Personal Data Protection in Telemedicine
Abstract
The relevance of personal data protection in telemedicine is predetermined by the rapid development of information technologies in different spheres, including health care. The key issue is that current legal framework for personal data protection does not adequately meet the needs of telemedicine. Rather than facilitating technological development the law creates unreasonable barriers for introducing innovations in health care. Modern information and communication technologies require a free, secure and legitimate information exchange among all actors of telemedicine relationships. The article contains recommendations on improving legislation on personal data for facilitating telemedicine development. The paper mainly focuses on the principles of personal data protection in telemedicine (requirements for informed consent, purposes of processing, special rules for data controllers and data processors, obligations to ensure confidentiality and security etc.). In particular, it is proposed to eliminate the mandatory requirement of written consent for processing special categories of personal data; to establish special grounds for personal data processing in telemedicine purposes; to differentiate the processing of personal data in telemedicine depending on the consent requirement (“without consent” “without consent, but with option to refuse processing”, “with consent”). It is necessary to set the legal status of telemedicine entities and possibly impose special obligations for personal data processing performed by these entities. In addition, it is important to establish industry standards for security of health information systems taking into account specific threats typical to telemedicine technologies. The article also focuses on the Russian legislative approach to health information systems that are crucial for telemedicine. The thesis is supported that legislation in this area should facilitate integration and interoperability of health information systems, expand applicability of these systems and increase the role of patients in management of personal electronic health records. The methodological basis of the research includes analysis of legislation and draft laws on corresponding issues, comparative legal method (in some aspects Russian experience is considered in comparison with experience of the EU and USA) and method of legal modeling (amendments to Russian legislation are proposed).
References
Bainbridge D. (2008) Introduction to Information Technology Law. Trans-Atlantic Publications, 665 pp.
Birnhack M. (2013) S-M-L-XL Data: Big Data as a New Informational Privacy Paradigm (August 15, 2013). Big Data and Privacy: Making Ends Meet 7-10 (Future of Privacy Forum & Center for Internet & Society, Stanford Law School). Available at: http://ssrn.com/abstract=2310700 (accessed 16 August 2016).
Bogdanovskaya I.Yu. (2007) Pravovoe regulirovanie telemeditsiny: opyt SShA [Legal Regulation in E-medicine: Case of US]. Vrach i informatsionnye tekhnologii, no 3, pp. 64-68.
Carlisle G., Whitehouse D., Duquenoy P. (Eds.) (2013) eHealth: Legal, Ethical and Governance Challenges. Springer. XII, 396 pp.
Daly A. (2015) The law and ethics of ‘self-quantified' health information: An Australian perspective. International Data Privacy Law, 5(2), pp 144-155.
Gantt III W. A. H. (Editor) (2015) ABA Health Law Section. E-Health, Privacy, and Security Law, Second Edition, Cumulative Supplement. BNA Books, 538 pp.
Gilroy A., Spontoni C., Llewellyn K., von Diemar U. (2015) Data protection challenges for telemedicine in the EU and US. E-Health Law & Policy. Vol. 2. Issue 8. pp. 12-14.
Hongyang Y., Li J., Li. Xuan, Z. Gansen, Lee S., Shen J. (2006) Secure Access Control of E-Health System with Attribute-Based Encryption. Intelligent Automation & Soft Computing. Vol. 22, no 3, pp. 345-352.
Hordern V. (2015) Will the New EU Data Protection Regulation Facilitate Healthcare Innovation? Chronicle of Data Protection. Available at: http://www.hldataprotection.com/2015/01/articles/international-eu-privacy/will-eu-data-protection-regulation-facilitate-healthcare-innovation/ (accessed 16 August 2016)
Hordern V. (2016) The Final GDPR Text and What It Will Mean for Health Data. Chronicle of Data Protection. Available at: http://www.hldataprotection.com/2016/01/articles/health-privacy-hipaa/the-final-gdpr-text-and-what-it-will-mean-for-health-data/ (accessed 16 August 2016).
Mantovani E., Quinn P. (2014) mHealth and data protection — the letter and the spirit of consent legal requirements. International Review of Law, Computers &Technology. Volume 28, issue 2. pp. 222-236.
Naumov V.B., Savel'ev D.A. (2002) Pravovye aspekty telemeditsiny [Legal Aspects of Telemedicine]. Saint Petersburg: Anatoliya, 107 p. (in Russian)
Santos J. (2015) The Myth of Anonymization: Has Big Data Killed Anonymity? Kantar Health. Available at: http://www.kantarhealth.com/docs/white-papers/the-myth-of-anonymization-has-big-data-killed-an-onymity-.pdf (accessed 16 August 2016).
Savel'ev A. I. (2015) Problemy primeneniya zakonodatel'stva o personal'nykh dannykh v epokhu “Bol'shikh dannykh” (Big Data) [The Issues of Implementing Legislation on Personal Data in the Era of Big Data]. Pravo. Zhurnal Vysshey shkoly ekonomiki, no 1, pp. 43-67.
Shtykova N.N. (2014) Sushchnost' i problemy realizatsii elektronnoy meditsiny (na primere Vladimirskoy oblasti). Meditsinskoe pravo, no 5, pp. 22-27.
Tereshchenko L.K. (2013) Modernizatsiya informatsionnykh otnosheniy i informatsionnogo zakonodatel'stva: monografiya [Updating Information Relations and Information Legislation. Monograph]. Moscow: Institut zakonodatel'stva i sravnitel'nogo pravovedeniya pri Pravitel'stve RF, INFRA-M, 227 p. (in Russian)
Copyright (c) 2016 Law. Journal of the Higher School of Economics

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.













