Category: Health law

Covid-19

Covid-19 mini-series | Legal advice for Switzerland Privacy, Health & Technologies

With Covid-19, the world is facing a huge crisis and the economy will be massively impacted.

New coronavirus, known as “Covid-19“, spreads itself from China (Wuhan province) to Europe, and then to the world leading to unprecedented measures from authorities in various countries, including Switzerland. Public health issues combine health law, protection of personal data & Privacy and the use of new technologies to fight and help during this tough historical time. Remote work and the use of online conferencing tools has flourished and turned from B2B to B2C with down sides of using online tools in an urgency mode without proper diligence.

To support as much as we can on providing useful information, we have started a legal mini-series, including tips and downloadable documents for business and organizations. This series of guidance and materials aim at providing simple and practical information to better understand and tackle legal issues and economic repercussions due to the coronavirus.

Both public and private organisations are suffering. We intend to publish regular posts on our LinkedIn page and our dedicated Covid-19 website on datalex, our new digital legal platform for organizations seeking legal advice and services.

_______________________________

ABOUT OUR MINI LEGAL SERIES 

We are committed to providing legal advice and guidance to individuals and companies in connection with Covid-19.  As usual, this series is bilingual (FR/EN) with some episodes in Italian!  The first episode provides information on the application of the law on epidemics and its federal ordinance. For the other ones, here is the list of our episodes:

Episode 1Federal Act on Epidemics

Episode 2: Telemedicine & Law

Episode 3: Criminal sanctions: what are the risks?

Episode 4: Ethics guidelines: rules for triage of patients in intensive care units

_______________________________

DATA PRIVACY PERSPECTIVE FOR SWITZERLAND / GERMANY / BELGIUM

To provide further legal guidance on technology and data protection to businesses, we regularly participate webinars with law firms around the world that are part of the PrivacyRules network on data privacy matters. We have started with the following webinar in 4 parts, in collaboration with German and Belgian experts for comparative data protection considerations between these three countries.

Part 1What Data Protection Authorities are saying

Part 2Challenges and possible solutions

Part 3Top tips and advice for organizations

Part 4 What may happen post-Covid-19

Note that the episodes of this webinar are in English only.

_______________________________

IMPACT ON THE ECONOMY

While Switzerland’s historic decision to limit events to a maximum of 1,000 people intends to reduce the risk of the virus spreading, it has a major impact on event organisers and other sectors of industry. Employers have to deal with teleworking solutions and implement health and remote work policies and deal with travel and distance restrictions. Employers also need to ensure that they do not interrupt the supply of goods, and have to potentially deal with contract termination or damages for non-performance. This includes, where necessary, to invoke force majeure or reject force majeure arguments from suppliers who are under the impossibility to deliver their services.

The economic repercussions in Switzerland and around the world are enormous. The Watches and Wonders exhibition decied to cancel the event on 27 February 2020. After this, the lucrative Geneva International Motor Show (GIMS), took the same path on 28 February 2020. After this, the famous Cully Jazz Festival had to accounce cancellation of its 2020 Edition on March 10, 2020. The organisers of this festival declared that, except with donation and external financial support and given the considerable losses, this cancellation may jeopardise future editions.

When it came to Italy deciding on 9 March 2020 to quarantine the country, the EU population was in shock, realizing the seriousness of the facts. France decided to limit the events to a maximum of 1000 people. In Spain, the World Mobile Exhibition in Barcelona cancelled the event, which was expecting more than 110k visitors. Such event would generate around 492 million euros in local economic spin-offs, as well as more than 14,000 jobs. The same happened to the Formula 1 Chinese Grand Prix. Originally scheduled for April 19 2020 in Shanghai, they decided to postpone it.

A list of all the episodes in this series can be found on the publications page of this blog or on the dedicated page on datalex.ch.

_______________________________

FEDERAL vs CANTONAL COMPETENCES

On 28 February 2020, the Federal Council decided by means of a federal ordinance to ban large scale events involving more than 1,000 people. This decision resulted from the outbreak of the “Covid-19”. This is a measure that is normally under the responsibility of the cantons. However, in special emergency situations, the government must protect the population against communicable diseases.  In those case, the Swiss Confederation may enact measures by means of a federal ordinance. It has used such power to limit the gathering of people. Furthermore, the Federal Office of Public Health (‘FOPH’) explained, in a press release dated 28 February 2020, the different situations that can arise when dealing with a contagious disease that endangers public health.

