Enabling Secondary Use of Health Data for the Development of Medical Devices Based on Machine Learning
摘要
Medical devices based on machine learning (ML) promise to have a significant impact and make advances in healthcare. This chapter analyzes to what extent data protection law, de lege lata and de lege ferenda, enables the development of ML-based medical devices. A key aspect of this is the processing of health data, which does not originate with the developers but with the healthcare providers. ML-based medical devices are trained with a large amount of health data. According to the current legal situation under the General Data Protection Regulation (GDPR), secondary use of health data is possible in principle (Article 6 (4) GDPR). However, the consentConsent of the data subjects faces certain difficulties, and as the following analysis shows, the development of an ML-based medical device does not necessarily constitute scientific research within the meaning of the GDPR. Therefore, this chapter argues that a separate legal basis is needed. This must be accompanied by technical-organizational measures that safeguard the rights of the data subject to a large extent and should only be allowed if the general public benefits from the research on and/or deployment of the ML-based medical device. In addition, there is a need for infrastructural measures such as the establishment or expansion of intermediary bodies, given the lack of incentives, personnel capacity, and expertise among healthcare providers to share health data with a broad range of interested parties. Furthermore, to ensure a reliable output from ML-based medical devices, standards for data preparation must be established. Finally, this chapter discusses the proposal of the European Health Data Space (EHDS) and briefly examines whether this is a step in the right direction.