even consumer health data, discussed below.
The changes that big data and AI techniques have brought to research have affected research regulation. Until quite recently, federal research policy did not contemplate AI. Research protections for human subjects arose globally in reaction to atrocities against marginalised populations in Nazi Germany and the apartheid US.53 In the US, these protections culminated in the Federal Policy for the Protection of Human Subjects in 1991.54 As it is common to 20 federal agencies, it is generally referred to as the Common Rule.55 The Rule governs ‘all research involving human subjects conducted, supported, or otherwise subject to regulation by any Federal department or agency’.56 ‘[R]esearch’ refers to ‘a systematic investigation [. . .] designed to develop or contribute to generalizable knowledge’.57 A ‘human subject’ is a ‘living individual about whom an investigator [. . .] conducting research obtains’ either data through ‘intervention or interaction with the individual’ or ‘identifiable private information’.58 In general, Institutional Research Boards (IRBs) must review the risks and benefits of covered research, and ensure equitable subject selection,59 informed consent standards60 and privacy protections.61
As AI and big data techniques developed, however, questions increasingly arose regarding the use of health data and biospecimens. Pro-privacy advocates found the existing regimen problematic. Given the definition of ‘human subject’ under the old Common Rule, consent was not required for research carried out with secondary data – that is, data obtained without interaction with a human subject – if it was not ‘identifiable’. Notably, the identifiability standard under the Common Rule is lower than that of HIPAA: identifiable information is ‘private information for which the identity of the subject is or may readily be ascertained by the investigator or associated with the information’.62
On the other hand, research involving large identifiable datasets also presented concerns. Identifiable information is sometimes vital for research. The old Common Rule technically required informed consent simply for collecting identifiable information, even if no intervention or interaction occurred. Recognising the burdens, IRBs would usually just grant expedited review when large identifiable datasets were involved.63
Accordingly, in 2011, HHS began the process of revising the Common Rule, recognising that ‘current regulations governing human subjects research were developed years ago when research was predominantly conducted at universities, colleges, and medical institutions’ and that new standards were required for ‘research involving databases, the Internet, and biological specimen repositories, and the use of advanced technologies, such as genomics’.64 The final regulations were released in 2017 and became effective in 2019.65 HHS explained that the existing regulations were not viable for research geared towards AI: ‘IRBs frequently waive consent for research involving the secondary use of identifiable private information, particularly when the data sets are large or drawn from multiple institutions.’66 And in general, ‘requiring these studies to undergo IRB review will provide little or no additional protections to subjects, while continuing to generate potentially substantial burdens on investigators and IRBs’.67 It accordingly fashioned ‘a framework for “broad consent,” a new type of consent’ pertaining to large identifiable datasets.68 Under the new Rule, an IRB can approve broad consent for studies that maintain appropriate confidentiality and that involve ‘storage, maintenance, and secondary research [. . .] of identifiable private information or identifiable biospecimens’.69 Broad consent requires the IRB only to ensure that the subject is informed generally regarding the kind of information that may be used, how long it may be used for, the types of research that might be carried out, risks, benefits and confidentiality protections, as well as the possibility of commercial benefits or genome sequencing.70 When identifiable data is collected, there must also be a statement as to whether the data may be de-identified and used for further research studies, possibly by other investigators ‘without additional informed consent’.71
Broad consent provides a compromise between the full consent requirements of the older Common Rule that would have made AI techniques impossible to apply, and a complete waiver of consent. But an IRB may waive any informed consent requirement if the risks to the subjects are minimised and the burdens on the research are substantial.72
Finally, the new Rule explicitly considers the fact that newer forms of research rely on data collected in the course of clinical practice. First, it notes that the review is allowed for biological specimens or data obtained through means ‘routinely employed in clinical practice’ (with a few exceptions) or ‘voice, video, digital, or image recordings made for research purposes’.73 Second, it clearly recognises the interface between HIPAA protections and the Common Rule. As it explains in justifying broad consent requirements: ‘[I]n many cases, other laws such as HIPAA also provide protections in the research context for the information that would be subject to this proposed exemption (e.g., clinical records), such that additional Common Rule requirements for consent may not be necessary in those contexts.’74
HIPAA, it notes, includes, ‘where appropriate, requirements to obtain the individual’s authorization for future, secondary research uses of protected health information’.75 Indeed, the important role that HIPAA plays in research regulation is a testament to the influence that AI has had. AI insights into clinically generated data that may fall under the Common Rule can be fed back into the clinic, which then produces further clinical outcomes. This produces ‘a “continuous feedback loop,” the analysis of which iteratively helps to improve clinical and health delivery outcomes’.76 This changing approach to research means that the boundaries between clinical and research uses of data become more porous.
Turning then to HIPAA, HIPAA requires authorisation that states the ‘purpose’ of any research before a covered entity can use patient data.77 Until 2013, HHS took the position that this purpose had to describe a specific research study – an approach that would have been fatal to AI development. Under 2013 modifications to HIPAA, HHS considered ‘evolving technologies and discoveries’ that made such consent impractical and modified its interpretation of the Rule.78 Its current interpretation allows patients to generally consent to future research without any specific requirements. HIPAA also allows an IRB or Privacy Board to waive consent requirements – though obtaining such a waiver requires satisfying several requirements, including some regarding membership of the relevant IRB or board.79
The HIPAA regime presents one final complication when it comes to the analysis of big data. HIPAA, as noted above, allows data to be used for ‘treatment, payment, and healthcare operations’ without authorisation.80 Yet, hospitals and healthcare organisations may use data to develop AI in ways that straddle the line between healthcare operations and research.
