BIG DATA AND AI IN HEALTH CARE: Ethics and privacy in data management.

by | Jan 31, 2025 | General, ethics and privacy

Big Data and AI are currently transforming the healthcare sector. 

As I explained in my previous article, “The role of artificial intelligence in the medicine of the future: opportunity or threat?” these technologies have the power to improve diagnoses, personalize treatments, and improve the efficiency of the healthcare sector, among other benefits. 

However, the handling of sensitive medical data creates challenges in the field of ethics and privacy that we must consider. 

How could patient data privacy be guaranteed? How could we avoid biases in the data? Who would be responsible for errors made by AI?

 Are there regulations on the use of AI, and should we place limits on the development of AI?

Why is health data privacy so important? 

ethics and privacy marta gs

First, we must keep in mind that a patient, when going to the doctor, whether in a hospital or a medical center, has the right to privacy of his or her data. There is a duty of confidentiality that the physician must ensure is fulfilled if he wants to maintain his good reputation.

If we want to protect this privacy, it is necessary to implement adequate data protection frameworks throughout the entire AI lifecycle, as advised by UNESCO. I am referring to all stages of AI development: data collection, storage, processing, and disposal. 

We should keep in mind that, following digitization in the healthcare sector, a lot of sensitive patient data is stored digitally; this data is very valuable to cybercriminals. 

If, for example, a medical record falls into the wrong hands, it can lead to identity theft, insurance fraud, or some kind of discrimination, such as in the workplace. 

Current challenges in storing and sharing medical records.

Medical records contain diagnoses, treatments, diagnostic images, and much more. However, on frequent occasions, we can be confronted with:

  • Data fragmentation: When the patient has records in different centers, which makes it difficult to obtain all the information on the patient’s health status. 
  • Access problems: Patients and professionals may have access problems due to bureaucratic requirements when trying to access these data. 
  • Security and privacy: The security of healthcare data is very necessary due to the increase in cybercrime. 

Technological alternatives to meet these challenges.

  1. Unified platforms in the cloud. Patients and professionals will be able to access them through appropriate procedures, so that information is always available where it is needed. 
  1. Blockchain technology could provide a secure storage system, and data could only be shared with certain permissions, maintaining the confidentiality of patient information. 
  1. Patient tracking applications: allow patients to keep control of their data at all times, decide who to share it with, and access it from any device. 
  1. Biometric identification system: such as facial recognition or fingerprints, to ensure that only authorized persons access data. 
  1. Artificial Intelligence: useful for organizing, categorizing and analyzing large amounts of medical data, facilitating diagnosis and personalized treatment. 

Example of a medical data breach.

Shields Health Care Group suffered a data breach affecting 2,000,000 individuals in the United States in 2022. 

This company is a Massachusetts-based medical services provider specializing in diagnostic MRI and PET/CT imaging, radiation oncology, and outpatient surgical services. 

The stolen information could be used for social engineering, phishing, scamming and even extortion, as it is quite sensitive data. 

Shields comments that he has seen no evidence that the stolen information has been disseminated in illegal channels or misused.

Cyber Incidents statistic

Global regulations protect medical data. 

  • GDPR (General Data Protection Regulation of the European Union):

It is the world’s most strict privacy and security regulation.  

It came into effect in 2018. 

This regulation details:

– The fundamental rights of individuals in the digital age. 

– The obligations of data processors. 

– The methods for ensuring compliance. 

– The penalties for those who violate the rules. 

Rights of individuals: 

These provide individuals with greater control over their personal data. Such as, for example, the rights to erasure, rectification and “to be forgotten.”

Data processors:

They have to implement appropriate security measures according to the risk involved in data processing.

———————————————————————————————————–

  • HIPAA (Health Insurance Portability and Accountability Act of 1996):

This law protects the use and disclosure of health information that includes a person’s medical information as well as personal data such as name, address, date of birth and Social Security number. 

There are 3 main rules that health care facilities must follow:

  1. Privacy Rule: Sets a standard for the protection of health information and limits when it can be used. 
  2. Security Standard: Protective measures to be implemented to protect confidentiality and integrity.
  3. Breach Notification Rule: Covered entities and business associates will report any privacy “breaches.”

The goals of HIPAA are to: 

Ensure portability of health insurance.

Reduce health care fraud and abuse. 

Ensure the security and privacy of health information. 

To ensure compliance with health information regulations.

———————————————————————————————————–

  • Key regulations in Spain on health data protection. 

Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD – Law 3/2018). 