(1) In normal situations

The cantons are competent to put in place the necessary measures to protect the population. These consist of quarantine and isolation measures.

(2) In special situations

The Federal Council may encroach on the autonomy of the cantons. This may be the case where: (a) the cantons can no longer exercise their prerogatives or take appropriate measures, should there be a (i) high risk of infection and spread to the population, a (ii) risk to public health or (iii) to the economy. This may also be the case if (b) the World Health Organization (WHO) declares an international health emergency threatening Switzerland.

(3) Extraordinary situations

They arise in the event of an “extraordinary threat to public health“. In such circumstances, the Federal Council may issue federal ordinances without the need for a legal basis in order to take rapid and targeted actions applicable to all Switzerland. The cantons may still have some room to implement them or to issue stricter rules. Pandemic situations may be considered as extraordinary situations, which the Federal Council may invoke to use its overriding powers.

By Gabriel Avigdor | NTIC.ch

Revision of the Swiss Data Protection Act: Conference for HCPs

This Thursday 24 October 2019, I will have the pleasure to present the current state of the revision of the Swiss Federal Data Protection Act (DPA), as currently discussed at the Federal Parliament. I will be discussing the consequences for doctors in private practice in a conference organised by FMH Services, at the Hotel Aquatis in Lausanne.

Since the GDPR become enforceable on May 25, 2018, data protection has become a hot topic and an area concern for many sectors, particularly in the healthcare sector. The various actors, whether healthcare institutions or organizations (HCOs), hospitals, clinics or doctors (HCPs), are particularly sensitive to the changes of the legal framework given the sensitivity of the data processed on a daily basis.

The objective of this conference is to review the updates that will likely pass and be introduced by the total revision of the Swiss Data Protection Act. We will discuss the challenges that doctors will face and the recommendations they will need to receive for preparing to the changes. This will be the opportunity to discuss how the GDPR applies to physicians and HCPs, as well as best practices for the use of technologies by doctors as data controllers of health-related personal data.

The revision of the Swiss DPA aims at strengthening the rights of the individuals, in this case patients, and at aligning on the European data privacy standards. We will examine to what extent the revision fulfils this objective.

________________________________

CONSEQUENCES ON THE DAILY PRACTICE OF HCPS

Generally, the daily practice of HCPs will not change drastically with the new Swiss Data Protection Act and the guidance will remain similar for a physician’s practice to the ones already issued by the Commissioner in the past.

In my previous article on outsourcing medical billing, I mentioned what guidance the Federal Commissioner issued in the context of healthcare, which contains exhaustive recommandations, examples and cases studies on security measures at the medical office, outsourcing, guidance on the use of cloud computing and how to respond to patients exercising their access right to medical records. The Federal Commissioner also issued a guidance on how to deal with data privacy generally at the office.

This being said, the major changes for processing of medical information is relating to the use of new technologies, where the risk for medical secrecy and data protection is the highest. This is also true because a very low number of HCPs are prepared to face digital transformation and have little measures in place or best practices for the use of ICTs. This requires an increased vigilance and diligence from health professionals and physicians to avoid being held liable from a civil or a criminal perspective.

Therefore, security and the application of data privacy principles of patient data at the medical office remains essential because of the increased risks associated with the use of information systems, social media, cloud computing, telemedicine and other similar technologies. In this context, all previous recommendations of the Federal Commissioner remain valid (see below) and must be followed, as must those issued by the Code of Ethics of the Swiss Federation of Physicians.

It should be noted that risks increase with the use of telemedicine systems and unsecured means of communication, as well as in the case of outsourcing (subcontracting) of services, such as invoicing or secretarial services.

________________________________

FINES IMPOSED ON HOSPITALS AND DOCTORS UNDER THE GDPR

In Europe, we have already seen hospitals sentenced by data protection authorities to administrative penalties of several hundred thousand euros.

Since the implementation of the GDPR, most breaches have consisted of deficiencies in appropriate security measures to protect patient data. Similarly, the violation of the duty to set up controls for the rights of access to the same data in patient files has often been the cause of sanctions and breaches by health institutions.