The distinction between ‘healthcare operations’ and ‘research’ turns largely on a single term: ‘generalizable knowledge’. Under HIPAA, research is ‘a systematic investigation, including research development, testing, and evaluation, designed to develop or contribute to generalizable knowledge’.81 Healthcare operations, in turn, involve ‘quality assessment and improvement activities, including outcomes evaluation and development of clinical guidelines, provided that the obtaining of generalizable knowledge is not the primary purpose of any studies resulting from such activities’.82 The term also includes ‘population-based activities relating to improving health or reducing health care costs’ and ‘protocol development’.83
Now, AI which assesses data to develop clinical guidelines, evaluate outcomes, or improve healthcare quality, is often used for research. Thus, HHS has clarified, ‘[t]he distinction between health care operations and research rests on whether the primary purpose of the study is to produce “generalizable knowledge”’.84
But when does the development of AI involve contribution or the obtaining of generalisable knowledge? Publishing an article based on research can fairly be said to contribute to such knowledge. But as the HHS Office for Human Research Protections (OHRP) notes:
Whether or how an investigator shares results with the scientific community is not the deciding factor for whether the activity was designed to develop or contribute to generalizable knowledge. For example, lots of information is published that comes from activities that do not meet the Common Rule’s definition of research. And sometimes results from research that meets the Common Rule definition never get published.85
But what if AI is used to develop tools that a hospital or healthcare organisation seeks to sell without publication? HHS provides no answer. One might reason by analogy, however. In its Privacy Rule guidance, HHS contemplates that ‘a covered entity could disclose protected health information to a pharmaceutical company for research purposes’ if certain requirements are met.86 Presumably, such companies, in most cases, use the data to develop a commercial product rather than for publication. Research that allows for the development of a commercial product available to the public, therefore, appears to contribute to generalisable knowledge.
However, what if a hospital develops AI for its internal use, but the AI attracts academic or commercial interest, resulting in publication or sales? At the time of transition, ‘the covered entity should document the change in status of the activity to establish that they did not violate the [Rule’s] requirements’.87
Overall, HHS will likely consider the behaviour of the covered entity in determining whether the data was geared towards research or healthcare operations. Thus, as one expert counsels, ‘[b]ecause the line between health care operations and research can get blurry, counsel should consider how the flow of payments between the parties and the ownership rights of intellectual property affect the perception of the primary purpose of each use and disclosure of PHI’.88
While the big innovation that AI brings is analysis and pattern detection in big data, as noted above, it can also contribute to clinical trial contexts. As the FDA notes in a report released in the summer of 2023, AI can be used in identifying and prioritising drug targets; recruiting, selecting, dosing, maintaining adherence, retaining and site selection for clinical trial participants; collecting and analysing data; and identifying endpoints.89 Drug manufacturers also use post-market surveillance. The FDA offers its own regulatory regimen for clinical trial research. Details regarding the specifics of the FDA scheme are beyond the scope of this chapter. The FDA recently issued rulemaking standards to bring its research protections more in line with the Common Rule, pursuant to statutory mandate,90 and its recent Report asks stakeholders to report privacy practices with respect to AI as the FDA moves forward with additional recommendations.91
4. Consumer and Commercial Protections
AI that is used in consumer and commercial contexts relies largely on data generated outside the privacy regimes described above and generally involves data provided directly by the consumer. Analyses of these datasets produce a range of outcomes that can harm consumers. Yet, privacy regimes fail to fully address these harms.
AI in the consumer space that relies on health data serves numerous functions. Advertising and analytics companies, for example, purchase consumer data to run AI that allows them to target advertising to users. In one famous example, Target analysed buying patterns to determine when its customers were pregnant. When it received pushback for sending marketing that disclosed its customer’s pregnancy (in one instance, the customer’s father did not know his daughter was pregnant), it began sending personalised flyers that had a higher density of pregnancy-related advertising interspersed with other products.92 But the data is used for other purposes as well. It can be sold back to app developers seeking to improve the predictive accuracy of their algorithms, or to companies seeking to use AI to figure out how to invest in pharmaceuticals.93
Health insurers purchase data for a range of purposes: a woman who has changed a name might ‘have a pricey pregnancy pending’ or be ‘stressed and anxious from a recent divorce’; someone ‘who has purchased plus-size clothing [. . .] [is] considered at risk of depression’ (and presumably other conditions).94 Someone who is ‘[l]ow-income and a minority [. . .] [is] more likely to live in a dilapidated and dangerous neighborhood, increasing [. . .] health risks’.95 While insurance companies claim that they only use this data to get clients the services they need, and various civil rights laws prevent them from discriminating based on certain characteristics,96 those who work with insurers cannot rule out that such discrimination does occur.97 As one source explains, insurers may use the data to discourage sick patients from signing up by excluding providers with certain expertise from their networks, excluding certain types of care, altering the language of plan documents and even modifying pricing.98 And, of course, AI can predict the best ways to achieve those exclusions. Some commentators raise concerns about employers and financial and educational institutions also engaging in discrimination.99
The data on which such AI relies on comes from numerous sources. Some sources are covered entities that sell de-identified data.100 But that data can then be linked to data generated in non-covered spaces, which is generated at increasingly high rates. For example, an individual may conduct a web search to assess symptoms or identify a pharmacy to purchase an over-the-counter drug to obtain clinical results. Spending habits, online interactions, membership in Facebook groups and Twitter (or Threads) feeds can predict physical and mental health.101
But sources that are geared directly towards health also generate AI-relevant consumer data. For example, an estimated 63 percent of adults in the US have used mobile health applications since 2022,102 which collect a significant amount of data: 88 percent have tracking capabilities, two-thirds can collect identifiers or cookies, one-third can collect email addresses and one-quarter can identify the mobile phone tower to which a user’s device is connected.103
Some evidence suggests that mobile health applications engage in tracking and advertising at lower rates than other mobile applications.104 But one report, which studied ten opioid treatment apps that had been installed at least 180,000 times, ‘found that the majority of the apps accessed unique identifiers about the user’s device and, in some cases, shared that data with third parties’.105 Many apps accessed the devices’ phone numbers, unique IMEI and IMSI numbers and a list of the users’ list of installed apps, which could be ‘used to build a “fingerprint” of a user to track their activities’.106
The data from numerous apps, anonymised medical records, web searches, consumer reports and elsewhere is then agglomerated by data brokers who match the records together using the abovementioned linkage methods. Brokers claim to strip names from the record and keep them anonymous. Yet, each record is usually assigned a unique identifier with all the information, which, as a full profile of the individual, does not provide much anonymity.107 More importantly, not all brokers engage in this practice. One recent report from Duke’s Sanford School of Public Policy reveals that brokers researched would sell information regarding ‘depression, attention disorder, insomnia, anxiety, ADHD, and bipolar disorder as well as data on ethnicity, age, gender, zip code, religion, children in the home, marital status, net worth, credit score, date of birth, and single parent status’, and not all of them stripped names.108
