The growing availability of data in the healthcare sector has opened a fresh frontier in the industry, generating numerous potential opportunities. Combining modern biomedical investigations with potential new insights derived from large-scale analysis of health data offers the chance to create new products, services, and therapies. It encourages innovation and has the potential to improve treatment protocols.
However, realising these opportunities requires overcoming significant challenges, many of which relate to the transfer and sharing of such highly sensitive information. There’s a complex legal framework surrounding the processes for dealing with data handling and data security. The unlawful use of personal data and breaches of protocols and security can carry heavy financial penalties or even an order to cease the use of the data in question.
PwC Legal can help you in navigating this challenging legal landscape, informing you where the liabilities lie, what is and what isn’t possible, and protecting and advising you from a legal perspective. Our expertise will help place you in the best possible position to take advantage of the potential offered by the data revolution.
Processing and sharing health data is governed by a complex legal framework. The General Data Protection Regulation (GDPR) addresses the use and handling of health data as sensitive personal data. In addition, the European Health Data Space (EHDS) Regulation imposes rules on access to health data by patients, physicians, and researchers, while the Data Governance Act creates a framework for data brokers and data altruism organisations. For connected devices, the Data Act foresees rules on access to data generated by the device and data portability. Lastly, the AI Act imposes rules on the development and use of artificial intelligence in the healthcare sector, for example AI used in medical devices or by hospitals.
This complex framework, however, gives rise to material legal uncertainty for organisations seeking to process health data for secondary purposes. The interaction between the GDPR’s legal bases for processing special category data, the EHDS’s own legal basis provisions, and diverging national research laws creates uncertainty as to which combination of legal bases applies, particularly in cross-border settings.
A related area of ambiguity concerns the boundary between anonymisation and pseudonymisation: the threshold for genuinely anonymising health data remains contested among regulators, courts, and practitioners, even though the EHDS generally requires that only anonymised data may leave a secure processing environment.
PwC Legal can get you ready for the challenges of these Acts; not simply from a compliance point of view but also by helping you spot, at an early stage, any opportunities offered by the framework.
In healthcare, being positioned to make the most of the data revolution is pivotal to your future business success. At PwC Legal, we know the importance of retaining your competitive advantage. We work with you to make sure you’re ready and equipped to benefit from the opportunities that data offers in a way that won’t compromise you legally, now or in the future.
In such a rapidly changing landscape, it’s important to know and follow best practices; PwC Legal can advise you on how to adapt while maintaining the continuity of business operations. We’ll also help you implement the correct data handling system to ensure your compliance.
Data security is vitally important, but accidents can and will happen. In the unfortunate event that there are data breaches -for whatever reason -PwC can supply you with the necessary legal support as you properly notify relevant stakeholders of any breaches and take your next steps.
Where a data breach occurs, organisations must also navigate overlapping notification obligations across multiple regimes - including the GDPR, the Network and Information Security (NIS2) Directive, and the EHDS Regulation (where applicable) -each imposing its own notification timelines and addressees. PwC Legal can help you coordinate these parallel notification duties so that a single incident doesn’t trigger inconsistent or duplicative reporting.
Many of the benefits to come from data stem from working and pooling with partners. However, in the health sector, data can arise from a number of sources, including hospitals and institutions, often with their own compliance requirements and strict constraints on its use. This leads to complex contractual ecosystems, with differentiated rights and obligations for each party. PwC can develop the appropriate answers and assurances to the relevant data holders.
We can also ensure that any acquisition or partnership you make or ecosystem that you build is compliant and that the data is appropriately protected and secured. Furthermore, with the help of our other PwC teams, we can conduct the necessary due diligence to ensure that the provenance of any data you acquire is impeccable.
Realising the full value of health data depends on having the correct contractual and policy documents in place. Data sharing agreements, data processing agreements, licensing arrangements, and internal data governance policies are essential tools to cover the relevant risks associated with collecting, sharing, and analysing health data.
These documents also allocate responsibility between the parties involved - clarifying who is accountable for compliance, security and breach notification obligations - and define the usage privileges that each party has over the health data in question, including any restrictions on further sharing, combinations with other datasets, or use for secondary purposes.
PwC Legal can help you draft, review, and negotiate the contractual and policy framework you need, ensuring that your rights and obligations are clearly documented and that you’re properly protected before you start sharing or using health data.
Many actors in the health sectors are aware of the potential of the EHDS. This initiative is aimed at providing a connected network where patient health data is interoperable and exchangeable across borders for a multitude of players. While the overarching concept underpinning the EHDS is excellent, questions remain around the practical reality of its future implementation.
The EHDS also leaves Member States considerable flexibility in areas such as the structure of health data access bodies, opt-out mechanisms, trusted health data holder designation, and fee structures, which risks reproducing - or even amplifying - the fragmentation the Regulation was designed to overcome. Interoperability across borders is further complicated by the fact that the technical standards underpinning the EHDS are being developed by different standardisation bodies on divergent timelines, requiring organisations to implement provisional solutions while awaiting the finalisation of harmonised specifications.
PwC Legal can assist hospitals, universities, institutions, and research centres with a smooth transition to the EHDS. We’ll guide you through the implementation process and advise you on any changes you may need to make to remain compliant.
The use of AI applications is growing in importance in the healthcare sector, with applications in areas as diverse as accelerating drug research and improving disease screening. Companies need to embrace this reality in order to survive and evolve for the new markets being created.
This also requires companies to be compliant with the AI Act, especially as several AI systems used in the healthcare sector are classified as high-risk AI systems that are subject to a strict set of compliance obligations under the act.
PwC Legal has extensive experience on data-related initiatives for pharmaceutical companies, hospitals, local governments, and European institutions in the healthcare sector. Together with technology, cybersecurity, and life science consultants from PwC Belgium, PwC Legal takes an integrated approach to obtain a holistic view of risks and mitigation measures throughout the project.
In practice, this is a seamless approach. PwC Legal outlines your legal requirements while PwC cybersecurity experts advise you on which measures to implement. PwC forensic experts help investigate a data breach while PwC Legal assists you to draft, file, and follow up the data breach notification with the relevant authorities. And PwC AI experts show you how your patient data—processed using powerful AI techniques—can revolutionise your research while PwC Legal protects your interests by ensuring the data in question can be used lawfully and that you acquire full ownership of the potential outcomes of your research.
If you want to know more about our insights into the health data environment, read our thought leadership pieces.