{"id":4582,"date":"2026-09-09T09:24:19","date_gmt":"2026-09-09T07:24:19","guid":{"rendered":"https:\/\/naaia.ai\/?p=4582"},"modified":"2026-09-09T11:08:30","modified_gmt":"2026-09-09T09:08:30","slug":"https-naaia-ai-en-ai-act-gdpr-cra-medical-devices-how-does-european-regulation-protect-patients-fundamental-rights","status":"publish","type":"post","link":"https:\/\/naaia.ai\/en\/https-naaia-ai-en-ai-act-gdpr-cra-medical-devices-how-does-european-regulation-protect-patients-fundamental-rights\/","title":{"rendered":"AI Act, GDPR, CRA, medical devices: how does European regulation protect patients&#8217; fundamental rights?\u00a0"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The rise of digital health technologies opens up new prospects in terms of quality of care, patient management and the efficiency of health systems, while raising major challenges relating to the safety of individuals, data protection, cybersecurity and respect for fundamental rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Faced with these challenges, the European Union has progressively developed a regulatory framework combining sector-specific health regulation, artificial intelligence governance, cybersecurity requirements and the protection of personal data.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond risk management alone, all of these texts pursue a common ambition: enabling the development of trustworthy digital innovation while guaranteeing a high level of protection of health and of the fundamental rights of natural persons.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article sheds light on the main European texts that currently govern the development and use of digital technologies in the healthcare sector.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sector-specific health regulation: the European foundation for trustworthy innovation &nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">European regulation of medical devices supports the development of health technologies by imposing requirements intended to guarantee their quality, safety and performance, while ensuring a high level of protection of the health of patients and users.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It rests primarily on two texts: Regulation (EU) 2017\/745 on medical devices and <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/FR\/TXT\/HTML\/?uri=CELEX:32017R0746#art_2\" target=\"_blank\" rel=\"noreferrer noopener\">Regulation (EU) 2017\/746 on in vitro diagnostic medical devices<\/a>.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1.1. The European regulations applicable to medical devices<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Regulation (EU) 2017\/745 on medical devices<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regulation (EU) 2017\/745 on medical devices (MD), or the Medical Devices Regulation (MDR), governs the placing on the market, the making available and the putting into service of medical devices for human use and their accessories within the European Union.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its scope covers a wide variety of products and may in particular include, depending on their intended purpose and their characteristics:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Medical software; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Patient monitoring systems; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Diagnostic equipment; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Digital therapeutic devices. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The logic of the text is straightforward: medical devices may only be placed on the European market if their manufacturer demonstrates that they offer a sufficient level of safety and performance in light of their intended purpose. This approach continues after the placing on the market, in particular through risk management, post-market surveillance and improvement throughout the device&#8217;s life cycle.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Regulation (EU) 2017\/746 on in vitro diagnostic medical devices<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regulation (EU) 2017\/746 on in vitro diagnostic medical devices (IVD), or the In Vitro Diagnostic Medical Devices Regulation (IVDR), applies to devices intended to be used in vitro for the examination of specimens derived from the human body in order to provide information, and includes in particular:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Laboratory tests; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Diagnostic support tools; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Software analysing biological data; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Solutions based on genetic or biomolecular analyses. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Like the Medical Devices Regulation, the In Vitro Diagnostic Medical Devices Regulation seeks to ensure that the information produced by these devices is sufficiently reliable, accurate and robust to inform medical decisions that may be decisive for patients.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Requirements applicable throughout the life cycle of medical devices<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond their respective scopes, the MD Regulation and the IVD Regulation respond to the same imperative: ensuring that health technologies placed on the European market present an appropriate level of safety, performance and risk control.