What are the legal protections that apply in this space? Problematically, all the legal protections apply only at the points of data collection rather than to how AI will use the data. Under the Federal Trade Commission Act of 1914 (FTCA), the FTC is responsible for remedying ‘unfair or deceptive acts or practices in or affecting commerce’.109 In the privacy context, this means that the FTC penalises non-adherence to privacy policies. Further, the American Reinvestment and Recovery Act of 2009, in addition to amending certain HIPAA protections, required non-HIPAA-covered companies to notify consumers and the FTC of data breaches of personal health information and gave the FTC power to promulgate rules and penalise non-compliance.110
In some cases, where companies misrepresent policies, the FTC has brokered settlements resulting in changes in how data brokers facilitating AI analysis and others down the line can use the data. For example, in the Flo Health Inc. Settlement of 2021, the FTC settled with Flo Health Inc., a developer of a period and fertility-tracking app used by more than 100 million consumers. According to the FTC’s complaint, the Flo Period & Ovulation Tracker used software from various third-party marketing and analytics firms, which gathered unique user identifiers, among other data. According to the FTC, such data sharing violated Flo’s own privacy policy and the terms of use of the third parties with whom Flo was sharing the information. As part of its settlement agreement with the FTC, Flo was required to notify users (through its website and by email) that Flo had shared an identifying number and personal health information with third parties, as well as information about the settlement with the FTC, and to represent its data policies correctly. Flo was also required to instruct any third party that received users’ health information to destroy that data.111
Similarly, in 2023, the FTC issued a civil penalty judgment against GoodRx Holdings, Inc.,112 for failing to adhere to its privacy policy and failing to report disclosures as required by the Health Breach Notification Rule.113 The defendant was a California-based company that operated a digital health platform which offers prescription drug discounts, telehealth visits and other health services. The company collected personal and health information about its users from pharmacy benefit managers. The FTC held that GoodRx violated the FTCA by sharing personal sensitive health information for years with advertising companies and platforms, contrary to its privacy policy, and failed to report those disclosures as required by the Health Breach Notification Rule. It imposed a $1.5 million penalty and permanently prohibited GoodRx from sharing health data for ads, among other requirements.
But there are various limitations with these restrictions. Where companies do not violate their privacy policies, and correctly disclose that data is conveyed to third parties that may use it for a range of purposes, they are not subject to FTC corrective action. Next, the limits focus on data conveyance – not the kinds of AI-based analyses that companies can carry out with the data. Similarly, legislative proposals that seek to allow consumers to delete the data that data brokers hold about them focus on whether the broker holds the data, not the uses to which the data can be put.114
5. Public Health Protections
AI has increasingly been used for public health surveillance. The DEFENDER software system, for example, ‘integrates Twitter and news media for outbreak detection’.115 Similarly, during the COVID-19 pandemic, Google and Apple worked together to create an exposure notification infrastructure using apps where users could opt into participation.116 Florence, the World Health Organization’s ‘digital health care assistant’, used computer-generated imagery, animation and AI to help people quit tobacco and address COVID-19 misinformation.117 Using marketing techniques similar to those described in the previous section, public health campaigns can target individuals who would be most receptive to help prevent smoking uptake or support smoking cessation, identify individuals at risk of suicide and provide engaging and motivating methods to help individuals prevent and manage chronic disease or to encourage behavioural change.118 Others envisage an app that can identify when someone is near someone else who is sick and analyse other data such as ‘environmental risk and user health conditions to predict the risk of spreading infection in real time’.119 Indeed, the University of Pittsburgh developed AI that analyses hospital medical records and, with whole-genome sequencing, identifies the initial source of various outbreak scenarios ‘including one spanning six patients over the course of seven months’.120 Other relevant data includes ‘spatial layouts, population distribution, social networks, and contact patterns’.121
The sources that AI uses for these analyses are numerous. They include:
longitudinal health claims data; secondary use anonymized electronic health records; cohort studies, health surveys, and registries; environmental variables; molecular data such as from the genome, exposome, microbiome, or transcriptome; ‘mhealth’ wearable and sensor data; mobile phone sensing data and self-reports; online patient generated content; and the semantic web.122
The proliferation of these sources has led to the fear of surveillance creep – that is, ‘the extension of platform-specific surveillance capabilities’, which includes user tracking, geolocation, encouragement and engagement with online and mobile-app use, ‘into the domain of public health’.123 Research seeks to examine how the infrastructure built during COVID-19 can be used to address other conditions, such as HIV/AIDS, and address various other social determinants of health.124
Notably, the industry has taken a lead in public health AI. As HHS notes, ‘although significant funding [. . .] propelled EHR adoption among hospitals and physician offices, until recently, our public health information technology (IT) systems had not received substantive resources’.125 Accordingly, ‘public health agencies saw one-way data flows, overwhelmed public health data systems, and manual data review that led to limited actionable data for decision-making and no ability to provide real-time feedback to communities’.126 Conversely, concerns regarding surveillance creep increase in line with the industry, which might use the data collected during public health emergencies for commercial reasons, as described above.127
Even as private industry uses AI in large datasets for public health purposes, existing privacy protections are targeted only towards the government (apart from the restrictions described in the previous actions). HIPAA permits disclosure of records to government entities for public health purposes.128 But once disclosed, protections are fragmented and limited: states take a variety of approaches, some releasing information for different purposes, depending on the condition involved.129 Data collected by and reported to the Centers for Disease Control and Prevention and contractors are subject to protections under the Federal Privacy Act of 1974, which limits the release of data maintained in a ‘system of records’.130 Furthermore, all agencies are subject to the protections of the E-Government Act of 2002, which requires agencies to carry out privacy impact assessments when implementing technology that collects data or when collecting new data using existing technology.131
To be sure, the federal government has shifted its focus to replicating industry techniques for AI in public health. The CDC seeks to ‘[i]dentify [] personally identifiable information (PII) and protected health information (PHI) from unstructured text’ in ‘non-traditional data sources, including images, audio, social media, and data not specifically collected for public health analysis, such as electronic health records’.132 But the industry is, and will remain, far ahead of public health authorities for the foreseeable future, without any significant privacy protections.