In this respect, the following European decisions are worth mentioning:

  • Portugal: my previous article and comments on the € 400,000.- fine imposed to a Portuguese hospital. Note that in this article, I also discuss other major fines under the GDPR (equifax, Cambridge Analytica) and the very first fine (ICANN) under the GDPR, as well the situation of Swiss hospitals with regard to privacy and data protection and some elements of the current revision of the Swiss Data Protection Act;
  • Pays-Bas: € 460,000 fine imposed to Haga Hospital (Netherlands) for allowing non-authorized access to employees and third parties to the medical record of a local celebrity. The fine was imposed as a result of inapropriate security measures, especially a weak access control mechanisms (art. 32 GDPR) with no double-factor authentication, which was considered the “ABC” of security;
  • Cyprus: € 14,000 imposed to a doctor for publishing health-related information of a patient on Instagram, mentioning the name of the patient without her consent. After investigations, the Data Protection Commissioner of Cyprus also imposed a €5,000 fine to the hospital for not being able to recover the medical record of the patient following an access request.

These examples demonstrate the importance of privacy and security compliance and data protection principles. Those basic principles have to be applied in medical offices and hospitals. Also to guarantee a good control over personal data, it is crucial to apply the principle of privacy-by-design, implement a complete data protection and management program for all types of health actors.

This should include training, rules of conduct for employees and managers, access controls, as well as appropriate organizational and technical measures to avoid data breaches, unauthorized access to personal data, data losses, alteration, and other violations protection. It also remains key, even for micro enterprise and medical offices to have an action plan in the event of a data breach in order to notify the authorities or the patient if necessary. Given those challenges, a light version of an data protection officer (external) would be welcome.

Even if the legal regime of the Swiss DPA will differ from the European sanctions under the GDPR (2% – 4% of the global turnover or €10 – €20 million), these basic rules and principles are essential and must be respected in order. This is key to avoid civil or criminal liability for violation of the Data Protection Act. Also, where applicable, such behavior may infringe the Criminal Code (Art. 321) for violation of medical secrecy.

Now, the Swiss sanctions system only offers the possibility for individuals to initiate a civiel or a criminal proceedings for violation of the Federal Data Protection Act. The maximum penalties amount to CHF 10k. However, the plan with the revision is to increase the level of criminal fine up to CHF 250,000 maximum. This still remains a criminal fine, based on a criminal trial initiated by a plaintiff or a data subject, where the individual will be held liable, excepting the data controller that cannot receive any direct administrative sanction from the Swiss authority.

Find my other articles relating to healthcare:

  • Article on the outsourcing of medical data
  • Non-economic physicians and the consequences of overbilling (in French: “polypragmasie”, in German “Überarztung”)
  • Videoconference: software and medical devices regulation
  • Conference on telemedicine

Conference on telemedicine

On 4 October 2018, I was invited by Planète santé to speak at the assises de la médecine romande on the topic of telemedicine. The title of my conference was:

Telemedicine : legal framework for physicians

The Swiss health forum 2018, including the “assises de la médecine romande”, is global conference and Forum where more thatn 1’000 healthcare professionals and doctors meet and participate during a few days. This forum held a practical conference on the ‘digitalisation of the medical profession‘. I had the pleasure to speak along with Dr Jean-Gabriel Jeannot and other healthcare experts, including lawyers and physicians on digital in the context of healthcare.

Dr Jean-Gabriel Jeannot and I had the pleasure to develop thoughts and highlights challenges with this specialized audience in the context of telemedicine. For those who do not know him, Dr Jeannot is a Swiss physician specialized in internal medicine known for his digital initiatives to medical care, his numerous websites Medicalinfo, Medplus.ch, cabinetmedical.ch and his large amount of articles on his blog hosted by the local newspaper “Le Temps”. He spoke about the practical aspects of telemedicine for physicians, while I tackled the legal part of the topic. I mainly oriented my presentation for global awareness to healthcare professionals and doctors about legal issues which they may not find obvious, while offering practical recommendations.

_____________________

ISSUES RAISED BY TELEMEDICINE

Telemedicine is a wide topic.

Physicians and healthcare professionals have issued a few guidelines. Just to name a few, in the US, the American Telemedicine Association (ATA) and, in Europe, the Standing Committee of European Doctors (CPME) have created a useful documents, containing best practices for telemedicine services and remote healthcare.