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To this end, manufacturers must in particular demonstrate:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The identification, assessment and control of risks liable to affect the health and safety of patients; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The safety, the performance and, where applicable, the clinical or diagnostic performance of the device in light of its intended purpose; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The conformity of the device by means of technical documentation detailing its design, its operation and the associated evidence of conformity; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The implementation of a post-market surveillance system enabling the device&#8217;s behaviour to be monitored under real conditions of use; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The continuous collection, analysis and handling of incidents, complaints, user feedback and the corrective actions required throughout the device&#8217;s life cycle. &nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1.2. A framework designed to support digital innovation<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The regulations on medical devices and on in vitro diagnostic medical devices adopt an approach based above all on the medical purpose of the product and on the risks it is liable to present for patients, rather than on the technology used.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Accordingly, software may be qualified as a medical device where it pursues one or more specific medical purposes, such as:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The diagnosis, monitoring, treatment, alleviation of, or compensation for, an injury or disability; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The investigation, replacement or modification of an anatomical structure, a physiological function or a pathological state; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The provision of information obtained from the analysis of human biological samples, in particular in the context of in vitro diagnostic activities. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This approach enables these two regulations to capture a wide variety of digital health innovations as soon as they meet the applicable qualification criteria.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These regulations thus form the sector-specific framework applicable in the field of health, which is complemented by the AI Act, the Cyber Resilience Act and the GDPR with regard to the risks specific to artificial intelligence, cybersecurity and the processing of personal data.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>2. The AI Act: enhanced requirements for AI systems liable to affect people&#8217;s health<\/strong>&nbsp;<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2.1. Health protection as a central objective of the AI Act<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/FR\/TXT\/HTML\/?uri=OJ:L_202401689\" target=\"_blank\" rel=\"noreferrer noopener\">European AI Regulation<\/a> pursues two closely linked objectives: promoting the uptake of human-centric and trustworthy artificial intelligence, while ensuring a high level of protection of health, safety and fundamental rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Health therefore stands out as one of the major public interests protected by the regulation. The European Union recognises that certain AI systems can contribute to diagnosis, support medical decision-making or improve the organisation of care. However, those same systems may also produce errors, biases or decisions with significant consequences for patients&#8217; health, for the care they receive or for the exercise of their fundamental rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The AI Act therefore provides for oversight proportionate to the level of risk presented by each system, with certain uses of AI in healthcare falling within the category of high-risk AI systems.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2.2 A high-risk classification for AI systems liable to affect people&#8217;s health<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The risk-based approach adopted by the AI Act leads to certain uses of AI in healthcare being subject to enhanced oversight where their intended purpose and their potential effects justify their qualification as high-risk AI systems, that is to say systems whose use is liable to adversely affect people&#8217;s health, safety or fundamental rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the field of health, this qualification mainly covers two categories of systems.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">AI systems embedded in medical devices (Annex I) &nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The AI Act considers as high-risk those AI systems that themselves constitute a medical device or an in vitro diagnostic medical device (in accordance with the regulations referred to above), as well as those intended to be used as a safety component of such devices, where they are subject to a third-party conformity assessment procedure.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Indeed, where an AI system fulfils a medical purpose, an error, a design flaw or a malfunction may have direct consequences for patients&#8217; health.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This qualification may in particular concern certain diagnostic support systems, medical image analysis systems, systems for interpreting results, or clinical or therapeutic decision-support systems.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The AI Act thus complements the regulations applicable to medical devices by providing specific safeguards relating to the risks linked to the functioning of artificial intelligence, such as algorithmic bias, lack of transparency or insufficient human oversight.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Systems used in contexts that are particularly sensitive for health (Annex III) &nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond medical devices, Annex III of the AI Act also qualifies as high-risk certain AI systems whose decisions may have a decisive influence on access to care, on the care provided to individuals or on the exercise of their rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is notably the case for systems used to:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Assess eligibility for certain health services or benefits; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Assess risks or set pricing in the context of health insurance; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Prioritise emergency calls; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Assist with the triage of patients in emergency departments. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In these situations, the risk identified by the legislator does not stem solely from a possible technical error. It also stems from the fact that the persons concerned are often in a situation of dependence or particular vulnerability, which may amplify the consequences of an erroneous or discriminatory decision.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The AI Act also extends this logic to certain uses of AI in the context of migration, asylum and border control, in particular where systems are used to assess the health risk posed by a person seeking to enter, or having already entered, the territory of a Member State.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2.3 Enhanced requirements to control AI-related risks<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Where an AI system is qualified as high-risk, the AI Act imposes a set of requirements designed to identify, prevent and mitigate the risks it may present for health, safety and fundamental rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These requirements rest on four main pillars:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A risk management system, covering the system&#8217;s entire life cycle, in order to identify, assess, mitigate and regularly review the risks liable to affect, in particular, the health of natural persons. &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Rigorous data governance, guaranteeing the quality, relevance and representativeness of the datasets used, with particular attention paid to the detection and reduction of biases that may lead to errors or discrimination. &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Appropriate transparency, enabling users to understand the system&#8217;s purpose, its performance, its limitations and the risks associated with its use, so as to take informed decisions. &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Effective human oversight, intended to prevent decisions having an impact on people&#8217;s health from resting exclusively on algorithmic outputs, and to enable potential errors to be identified and corrected. &nbsp;<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>2.4 Prohibited practices to preserve autonomy and protect vulnerable people<\/strong>&nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond the obligations applicable to high-risk AI systems, the AI Act prohibits certain uses considered incompatible with the fundamental values of the European Union, such as AI systems using manipulative or deceptive techniques, or exploiting the vulnerabilities of certain persons, where they are liable to materially distort their behaviour and cause them significant harm, in particular to their physical or psychological health.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This prohibition is particularly relevant in the healthcare sector, given the vulnerability of certain patients linked to their age, a disability, a pathology or their dependence on health professionals or services.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this context, the European legislator sought to prevent uses of AI liable to unduly influence decisions or to exploit the situation of fragility of natural persons, without however prohibiting the use of AI in medical care.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2.5 Enhanced protection for persons affected by AI systems<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond the obligations imposed on high-risk AI systems, the AI Act also introduces several mechanisms aimed at strengthening the protection of persons liable to be affected by the use of an AI system:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The right to explanation of individual decision-making (Article 86): Where a decision is based mainly on the output of a high-risk AI system and produces legal effects or significant consequences for a person&#8217;s health, safety or fundamental rights, that person has the right to obtain clear and meaningful explanations of the role played by the AI system in the decision-making procedure, as well as of the main elements that led to the decision taken. &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The obligation to carry out a fundamental rights impact assessment (Article 27): This obligation, to be fulfilled prior to putting certain high-risk AI systems into service and provided for in particular for certain deployers providing public services, including in the field of health, aims to identify upstream the risks liable to affect the persons concerned and to put in place the measures necessary to prevent or mitigate them. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These safeguards illustrate the approach taken by the European legislator: beyond the safety and performance of systems, the AI Act seeks to ensure that their deployment remains compatible with the protection of fundamental rights and the interests of the persons who are subject to their effects.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>3. The Cyber Resilience Act: how does it articulate with medical device regulation?<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the field of health, the reliability of technologies depends as much on their performance as on their ability to withstand cyber threats liable to affect their functioning, or people&#8217;s health or safety.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/FR\/TXT\/HTML\/?uri=OJ:L_202402847\" target=\"_blank\" rel=\"noreferrer noopener\">Regulation (EU) 2024\/2847 on horizontal cybersecurity requirements for products with digital elements (CRA<\/a>) contributes to this development by strengthening the consideration given to cybersecurity risks.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3.1. An articulation based on the complementarity of regulatory frameworks<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Unlike the AI Act, the CRA does not apply to medical devices and in vitro diagnostic medical devices governed respectively by Regulations (EU) 2017\/745 and (EU) 2017\/746.