  • Adapts the GDPR to the Spanish context. 
  • Specifically regulates the processing of health data in the healthcare field. 
  • Reinforces explicit consent for the processing of medical data. 

Law 41/2002, on Patient Autonomy.

  • Regulates the rights and duties of patients with regard to clinical information and documentation.
  • It establishes that access to medical records must be restricted and only allowed to authorized healthcare professionals.

General Health Law (Law 14/1986).

  • Regulates the organization of the health system in Spain.
  • Includes provisions on the confidentiality of patient data.

Specific regulations for electronic medical records.

  • Spain has developed specific standards for digital medical records, guaranteeing the interoperability and security of data in electronic health systems.
Table Regulations

Ethical dilemmas for the use of AI in healthcare.

Data privacy:

Thanks to the evolution and advancement of artificial intelligence in this sector, we have the need to train algorithms with large amounts of health data, which poses major challenges: how to protect patient privacy while harnessing the potential of AI to improve medical care. 

AI systems, especially those that need genetic data or complete medical histories, rely on massive data sets (Big Data) to learn and function. However, these data are personal and sensitive; their collection and use pose significant risks to patient privacy.

Algorithmic biases:

AI algorithms need to be trained on large volumes of medical data. But, if this data does not fairly represent the entire population, AI may generate less accurate diagnoses or predictions for certain demographic groups. 

For example, some studies have shown that some skin disease detection algorithms perform better on fair-skinned patients because they have been trained mostly on images of Caucasian people. If you want to diagnose a person with a darker skin tone, it could lead to misdiagnoses. 

Responsibility:

The implementation and development of Artificial Intelligence (AI) has brought many benefits, but it has also raised complex ethical and legal challenges, especially in issues of liability in case of errors or damage caused by AI systems. 

The responsibility dilemma. For example, an AI system designed to detect cancer in X-rays. If the algorithm makes a mistake in detecting the tumor and the patient does not receive his treatment in time, whose fault is it?

  • The algorithm developer’s? Because he designed the model and trained the AI.
  • The hospital or healthcare institution? Because it decided to implement the tool. 
  •  The doctor who used the AI? Because he could have checked the result against his clinical judgment. 

The answer is not simple and depends on multiple factors, such as the nature of the error, the degree of autonomy of the AI system, the causal relationship between the error and the harm, and the applicable legal framework.

Transparency and explainability:

Complex AI models, such as deep neural networks, in the medical sector present significant challenges due to the lack of transparency and explainability. These models are very accurate in many tasks, but they function as “black boxes,” by which I mean that it is difficult to understand how they arrive at their decisions. 

This raises ethical, legal and practical problems, especially when the decisions affect people’s health and well-being.

How to achieve a balance between Innovation and Privacy?

In a sector such as healthcare, we have the challenge of balancing technological innovation, especially in the field of artificial intelligence (AI), but also with respect for privacy and ethics. 

If we want to achieve this, we need to adopt an approach that combines technical, regulatory and educational measures. What strategies could we implement to achieve this balance?

Strategies to protect privacy and ethics in healthcare AI:

✅ Use of anonymized or pseudonymized data.

One way to use healthcare data to train algorithms without compromising patient identity is through anonymization (removal of personally identifiable information) and pseudonymization (replacement of sensitive data with codes or identifiers that can only be decoded through strict security conditions). 

✅ Implementation of differential privacy systems. 

Consists of introducing mathematical noise into the data, ensuring that no individual information can be identified within the training data set. 

✅ Creation of ethical committees in the development of AI-based medical technologies.

 Decisions such as the design, training, and application of AI in healthcare should be reviewed by multidisciplinary committees that include medical ethicists, healthcare professionals, AI engineers, and patient representatives. 

✅ Education and awareness of the use of AI in healthcare. 

The medical professional community, as well as patients, must understand how AI works and what implications it has on their health decisions.

Controversial cases and good practices.

The implementation of AI in the healthcare sector has left no one indifferent; it has generated benefits and positive advances, but also a lot of controversy. 

Below, I will explain some controversial cases that have highlighted the ethics and privacy of data and also good practices that show how to implement AI in an ethical and responsible manner.  

Controversial cases:

Use of data without explicit consent. 

In 2016, it came to light that the UK’s National Health Service (NHS) had shared data from 1.6 million patients with Google DeepMind for the development of an AI application called Streams, designed to detect kidney disease. 

The problem was that none of the patients were informed or gave explicit consent for the use of their data. A huge uproar was formed due to the lack of transparency and consent, as the data included sensitive patient information.