6. Conclusion
Privacy is a key issue in AI regulation, especially in a sensitive area such as healthcare. The US has taken a sectoral approach to protecting privacy that presents limitations when it comes to AI. AI relies on vast quantities of data that travel from one context to the other, draws inferences that were never present in the data and can be used in unforeseen ways. Further, even the sectoral approach has its limitations – in the public health sphere, private entities that lead the AI ecosystem are left unregulated, while in the commercial context, AI privacy regulation relies on policies that companies write themselves.
While some data regimes in the US, such as those governing research, have changed to address AI, a better approach would focus on protections that rely on the nature of the data. Thus, for example, the European Union General Data Protection Regulation (GDPR) approved in 2016 protects ‘special categories of personal data’, which includes ‘genetic data, [. . .] data concerning health or data concerning a natural person’s sex life or sexual orientation’, or other matters; health data, in turn, includes data ‘pertaining to the health status of a data subject which reveal information relating to the past, current or future physical or mental health status of the data subject’.133 While the nature and scope of this data is disputed, the underlying point is that protections apply to the data rather than who produces the data and where it travels. Such protections would better protect individuals than the existing fragmented sector-based data protection regime.
Notes
- 1
Vera Lúcia Raposo, ‘Facial Recognition AI Technology in Healthcare and the Law’ in Barry Solaiman and I Glenn Cohen (eds), Research Handbook on Health, AI and the Law (Edward Elgar 2024).
- 2
Craig Konnoth, ‘Data Collection, EHRs, and Poverty Determinations’ (2018) 46 Journal of Law, Medicine & Ethics 622.
- 3
Tom Goffin and Sofia Palmieri, ‘Regulating Smart Healthcare Robots: The European Approach’ in Barry Solaiman and I Glenn Cohen (eds), Research Handbook on Health, AI and the Law (Edward Elgar 2024).
- 4
Kit-Kay Mak and Mallikarjuna Rao Pichika, ‘Artificial Intelligence in Drug Development: Present Status and Future Prospects’ (2019) 24 Drug Discovery Today 773, 777.
- 5
Debleena Paul and others, ‘Artificial Intelligence in Drug Discovery and Development’ (2021) 26 Drug Discovery Today 80.
- 6
For more on such studies, see Rune Nyrup and Beba Cibralic, ‘Idealism, Realism, Pragmatism: Three Modes of Theorising within Secular AI Ethics’ in Barry Solaiman and I Glenn Cohen (eds), Research Handbook on Health, AI and the Law (Edward Elgar 2024).
- 7
On protection for automated manufacturing data, see Goffin and Palmieri (n 3).
- 8
Other chapters in this book examine these issues. See Elisabetta Biasin, Erik Kamenjašević and Kaspar Rosager Ludvigsen, ‘Cybersecurity of AI Medical Devices: Risks, Legislation, and Challenges’ in Barry Solaiman and I Glenn Cohen (eds), Research Handbook on Health, AI and the Law (Edward Elgar 2024); Barry Solaiman and Georgios Dimitropoulos, ‘The Legal Considerations of AI-blockchain for Securing Health Data’ in Barry Solaiman and I Glenn Cohen (eds), Research Handbook on Health, AI and the Law (Edward Elgar 2024).
- 9
Craig Konnoth, ‘Regulatory De-Arbitrage in Twenty-First Century Cares Act’s Health Information Regulation’ (2020) 29 Annals Health Law & Life Sciences 135.
- 10
45 CFR § 160.103 (2023) (United States).
- 11
ibid.
- 12
US Department of Health and Human Services, ‘Health App Use Scenarios & HIPAA’ (2016) <www
.hhs.gov/sites/default /files/ocr-health-app-developer-scenarios-2-2016.pdf> accessed 30 April 2024. - 13
Goffin and Palmieri (n 3); Won Bok Lee, ‘Regulating Artificial Intelligence in Medical Care in South Korea’ in Barry Solaiman and I Glenn Cohen (eds), Research Handbook on Health, AI and the Law (Edward Elgar 2024); see also Jörg Goldhahn, Vanessa Rampton and Giatgen A Spinas, ‘Could Artificial Intelligence Make Doctors Obsolete?’ (2018) 363 BMJ: British Medical Journal 1; Abdullah Shuaib, Husain Arian and Ali Shuaib, ‘The Increasing Role of Artificial Intelligence in Health Care: Will Robots Replace Doctors in the Future?’ (2020) 13 International Journal of General Medicine 891.