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This exclusion reflects the European legislator&#8217;s intention to avoid regulatory overlaps where a specific sectoral framework already covers cybersecurity risks at an equivalent or higher level.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA indeed provides that its application may be limited, or even excluded, where other European sectoral rules ensure a comparable level of protection in terms of cybersecurity.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That said, it would be wrong to infer that medical devices escape cybersecurity requirements: these requirements already fall within the regulatory framework applicable to medical devices themselves.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA therefore plays a complementary role by covering certain health-related digital products that fall outside the scope of the medical device regulations, and subjects the most sensitive of them to enhanced requirements.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3.2. Enhanced requirements for certain health-related digital products<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The exclusion of medical devices from the scope of the CRA does not mean that other health technologies escape European cybersecurity requirements.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The regulation forms part of a broader logic aimed at guaranteeing a high level of cybersecurity for all products with digital elements placed on the Union market. As such, it applies to software or hardware products as well as to their remote data processing solutions, including where certain components are placed on the market separately.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the field of health, this definition covers certain products with digital elements that are not qualified as medical devices. Some of them are of particular importance under the CRA insofar as a failure or the exploitation of a vulnerability would be liable to affect the health, safety or data of the persons concerned. The regulation thus subjects certain categories of products to stricter requirements in view of the specific risks they present.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this respect, among the important products with digital elements, Annex III covers in particular personal wearable products intended to be worn on or placed on the human body for health monitoring purposes where Regulation (EU) 2017\/745 or (EU) 2017\/746 does not apply to them, as well as personal wearable products intended to be used by and for children.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The European legislator considers that these products may present particular risks where a vulnerability is exploited. A breach of their cybersecurity may indeed compromise users&#8217; health or safety, affect the functioning of other products or expose personal data.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For this reason, these products are subject to <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/FR\/TXT\/HTML\/?uri=OJ:L_202402847#art_32:~:text=entreprises%20soit%20proportionn%C3%A9e.-,Article%C2%A032,d%E2%80%99%C3%A9valuation%20de%20la%20conformit%C3%A9%20pour%20les%20produits%20comportant%20des%20%C3%A9l%C3%A9ments%20num%C3%A9riques,-1.%C2%A0%C2%A0%C2%A0Le%20fabricant\" target=\"_blank\" rel=\"noreferrer noopener\">more demanding conformity assessment procedures<\/a>, reflecting the level of risk they are liable to present.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The approach taken by the CRA thus illustrates a central idea of the regulation: even where a product is not qualified as a medical device, its importance for people&#8217;s health may justify enhanced cybersecurity oversight. The protection of health therefore depends not only on the regulatory qualification of the product, but also on the consequences that a failure or malicious exploitation could have for its users.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.3 Intervention mechanisms in the face of persistent or emerging risks &nbsp;<\/h3>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">In order to strengthen the protection of people&#8217;s health and safety, the CRA provides for mechanisms allowing intervention where a product with digital elements, although compliant, continues to present a significant cybersecurity risk. Under Article 57, national authorities may in particular act where that risk is liable to affect people&#8217;s health, safety or fundamental rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on the nature and severity of the risk identified, the authorities may impose corrective measures, restrict the making available of the product on the market, or even require its withdrawal or recall.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA thus places cybersecurity within a continuous approach that does not stop at the placing on the market. Manufacturers must therefore remain able to identify, remedy and mitigate new vulnerabilities liable to affect users&#8217; health, safety or rights.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>4. The GDPR: the protection of health data as a pillar of digital trust<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While the AI Act governs the risks linked to the functioning of artificial intelligence systems and the CRA addresses the cybersecurity of digital products, <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/FR\/TXT\/HTML\/?uri=CELEX:32016R0679\" target=\"_blank\" rel=\"noreferrer noopener\">Regulation (EU) 2016\/679 on the protection of natural persons with regard to the processing of personal data (GDPR)<\/a> addresses another essential aspect of digital health: the protection of personal data.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This question is all the more central given that most digital health technologies rely on the collection, analysis and sharing of particularly sensitive information relating to patients.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4.1. Health data: a category of data benefiting from enhanced protection<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR grants particular protection to data concerning health by classifying it among the &#8220;special categories of personal data&#8221;.