Those guidelines are a first step to understand what a telemedicine project requires as a minimum. But a telemedicine project or initiative, may remain very simple (such as online or telephone medical consultations) or become extremely complex. Healthcare remains a heavily regulated environment, where laws are different in each country, with different practices and particularities, especially for cross-border projects. Moreover, there are many other aspects to take into consideration, such as from a regulatory perspective. Other issues relates to how securing contracts with third parties and partners in distant healthcare, how to tackle protection of health data and personal data under local laws, including the GDPR, as well as liability issues and how insurer can recognize distance medical services and reimburse them to  patient and pay doctors.

Structure of my conference

The main points of my talk related to three main pillars:

(1) Acts of telemedicine

The first part consisted in presenting the different acts of telemedicine that healthcare professionals my do. For each act, I have explained the typical contract that needs to be in place, highlighting the problem what issues may arise in each different scenario. A physician may provide four types or acts of telemedicine :

  • teleconsultations, which relate to the distant telephone or videoconferencing to provide a medical evaluation, including e-prescribing;
  • teleexpertise, where one physician instruct another physician that is answering remotely as an expert;
  • teleassistance, which applies in the event a doctor is unable to examine a patient on the site (emergency, distance, etc.) and a third person that is not a doctor assists the patient while communicating with the remote doctor based on his instructions; and
  • telesurveillance, which may involves remote biomonitoring of vital functions of the body, where a doctor is not present, or because there is no need for medical examination directly on the patient.

(2) Legal framework for physicians

The second part of my presentation was about the legal issues of telemedicine for doctors. It consisted in answering to a few questions, such as:

  • does telemedicine require a particular legal framework and how law applies to it?
  • who can practice telemedicine?
  • how to manage protection of health data?
  • telemedicine  and liability: how to minimize the risks?
  • how does the social insurance reimbursement work for telemedicine services?

(3) Recommendations

Finally, the last part had a main goal to provide practical guidelines and checklist for doctors and healthcare professionals, including insurance companies and innovators (start-ups and hospitals).

_____________________

TELEMEDICINE IS NOT A NEW METHOD, BUT A GROWING MARKET

A bit of history. It is not obvious to realize that the practice of medical services remotely is pretty ancient. The system of emergency medical hotline that associations of doctors have set up is a proof of it, as has been working for decades.

We can already find acts of telemedicine provided at the early 20th century.  Since the telephone invention in the late 19th, and television in early 20th century, doctors have provided medical services through different means, such as telephone (ECG and EEG), videoconferences in the context of psychiatry, virtual reality and with more modern tools after the invention of TCP/IP, etc. Four days before 9/11, the famous remote “Lindberg” surgery was a success, which demonstrated that technology could bring promising solutions remotely even to perform extremely sensitive acts of medicine.

In Switzerland, two main centers of telemedicine are in place since early 21st century, created by, and based on the model of, insurance companies such as Medgate and Medi24. These 2 providers mainly offer acts of teleconsultation (medical telephone calls). Other insurer now propose remote medical services, such the software myguide that the CSS insurance company provides to its clients.

Private initiatives, such as “heal-me” ” (“soignez-moi” in French) offer non-synchronized models (compared to synchronized). This online telemedicine platform allow patient to only pay CHF 39.- per consultation, with a assurance to receive a call from a doctor with a timeframe of 60 minutes. If the response takes longer, the medical consultation becomes free of charge, which becomes an incentive for the platform to ensure performance and availability for patients.

With respect to private clinics, the Aevis Victoria Group has massively invested telemedicine with acquisition of 40% of the share in MedGate, the Swiss leader in telemedicine. The Group also increased its participation in “LifeWatch AG” with an IPO in 2017. THis company is specialized in developing tools and devices for distant medicine. The Aevis Victoria Group continues to invest in other institutions or projects in the area.

_____________________

NOW WHAT?

Potential, but a probable slow growth. With such investments, and the potential of telemedicine, this market is likely to grow and complement ordinary medical care. One thing is sure, telemedicine will never replace ordinary physical examinations on patients. But it appears that physicians remain careful with distant medicine, probably for liability matters, or not knowing that most remote medical acts can be reimbursed by social insurances, by not using electronic communications, such as e-mail or text messages, or simply because they do not have the time or the need to change the way the provide healthcare to patient.

