Legal challenges for the implementation of advanced clinical digital decision support systems in Europe
Systems based on artificial intelligence and machine learning that facilitate decision making in health care are promising new tools in the era of ‘personalized’ or ‘precision’ medicine. As the volume of patient data and scientific evidence grows, these computerised decision support systems (DSS) have great potential to help healthcare professionals improve diagnosis and care for individual patients. However, the implementation of these tools in clinical care raises some foreseeable legal challenges for healthcare providers and DSS-suppliers in Europe: How does the use of complex and novel DSS relate to professional standards to provide a reasonable standard of care? What should be done in terms of testing before DSS can be used in regular practice? What are the potential liabilities of health care providers and DSS companies if a DSS fails to function well? How do legal requirements for the protection of patient data and general privacy rights apply to likely DSS scenarios? In this article, we provide an overview of the current law and its general implications for the use of DSS, from a European perspective. We conclude that healthcare providers and DSS-suppliers will have the best chance of meeting legal challenges if: they are first tested in translational research with the patients' explicit, informed consent; DSS-suppliers and healthcare providers are able to clarify and agree on their individual legal responsibilities, and; patients are properly informed about privacy risks and able to decide themselves whether their data can be used for other purposes, or are stored and processed outside the EU. DSS developers and healthcare providers will need to work together closely to ensure compliance with national and European regulations and standards required for reasonable and safe patient care.
Relevance to patients: Advanced digital decision support systems have the potential to improve patient diagnosis and care. In this article we discuss key legal issues to support translational research using DSS and ensure that they meet the high standards for protection of patient safety and privacy in Europe.
[1] Berner ES, Lande TJL. Overview of Clinical Decision Support Sys tems. In: Clinical Decision Support Systems [Internet] Springer, New York, NY; 2007 p. 3–22. (Health Informatics).
[2] Middleton B, Sittig DF, Wright A. Clinical Decision Support: a 25 Year Retrospective and a 25 Year Vision. Yearb Med Inform 2016;S103–16.
[3] <https://deepmind.com/applied/deepmind-health/>
[4] <https://www.ibm.com/watson/health/value-based-care/enable
effective-care/>
[5] Hempel D. Oncoguide System- a Computerized Interactive Assis tance System for the Diagnosis and Treatment of CML / MPN and MDS. Blood 2015;126:5145–5145.
[6] Goodman KW. Ethical and Legal Issues in Decision Support. In: Clinical Decision Support Systems [Internet] Springer, Cham; 2016 [cited 2017 Aug 21]. p. 131–46. (Health Informatics). Avail able from: https://link.springer.com/ chapter/10.1007/978-3-319-31913-18
[7] Shneiderman B. Opinion: The dangers of faulty, biased, or mali-cious algorithms requires independent oversight. Proc Natl Acad Sci 2016;113:13538–40.
[8] Goodman (n 6) 133.
[9] See HR 9-11-1990, ECLI:NL:PHR:1990:AC1103 (Speeckaert/-Gradener).
[10] The test in England and Wales is ‘the standard of the ordinary skilled man exercising and professing to have that special skill.’; Bolam v Friern Hospital Management Committee [1957] 2 All ER 118 at 121;[1957] 1 WLR 582 at 586.
[11] The Biomedicine Convention is signed by all member states of the Council of Europe, but several European countries did not ratify, such as the United Kingdom, the Netherlands and Belgium.
[12] Regulation of the European Parliament and of the Council (EU) 679/2016 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [2016] OJ L 119/1
[13] Article 29 Data Protection Working Party, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’ (European Commission, 13th Feb 2018)
[14] Article 22 (3) GDPR.
[15] Belard A, Buchman T, Forsberg J, Potter BK, Dente CJ, Kirk A, et al. Precision diagnosis: a view of the clinical decision support systems (CDSS) landscape through the lens of critical care. J Clin Monit Comput 2017;31:261–71.
[16] Belard (n 15) 267
[17] In this regard, an analogy may be made with the discussion of whether the developers and publishers of medical databases can be held li able for defects and inaccuracies in their database; see Adrian Thoro good, Robert Cook-Deegan Bartha Maria Knoppers, ‘Public variant databases: liability?’ (2017) 19 Genetics in Medicine, 838–841.