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This notion refers to all data pertaining to the health status of a data subject which reveal information relating to the past, current or future physical or mental health status of that data subject. It includes in particular:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Information collected in the course of the registration for, or the provision of, health care services; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A number, symbol or particular assigned to a natural person to uniquely identify that natural person for health purposes; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Information derived from the testing or examination of a body part or bodily substance; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Any information concerning a disease, a disability, a disease risk, medical history, clinical treatment or the physiological or biomedical state of the data subject, whether it comes from a physician or another health professional, a hospital, a medical device or an in vitro diagnostic test. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This enhanced protection is explained by the sensitivity of such data as well as by the consequences that inappropriate use could have on privacy, access to care, employment or access to certain services.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4.2. A principle of prohibition accompanied by strictly framed exceptions<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In order to guarantee a high level of protection, the GDPR sets out a clear principle: the processing of health data is, in principle, prohibited.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This prohibition is not, however, absolute. Article 9 provides for several exceptions specific to the health field, allowing the processing of such data where it is necessary and rests on an appropriate legal basis.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Processing necessary for patient care<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Health data may in particular be processed where it is necessary for:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Preventive medicine or occupational medicine, &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The assessment of the working capacity of the employee, &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Medical diagnosis, &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The provision of health or social care or treatment, &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The management of health or social care systems and services. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Such data may be processed only where it is processed by a health professional, or under his or her responsibility, subject to an obligation of professional secrecy provided for by applicable law.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These derogations make it possible to guarantee the continuity and quality of care while maintaining a high level of protection for the persons concerned.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Processing carried out in the public interest in the area of public health<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR also authorises certain processing where it pursues a reason of public interest in the area of public health, in particular for:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protection against serious cross-border threats to public health; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ensuring the quality and safety of health care, of medicinal products and of medical devices. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Processing for scientific research purposes<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Subject to appropriate safeguards, health data may also be used for scientific research, medical research or public health purposes.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This openness reflects the European legislator&#8217;s intention to reconcile innovation and the protection of individuals, by enabling the development of research while preserving individuals&#8217; fundamental rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Derogations extending beyond care and public health alone<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The derogations provided for care, public health or research are not, however, the only situations allowing the processing of health data. The GDPR also authorises such processing under certain specific conditions, in particular:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Where the data subject has given explicit consent for one or more specified purposes; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Where it is necessary for compliance with obligations or the exercise of rights in the field of employment law, social security or social protection, subject to appropriate safeguards for the fundamental rights and interests of the data subject; &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Where it is necessary to protect the vital interests of the data subject or of another person, in particular where the data subject is incapable of giving consent. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Additional national requirements regarding sensitive data<\/em>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, the GDPR allows Member States to provide for additional conditions, or even specific limitations, for the processing of genetic data, biometric data or data concerning health. This option makes it possible to adapt the level of protection to certain national contexts while maintaining the common foundation set by the European regulation.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4.3. Enhanced rights for patients<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR is not limited to regulating organisations that process health data. It also recognises a set of rights enabling data subjects to retain effective control over their information and over the processing carried out.