- 14
‘Health. Powered by Ada’ (Ada) <https://ada
.com/> accessed 30 April 2024. - 15
‘About Us’ (Ada) <https://ada
.com/about/> accessed 30 April 2024. - 16
Stephen Gilbert and others, ‘How Accurate Are Digital Symptom Assessment Apps for Suggesting Conditions and Urgency Advice? A Clinical Vignettes Comparison to GPs’ (2020) 10 BMJ Open 1, 1.
- 17
‘Medical Quality’ (Ada) <https://ada
.com/medical-quality/> accessed 30 April 2024. - 18
45 CFR §§ 164.502(a), 164.508, 160.103 (2023) (United States). At a threshold level, some commentators raise questions as to whether the release of data to a computer counts as ‘disclosure’ of information.
- 19
ibid § 164.502(b)(1).
- 20
Standards for Privacy of Individually Identifiable Health Information, 65 Fed Reg 82461, 82629 (28 December 2000) (United States).
- 21
ibid.
- 22
Office for Civil Rights, ‘FACT SHEET: Ransomware and HIPAA’ (US Department of Health and Human Services 2016) 5–6 <www
.hhs.gov/sites/default /files/RansomwareFactSheet.pdf> accessed 30 April 2024. - 23
Adam Greene, ‘More Data Please! The Challenges of Applying Health Information Privacy Laws to the Development of Artificial Intelligence’ (Davis Wright Tremaine, 26 February 2020) <www
.dwt.com/blogs/privacy--security-law-blog /2020/02/ai-healthcare-privacy-laws> accessed 30 April 2024. - 24
45 CFR § 164.508 (2023) (United States).
- 25
ibid § 165.510.
- 26
Terms subject to definitions at ibid §§ 164.501, 164.506.
- 27
ibid § 164.512.
- 28
ibid § 164.514(b)(1) and (2)(i). Namely, 18 identifiers must be removed, or an appropriate professional should certify the de-identification.
- 29
ibid § 164.514(e).
- 30
W Nicholson Price II, ‘Problematic Interactions Between AI and Health Privacy’ (2021) 2021 Utah Law Review 925, 926.
- 31
Shania Kennedy, ‘Exploring Data De-Identification in Healthcare’ (HealthITAnalytics, 15 March 2023) <https:
//healthitanalytics .com/features/exploring-data-de-identification-in-healthcare> accessed 30 April 2024. - 32
Michael Platzer, ‘AI-Based Re-Identification Attacks – and How to Protect Against Them’ (Mostly AI, 22 April 2022) <https://mostly
.ai/blog /synthetic-data-protects-from-ai-based-re-identification-attacks> accessed 30 April 2024. - 33
Luc Rocher, Julien M Hendrickx and Yves-Alexandre de Montjoye, ‘Estimating the Success of Re-Identifications in Incomplete Datasets Using Generative Models’ (2019) 10 Nature Communications 1, 5.
- 34
Weiyi Xia and others, ‘Enabling Realistic Health Data Re-Identification Risk Assessment through Adversarial Modeling’ (2021) 28 Journal of the American Medical Informatics Association 744, 745.
- 35
United States Government Accountability Office and National Academy of Medicine, ‘Artificial Intelligence in Health Care: Benefits and Challenges of Technologies to Augment Patient Care’ (2020) <www
.gao.gov/assets/720/711471.pdf> accessed 30 April 2024. - 36
21st Century Cures Act 2016 § 4003(b) (United States).
- 37
Craig Konnoth, ‘Health Data Federalism’ (2021) 101 Boston University Law Review 2169, 2212–13.
- 38
Amelia Whitman and others, ‘Addressing Social Determinants of Health: Examples of Successful Evidence-Based Strategies and Current Federal Efforts’ (Office of Health Policy 2022) <https://aspe
.hhs.gov /sites/default/files /documents/e2b650cd64cf84aae8ff0fae7474af82 /SDOH-Evidence-Review.pdf> accessed 30 April 2024; ‘Social Determinants of Health’ (Healthy People 2030) <https://health .gov/healthypeople /priority-areas /social-determinants-health> accessed 30 April 2024. - 39
Adewale Akinfaderin and others, ‘Philips and AWS Automate PHI De-identification with Machine Learning’ (AWS, 14 February 2023) <https://aws
.amazon.com /blogs/industries/philips-and-aws-automate-phi-de-identification-with-machine-learning/> accessed 30 April 2024. - 40
‘Data De-identification’ (Google Cloud) <https://cloud
.google .com/healthcare-api/docs /concepts/de-identification> accessed 30 April 2024. - 41
Amber Stubbs, Christopher Kotfila and Özlem Uzuner, ‘Automated Systems for the De-identification of Longitudinal Clinical Narratives: Overview of 2014 i2b2/UTHealth Shared Task Track 1’ (2015) 58 Journal of Biomedical Informatics S11, S11.
- 42
42 CFR § 2.35 (2023) (United States).
- 43
Jason Daniel-Ulloa and Jon Johnson, ‘HIV Confidentiality Laws by State: What to Know’ (MedicalNewsToday, 23 February 2022) <https://www
.medicalnewstoday .com/articles /hiv-confidentiality-laws-by-state> accessed 30 April 2024; Morgan Leigh Tendam, ‘The HIPAA-Pota-Mess: How HIPAA’s Weak Enforcement Standards Have Led States to Create Confusing Medical Privacy Remedies’ (2018) 79 Ohio State Law Journal 411, 425–26. - 44
Craig Konnoth, ‘Classification Standards for Health Information: Ethical and Practical Approaches’ (2016) 72 Washington and Lee Law Review Online 395.