[18] Goertzel KM. Legal Liability for Bad Software. CrossTalk 2016;23.
[19] Regulation (EU) 2017/745 of the European Parliament and of the Coun cil of 5 April 2017 on Medical Devices. OJ L 117/1 (5 May 2017).
[20] However, the regulation includes important transitional provisions (see Article 120 of the Regulation). These include that ‘[f]rom 26 May 2020, any publication of a notification in respect of a notified body in accordance with Directives 90/385/EEC and 93/42/EEC shall become void’ and that ‘[c]ertificates issued by notified bodies in accordance with Directives 90/385/EEC and 93/42/EEC prior to 25 May 2017 shall remain valid until the end of the period indicated on the certificate, except for certificates issued in accordance with Annex 4 to Directive 90/385/EEC or Annex IV to Directive 93/42/EEC which shall become void at the latest on 27 May 2022’.
[21] Art 51; Rule 11, Annex VIII Medical Devices Regulation.
[22] Art 10 (16) Medical Devices Regulation.
[23] Rule 11, Annex VIII Medical Devices Regulation.
[24] Arts 61-62, Medical Devices Regulation.
[25] Goertzel (n 18) 25.
[26] This would not ‘break the chain of causation’, or, constitute a novus actus interveniens.
[27] See for instance Z v. FINLAND - 22009/93 [1997] ECHR 10 (25 Febru ary 1997).
[28] Regulation of the European Parliament and of the Council (EU) 679/2016 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [2016] OJ L 119/1.
[29] Recital 26 GDPR.
[30] For example, the UK General Medical Council’s guidance on confi dentiality emphasizes that this implied consent may be overridden by an express objection by a patient, and that patient’s should have ready access to information that explains their personal information may be disclosed for clinical audit: General Medical Council, ‘Confidential ity: good practice in handling patient information’ (GMC, Manchester 2017) paras 96-8.
[31] Iacobucci G. Patient data were shared with Google on an “inappropri ate legal basis,” says NHS data guardian. BMJ 2017;357:j2439. The full decision letter from the Information Commissioner to the CEO of the Royal Free can be found at https://ico.org.uk/media/action
[32] Directive 95/46/EC, as implemented in the UK in the Data Protection Act 1998.
[33] Under Article 35, stipulating that, especially when it is likely that data processing results in a high risk to the rights and freedoms of natural persons (think of making use of new technologies and processing health data) ‘(…) the controller shall, prior to the processing, carry out an as-sessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.’
[34] Art. 9 (2) (h) GDPR.
[35] Law on client’s right to electronic data processing in health care (Wet cliëntenrechten bij elektronische verwerking van gegevens in de zorg) of October 5, 2016, Staatsblad 2016, 373. The law entered partly into force on July 1, 2017.
[36] Art 9 (2) (a) GDPR.
[37] Although, if the purpose of processing is scientific research, the pream-ble of the GDPR makes clear that if it is not possible ‘to fully identify the purpose of personal data processing (…) (...) data subjects should be allowed to give their consent to certain areas of scientific research when in keeping with recognised ethical standards for scientific research’. See recital 33 Preamble.
[38] Art 7(4) GDPR.
[39] See recital 157.
[40] See Art 89 GDPR.
[41] Arts 45-6 GDPR. See also recital 101 of its preamble: ‘(…) when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organisations, the level of protection of natural persons ensured in the Union by this Regulation should not be undermined (…)’.
[42] Art 46 (2) (c) (d).
[43] Taylor Wessing LEXOLOGY, EC standard contractual clauses for US data transfers to be scrutinised by the CJEU (Oct 19 2017)
[44] Art 49 (1) (a) GDPR.
[45] Art 49 (1) (f) GDPR.
[46] Arts 9 (4) & 49 (5) GDPR.
[47] However, according to-for instance-a recent Dutch law on patients’ rights regarding electronic data processing, explicit consent is required if patient data are exchanged between health care providers working in different institutions, even when this is solely for the purpose of medical care: : Law on Client Rights regarding Electronic Data Processing in Health Care [Wet cliëntenrechten bij elektronische verwerking van gegevens in de zorg], into force in 2017