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The right to information and transparency (Articles 12 to 14): Patients must be informed in a clear and accessible manner about the use of their data, in particular about the purposes of the processing, the recipients of the data, the retention period and the rights available to them. &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The right of access, the right to rectification and the right to erasure (Articles 15 to 17): Data subjects may access the data processed concerning them, request the rectification of inaccurate or incomplete data and request, under certain conditions, the erasure of their personal data. &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Rights relating to control over the use of data (Articles 18, 20 and 21): The GDPR also provides for several mechanisms enabling individuals to retain control over the use of their data, such as the right to restriction of processing, the right to data portability and the right to object to certain processing. &nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protection against certain automated decisions (Article 22): Finally, the GDPR provides for specific safeguards where individual decisions are based solely on automated processing, including profiling. This protection is of particular importance in the field of health, where automated decisions may have significant consequences for the fundamental rights, the health or the care of the persons concerned. &nbsp;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusion: towards comprehensive patient protection in the digital age<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In response to the integration of new technologies into the field of health, the European Union has progressively built a regulatory framework combining several complementary texts: the regulations on medical devices and on in vitro diagnostic medical devices, the AI Act, the Cyber Resilience Act and the GDPR.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each addresses a particular dimension of digital health, but all pursue a common ambition: ensuring that technological innovation remains compatible with a high level of protection of people&#8217;s health, safety and fundamental rights.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This evolution reflects a more comprehensive approach to patient protection. Trust in health technologies no longer rests solely on their medical or technical performance, but also on the protection of personal data, the transparency of the AI models used, resilience in the face of cyber threats and the ability to respect the fundamental rights of the persons concerned.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As technologies become more autonomous, more connected and more integrated into care pathways, compliance can no longer be approached in a fragmented manner. For actors in the sector, the challenge now lies in adopting an integrated approach to the governance of artificial intelligence, data and cybersecurity, in order to reconcile innovation, trust and patient protection.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Anticipating Regulatory Overlaps with&nbsp;Naaia<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With&nbsp;Naaia, organizations can structure their compliance efforts by&nbsp;identifying&nbsp;their AI systems, digital use&nbsp;cases&nbsp;and applicable regulations. The platform already enables organizations to document assessments,&nbsp;identify&nbsp;obligations arising from the AI Act and the GDPR, and track related compliance actions. Future CRA integration will also support the identification and management of cybersecurity obligations applicable to products with digital elements.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By centralizing system inventories, use case qualification, obligation&nbsp;management&nbsp;and decision traceability,&nbsp;Naaia&nbsp;helps organizations move from fragmented compliance processes to a more coherent,&nbsp;operational&nbsp;and sustainable digital governance framework.&nbsp;<\/p>\n\n\n<div class=\"naaia-button-wrapper wp-block-naaia-button\">\n\t<a href=\"https:\/\/naaia.ai\/en\/get-a-demo\" class=\"naaia-btn--primary\">\n\n\t\t\t\t\t<img\n\t\t\t\tclass=\"naaia-btn__icon\"\n\t\t\t\tsrc=\"https:\/\/naaia.ai\/wp-content\/themes\/naaia\/assets\/img\/icon-stars.svg\"\n\t\t\t\talt=\"\"\n\t\t\t\taria-hidden=\"true\"\n\t\t\t\twidth=\"16\"\n\t\t\t\theight=\"16\"\n\t\t\t>\n\t\t\n\t\t<span class=\"naaia-btn__label\">\n\t\t\t<span class=\"naaia-btn__label-text\">Get a demo<\/span>\n\t\t\t<span class=\"naaia-btn__label-text\" aria-hidden=\"true\">Get a demo<\/span>\n\t\t<\/span>\n\n\t<\/a>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The rise of digital health technologies opens up new prospects in terms of quality of care, patient management and the efficiency of health systems, while raising major challenges relating to&hellip; <a href=\"https:\/\/naaia.ai\/en\/https-naaia-ai-en-ai-act-gdpr-cra-medical-devices-how-does-european-regulation-protect-patients-fundamental-rights\/\">Lire la suite<\/a><\/p>\n","protected":false},"author":14,"featured_media":4585,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"naaia_last_modified":"","footnotes":""},"categories":[46,88],"tags":[],"class_list":["post-4582","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-governance-blog","category-expert"],"_links":{"self":[{"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/posts\/4582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/comments?post=4582"}],"version-history":[{"count":4,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/posts\/4582\/revisions"}],"predecessor-version":[{"id":4593,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/posts\/4582\/revisions\/4593"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/media\/4585"}],"wp:attachment":[{"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/media?parent=4582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/categories?post=4582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/naaia.ai\/en\/wp-json\/wp\/v2\/tags?post=4582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}