- 45
Office of the National Coordinator for Health Information Technology, ‘2015 Edition Final Rule: Data Segmentation for Privacy (DS4P)’ (2015) <https://www
.healthit .gov/sites/default/files /2015editionehrcertificationcriteriads4p_10615.pdf> accessed 30 April 2024. - 46
Will Jaibaji, ‘Efficient Data Governance with AI Segmentation’ (VentureBeat, 11 November 2022) <https://venturebeat
.com /ai/efficient-data-governance-with-ai-segmentation/> accessed 30 April 2024. - 47
Narendra Sahoo, ‘How Does Artificial Intelligence Help in Data Protection and HIPAA Compliance?’ (CPO Magazine, 27 January 2021) <https://www
.cpomagazine .com/cyber-security /how-does-artificial-intelligence-help-in-data-protection-and-hipaa-compliance/> accessed 30 April 2024. - 48
‘Automate and Accelerate HIPAA Compliance’ (DRATA) <https://try
.drata.com /product/hipaa?utm_term=hipaa %20audit&utm_campaign =DR+-+GOOG+-+HIPAA+-+PHR+EXT&utm _source =adwords&utm_medium =ppc&hsa_acc =2670496984&hsa _cam =18019011267&hsa_grp =144101801462&hsa_ad =650807352206&hsa_src =g&hsa_tgt =kwd-295000154390&hsa_kw =hipaa %20audit&hsa_mt =p&hsa_net =adwords&hsa_ver =3&gad =1&gclid=CjwKCAjwqZSlBhBwEiwAfoZUIDHPbyhON45MMlJ0yjwmi8tsfI1ykoXx48T6ngM7B7PpY9clx2fJ1xoCDZQQAvD_BwE> accessed 30 April 2024. - 49
‘AI Rising: ChatGPT, Healthcare, and HIPAA Compliance’ (CompliancyGroup, 27 January 2023) <https:
//compliancy-group .com/hipaa-and-chatgpt/> accessed 30 April 2024. - 50
AI can also aid with keeping data secure: see Nazish Khalid and others, ‘Privacy-Preserving Artificial Intelligence in Healthcare: Techniques and Applications’ (2023) 158 Computers in Biology and Medicine 1. The focus of this chapter, however, is on privacy rather than security.
- 51
45 CFR §§ 164.524, 164.526, 164.528 (2023) (United States).
- 52
Craig Konnoth, ‘Health Information Equity’ (2017) 165 University of Pennsylvania Law Review 1317, 1318–19.
- 53
David M Parker, Steven G Pine and Zachary W Ernst, ‘Privacy and Informed Consent for Research in the Age of Big Data’ (2019) 123 Penn State Law Review 703, 712–13.
- 54
Federal Policy for the Protection of Human Subjects, 82 Fed Reg 7149 (19 January 2017) (United States).
- 55
Office for Human Research Protections (OHRP), ‘Federal Policy for the Protection of Human Subjects (‘Common Rule’)’ (US Department of Health and Human Services, 27 March 2024) <https://www
.hhs.gov/ohrp /regulations-and-policy /regulations/common-rule/index .html> accessed 30 April 2024. - 56
45 CFR § 46.101(a) (2018) (United States).
- 57
ibid § 46.102(l).
- 58
ibid § 46.102(e)(1).
- 59
ibid § 46.111 (a)(1)–(7).
- 60
ibid § 46.117(c); ibid § 46.116(b)(5).
- 61
34 CFR § 97.111(a)(7) (2023) (United States).
- 62
45 CFR § 46.102(e)(5) (2018) (United States); see also 82 Fed Reg 7149 (n 54) 7164 and 7167 (noting the rejection of a broader approach in the 2017 revision).
- 63
45 CFR § 46.110 (pre-2018) (United States).
- 64
Human Subjects Research Protections: Enhancing Protections for Research Subjects and Reducing Burden, Delay, and Ambiguity for Investigators, 76 Fed Reg 44512, 44512 (26 July 2011) (United States).
- 65
Federal Policy for the Protection of Human Subjects: Six Month Delay of the General Compliance Date of Revisions While Allowing the Use of Three Burden-Reducing Provisions During the Delay Period, 83 Fed Reg 28497, 28497 (19 June 2018) (United States). An interim final rule (83 Fed Reg 2885) and the final rule (83 Fed Reg 28497) delayed the effective general compliance date until 21 January 2019.
- 66
Federal Policy for the Protection of Human Subjects, 80 Fed Reg 53933, 53963 (8 September 2015) (United States).
- 67
ibid.
- 68
Office for Human Research Protections (OHRP), ‘Attachment C – Recommendations for Broad Consent Guidance’ (US Department of Health and Human Services, 2 August 2017) <https://www
.hhs.gov/ohrp /sachrp-committee /recommendations/attachment-c-august-2-2017/index.html> accessed 30 April 2024. - 69
45 CFR § 46.104(d)(8)(i) (2018) (United States).
- 70
ibid §§ 46.111(a)(8), 46.116(a), 46.116(d).
- 71
ibid § 46.116(b)(9)(i).
- 72
ibid § 46.116(f)(3).
- 73
ibid § 46.110; Office for Human Research Protections (OHRP), ‘Expedited Review: Categories of Research that may be Reviewed Through an Expedited Review Procedure (1998)’ (US Department of Health and Human Services, 21 March 2016) <https://www
.hhs.gov/ohrp /regulations-and-policy /guidance/categories-of-research-expedited-review-procedure-1998/index .html> accessed 30 April 2024. - 74
80 Fed Reg 53933 (n 66) 53964.
- 75
ibid.