The UK Information Commissioner (ICO) conducted an investigation and concluded that the NHS had breached data protection law.

Biases in patient prioritization algorithms. 

In Spain, some triage systems (classification of patients according to the urgency of their care) based on AI have been criticized for possible biases in patient prioritization. For example, it has been questioned that they may have favored demographic groups over others, such as the elderly or those with chronic conditions. 

The problem is that, if the algorithms are biased, it could lead them to make unfair or discriminatory decisions.

Best practice:

Dravet Project (Spain). 

This project is led by the Dravet Syndrome Foundation in collaboration with Spanish researchers; they use AI to analyze genetic and clinical data of patients with this syndrome (a rare form of epilepsy). 

Their goal is to improve diagnosis and personalized treatment. 

Privacy and consent: Patients and their families give their explicit consent for the use of the data, and anonymization of the information is ensured. 

Transparency: Researchers communicate clearly with patients about how their data are used and the expected benefits. 

Collaborative approach: The project involves clinicians, geneticists, AI experts and patient families to ensure that solutions are ethical and patient-centered. 

Federated Learning in the MELLODDY project (Europe). 

MELLODDDY (Machine Learning Ledger Orchestration for Drug Discovery) is a European project that uses federated learning to accelerate drug discovery. Where pharmaceutical companies, universities and research centers across Europe collaborate. 

Data privacy: Data from pharmaceutical companies is not shared directly. Instead, local models are trained and then securely combined. 

Multidisciplinary collaboration: It is fostering collaboration between competing companies to advance research without compromising data confidentiality. 

Regulatory compliance: Complies with the EU’s GDPR (General Data Protection Regulation), ensuring that data is handled ethically and lawfully. 

Health Data Hub Platform (France). 

This is a French platform that centralizes anonymized health data to facilitate research and development of AI solutions in medicine. 

Anonymization and security: Data is rigorously anonymized and protected with advanced security measures. 

Transparency and control: Patients are informed about how their data is used and have the option to opt out of the platform. 

Ethical approach: The platform has an ethics committee that checks the use of data and ensures that patients’ rights are respected.

Conclusions.

New technologies such as Big Data and AI have changed the way we live and the benefits we are obtaining with the advancement and development of these technologies are surprising in many professional sectors. 

Specifically, in the healthcare sector, these technologies offer great opportunities to improve healthcare and medical care, allowing increasingly to personalize patient treatments. However, the handling of sensitive data raises ethical and privacy challenges that cannot be ignored. 

The ideal is to strike a balance between innovation and protection of patients’ rights; it seems important to me to exercise sound regulatory frameworks, develop technologies with privacy by design, and encourage transparency in algorithms. 

Achieving ethical and responsible AI in healthcare depends not only on developers and medical institutions, but also on society in general. Patient education and active participation will be key factors in ensuring a future where technology improves our quality of life without compromising our rights. 

Whether AI will be a tool for equality and progress, or a new engine of discrimination, will depend on the decisions made today. 

Are we prepared to handle these technologies in an ethical manner?

Bibliography:

https://www.unesco.org/es/artificial-intelligence/recommendation-ethics?utm_source=chatgpt.com

https://www.keepersecurity.com/blog/es/2024/10/15/the-importance-of-data-security-in-healthcare/#:~:text=Dado%20que%20los%20datos%20m%C3%A9dicos,y%20fraudes%20de%20seguros%20m%C3%A9dicos.

https://www.astera.com/es/knowledge-center/health-data-management-challenges-and-best-practices

https://www.linkedin.com/pulse/almacenamiento-y-uso-compartido-seguros-de-historiales-m%C3%A9dicos-kvidf

chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.boe.es/doue/2016/119/L00001-00088.pdf

https://www.powerdata.es/gdpr-proteccion-datos

https://www.consilium.europa.eu/es/policies/data-protection/data-protection-regulation

https://dravetfoundation.eu/proyectos

https://www.health-data-hub.fr

https://www.ihi.europa.eu/projects-results/project-factsheets/melloddy

Escrito por Marta Gan

Marta Gan, especialista en Big Data, Inteligencia Artificial y Health Data Science en formación.

Artículos Relacionados

How data visualization is transforming healthcare decision making.

How data visualization is transforming healthcare decision making.

In healthcare, data plays a crucial role in decision-making. From hospital management to disease diagnosis, the ability to analyze and understand large volumes of information can make the difference between successful treatment and medical error. However, the amount of data generated daily in hospitals, laboratories and medical devices is overwhelming. This is where data visualization becomes an indispensable tool.

read more