- 76
Konnoth, ‘Health Information Equity’ (n 52) 1319.
- 77
45 CFR § 164.508(c)(iv) (2023) (United States).
- 78
Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules, 78 Fed Reg 5565, 5611–12 (25 January 2013) (United States).
- 79
45 CFR § 164.512(i) (2023) (United States).
- 80
ibid § 164.506.
- 81
ibid § 164.501.
- 82
ibid.
- 83
ibid.
- 84
65 Fed Reg 82461 (n 20) 82608.
- 85
Office for Human Research Protections (OHRP), ‘Lesson 2: What is Human Subjects Research?’ (US Department of Health and Human Services) <https://www
.dwt.com/- /media/files/blogs/privacy-and-security-blog /2023/06/ohrphhslearningmodulelesson2 .pdf?la=en&rev =9401903f15914429b9c8bcab6c21acb0&hash =E94A491F149486A9154FCDF47E176C8F> accessed 30 April 2024. - 86
65 Fed Reg 82461 (n 20) 82652.
- 87
ibid 82608.
- 88
Greene (n 23).
- 89
See generally, US Food & Drug Administration (FDA), ‘Using Artificial Intelligence & Machine Learning in the Development of Drug & Biological Products: Discussion Paper and Request for Feedback’ (2023) <https://www
.fda.gov/media /167973/download> accessed 30 April 2024. - 90
OHRP, ‘Federal Policy for the Protection of Human Subjects (‘Common Rule’)’ (n 55); see 21st Century Cures Act 2016 § 1002; Protection of Human Subjects and Institutional Review Boards, 87 Fed Reg 58733 (28 September 2022); Institutional Review Boards; Cooperative Research, 87 Fed Reg 58752 (28 September 2022) (United States).
- 91
FDA (n 89) 20.
- 92
Charles Duhigg, ‘How Companies Learn Your Secrets’ (The New York Times Magazine, 16 February 2012) <https://www
.nytimes.com /2012/02/19/magazine/shopping-habits .html?pagewanted =1&_r =1&hp> accessed 30 April 2024. - 93
Adam Tanner, ‘How Data Brokers Make Money Off Your Medical Records’ (Scientific American, 1 February 2016) <https://www
.scientificamerican .com/article /how-data-brokers-make-money-off-your-medical-records/> accessed 30 April 2024. - 94
Marshall Allen, ‘Health Insurers Are Vacuuming Up Details About You – And It Could Raise Your Rates’ (NPR, 17 July 2018) <https://www
.npr.org/sections /health-shots /2018/07/17/629441555 /health-insurers-are-vacuuming-up-details-about-you-and-it-could-raise-your-rates> accessed 30 April 2024. - 95
ibid.
- 96
ibid (discussing some of the limitations).
- 97
ibid.
- 98
ibid.
- 99
Jianyan Fang, ‘Health Data at Your Fingertips: Federal Regulatory Proposals for Consumer-Generated Mobile Health Data’ (2019) 4 Georgetown Law Technology Review 125, 139.
- 100
Tanner (n 93).
- 101
Ryan Mueller, ‘Big Data, Big Gap: Working Towards a HIPAA Framework that Covers Big Data’ (2022) 97 Indiana Law Journal 1505, 1516.
- 102
Rajiv Leventhal, ‘Nearly Two-Thirds of US Consumers Are Mobile Health App Users’ (Insider Intelligence, 21 February 2023) <https://www
.insiderintelligence .com/content /nearly-two-thirds-of-us-consumers-mobile-health-app-users> accessed 30 April 2024. - 103
Quinn Grundy and others, ‘Data Sharing Practices of Medicines Related Apps and the Mobile Ecosystem: Traffic, Content, and Network Analysis’ (2019) 364 BMJ 1.
- 104
Gioacchino Tangari and others, ’Mobile Health and Privacy: Cross-Sectional Study’ (2021) 373 BMJ 1, 5.
- 105
Carly Page, ‘Opioid Addiction Treatment Apps Found Sharing Sensitive Data with Third Parties’ (TechCrunch, 7 July 2021) <https://techcrunch
.com /2021/07/07/opioid-addiction-treatment-apps-found-sharing-sensitive-data-with-third-parties/> accessed 30 April 2024. - 106
ibid.
- 107
Tanner (n 93).
- 108
Joanne Kim, ‘Data Brokers and the Sale of Americans’ Mental Health Data’ (Cyber Policy Program 2023) 4 <https://techpolicy
.sanford .duke.edu/wp-content /uploads/sites /4/2023/02/Kim-2023-Data-Brokers-and-the-Sale-of-Americans-Mental-Health-Data .pdf> accessed 30 April 2024. - 109
15 USC § 45 (United States).
- 110
American Recovery and Reinvestment Act of 2009 §§ 3009 and 13407 (United States).
- 111
Kirk Nahra and others, ‘Big Data Analytics Privacy Law Considerations’ (LexisNexis 2023) 5.
- 112
United States of America v GoodRx Holdings, Inc. 23-cv-00460 (ND CA District Court 2023) (United States).
- 113
16 CFR § 318 (2023) (United States).
- 114
Justin Sherman, ‘Data Broker Registries in Bills: The ADPPA and the DELETE Act’ (Lawfare, 6 June 2023) <https://www
.lawfaremedia .org/article/data-broker-registries-in-bills-the-adppa-and-the-delete-act> accessed 30 April 2024. - 115
Daniel Zeng, Zhidong Cao and Daniel Neill, ‘Artificial Intelligence-Enabled Public Health Surveillance – from Local Detection to Global Epidemic Monitoring and Control’ in Lei Xing, Maryellen L Giger and James K Min (eds), Artificial Intelligence Medicine: Technical Basis and Clinical Applications (Elsevier 2021) 442.
- 116
‘Apple and Google Partner on COVID-19 Contact Tracing Technology’ (Apple Newsroom, 10 April 2020) <https://www
.apple.com /newsroom/2020/04/apple-and-google-partner-on-covid-19-contact-tracing-technology/> accessed 30 April 2024. - 117
Stacey Fisher and Laura C Rosella, ‘Priorities for Successful Use of Artificial Intelligence by Public Health Organizations: A Literature Review’ (2022) 22 BMC Public Health 1, 2.
- 118
ibid.
- 119
Seyed Shahim Vedaei and others, ‘COVID-SAFE: An IoT-Based System for Automated Health Monitoring and Surveillance in Post-Pandemic Life’ (2020) 8 IEEE 188538, 188538.
- 120
Nicole Cloutier, ‘Artificial Intelligence: A Multi-Purpose Tool for Public Health’ (utmb Health, 26 May 2023) <https://www
.utmb.edu /spectre/education-resources /spectre-blog /spectre-blog/2023/05 /26/artificial-intelligence-a-multi-purpose-tool-for-public-health> accessed 30 April 2024. - 121
Zeng, Cao and Neill (n 115) 448.
- 122
Shawn Dolley, ‘Big Data’s Role in Precision Public Health’ (2018) 6 Frontiers in Public Health 1, 5.
- 123
John S Seberger and Sameer Patil, ‘Post-COVID Public Health Surveillance and Privacy Expectations in the United States: Scenario-Based Interview Study’ (2021) 9 JMIR mHealth and uHealth 1, 2.
- 124
ibid 3.
- 125
US Department of Health and Human Services and Office of the National Coordinator for Health Information Technology, ‘2022 Report to Congress’ (2022) 3 <https://www
.healthit .gov/sites/default/files /page/2023-02/2022 _ONC_Report_to_Congress.pdf> accessed 30 April 2024. - 126
ibid.
- 127
Seberger and Patil (n 123).
- 128
Jean O’Connor and Gene Matthews, ‘Informational Privacy, Public Health, and State Laws’ (2011) 101 American Journal of Public Health 1845, 1845.
- 129
ibid.
- 130
GSA, ‘Privacy and Contract Requirements’ (US General Services Administration, 4 January 2024) <https://www
.gsa.gov/reference /gsa-privacy-program /privacy-and-contract-requirements> accessed 30 April 2024; 5 USC § 552a(b) (United States); for the relevant doctrinal test, see Speaker v U.S. Department of Health & Human Services Centers for Disease Control and Prevention 623 F 3d 1371, 1381 (US Court of Appeals 11th Cir 2010) (United States). - 131
E-Government Act of 2002 § 208(b)(1)(A) and (B) (United States).
- 132
CDC Office of Public Health Data, Surveillance, and Technology, ‘Artificial Intelligence and Machine Learning: Applying Advanced Tools for Public Health’ (Centers for Disease Control and Prevention, 3 July 2023) <https://www
.cdc.gov/surveillance /data-modernization /technologies/ai-ml.html> accessed 30 April 2024. - 133
Paul Quinn and Gianclaudio Malgieri, ‘The Difficulty of Defining Sensitive Data – The Concept of Sensitive Data in the EU Data Protection Framework’ (2021) 22 German Law Journal 1583, 1593; Gianclaudio Malgieri and Giovanni Comandé, ‘Sensitive-by-Distance: Quasi-Health Data in the Algorithmic Era’ (2017) 26 Information & Communications Technology Law 229, 233.
- Privacy Protection in Using Artificial Intelligence for Healthcare: Chinese Regulation in Comparative Perspective.[Healthcare (Basel). 2022]Privacy Protection in Using Artificial Intelligence for Healthcare: Chinese Regulation in Comparative Perspective.Wang C, Zhang J, Lassi N, Zhang X. Healthcare (Basel). 2022 Sep 27; 10(10). Epub 2022 Sep 27.
- Health Insurance Portability and Accountability Act (HIPAA) Compliance.[StatPearls. 2026]Health Insurance Portability and Accountability Act (HIPAA) Compliance.Edemekong PF, Annamaraju P, Afzal M, Haydel MJ. StatPearls. 2026 Jan
- A Policy and Practice Review of Consumer Protections and Their Application to Hospital-Sourced Data Aggregation and Analytics by Third-Party Companies.[Front Big Data. 2020]A Policy and Practice Review of Consumer Protections and Their Application to Hospital-Sourced Data Aggregation and Analytics by Third-Party Companies.Rahimzadeh V. Front Big Data. 2020; 3:603044. Epub 2021 Feb 12.
- Surveying Public Perceptions of Artificial Intelligence in Health Care in the United States: Systematic Review.[J Med Internet Res. 2023]Surveying Public Perceptions of Artificial Intelligence in Health Care in the United States: Systematic Review.Beets B, Newman TP, Howell EL, Bao L, Yang S. J Med Internet Res. 2023 Apr 4; 25:e40337. Epub 2023 Apr 4.
- Review Retinal imaging in an era of open science and privacy protection.[Exp Eye Res. 2025]Review Retinal imaging in an era of open science and privacy protection.Gim N, Blazes M, Sánchez CI, Zalunardo L, Corradetti G, Elze T, Honda N, Waheed NK, Cairns AM, Canto-Soler MV, et al. Exp Eye Res. 2025 Jun; 255:110341. Epub 2025 Mar 14.
- AI and data protection law in health - Research Handbook on Health, AI and the L...AI and data protection law in health - Research Handbook on Health, AI and the Law
Your browsing activity is empty.
Activity recording is turned off.
See more...