There are many ongoing initiatives, but as we saw, regulatory, legal, political barriers and reluctance from doctors. So this market remains full of potential, but is likely to grow slowly before becoming more in the daily practice and complement traditional care.

Some elements to consider. Patients use more electronic communication means. They have few time to go and visit the doctor. Nowadays, it is common that both parents work and struggle to organize to find medical appointments either for themselves or for their kids. They also prefer not to go to the doctor unless it becomes urgent. Sometimes, they even perform medical care on themselves. Now patients change their doctor more easily, or even have not a general physician: therefore telemedicine has all potential to match with a true market.

Now the players arriving with new ideas on the market will have to demonstrate that it is worth it from an economical and quality standpoint, while being able to reduce the costs of healthcare.

But maybe, digital medical office are not so far to come on the market…

To know more:

___________________________________________

You are launching a project in the context of digital health or distant healthcare? If you have questions or want to meet, go and check out our platform and schedule a meeting with us on datalex.

___________________________________________

Abilify connected pill: ethics and privacy aspects of Personal Health Monitoring

ABILIFY MYCITE: A FIRST FDA APPROVAL FOR mHEALTH AND CONNECTED MEDICAL DEVICES

On 13 November 2017, we have probably reached a historical new step in digital health (and mHealth) with this market approval from the FDA for “Abilify MyCite“, the first digital tracking-pill which sends data to your doctor. This connected pill is used to track whether patients sufferring from schizophrenia, bipolar I disorder, and depression have taken their medication, which is used for Personal Health Monitoring (‘PHM‘).

As mentionned by Pharmacytimes:

the approval of the pill and the sensor together represents a first for the FDA

even if the sensor itself that is used along with aripiprazole (substance used for patient suffering from schizophrenia) was first cleared for use by the FDA in 2012. As secondary or side effects, the clinical trials revealed adverse events such as nausea, vomiting, constipation, headache, dizziness, uncontrollable limb and body movements (akathisia), anxiety, insomnia, and restlessness. However, the common adverse events associated with the sensor were related to the patch, and were predominantly skin irritation.

Find more information on the website of the FDA.

________________________________

TECHNOLOGY AND FUNCTIONALITIES – How it works

On the technology side, the sensor embedded into the Ability MyCite pill syncs with a smartphone and sends an alert to the patient’s smartphone. The doctor receives also a notification through the App when the medication is ingested via a patch that is worn on the surface of the skin of the patient. If the patient shares its data with his practitioner, the latter has the ability to monitor whether the patient has ingested properly. According to the US TV channel PBS, researchers are also trying to manufacture ePills that collect and process other body-related data by monitoring internal heat of the body for several days long.

________________________________

TECHNICAL ASPECTS OF THE DEVICE

According to LiveScience, the technical aspects are as follows:

“It’s a partial power source, “the patient becomes the battery”. The pill integrates a silicon chip with a logic circuit and contains copper and magnesium.  The chip’s logic circuit makes a small modulated current — a graph of the current levels would look like a sine wave. Since the human body is conductive, the wearable sensor can pick up the changes. The modulated current can encode ones and zeroes, similar to an FM signal. “It works in a similar way as an EKG,” or electrocardiogram. These machines pick up on changes in electrical current in the body to monitor heartbeats. The wearable sensor does the same thing, though the current is smaller.” The pill is designed to work for only about 3 minutes. That’s just enough time for it to send a signal to the wearable sensor that it should wake up and start gathering data. That saves battery power and allows the wearable sensor to work for a week at a time.

The patch and sensor is manufactured by the company Proteus Digital Health and aripiprazole marketed by Otsuka Pharmaceutical.

________________________________

ETHICS AND LEGAL ISSUES

PATIENT MONITORING AND REDUCING HEALTH COSTS

Personal Health Monitoring (‘PHM ) contains at least two major advantages.

MEDICAL COMPLIANCE – being the “consistency and accuracy with which someone follows the regimen prescribed by a physician or other health professional“. In the context of mental disability, the physician must ensure that the patient suffering from a mental disorder takes the prescribed medication on a regular basis. This may be particularly interesting for patients who may find themselves incapable of making a proper judgement (such as elder people). In the USA, a study from the National center for biotechnology information showed that “an estimated 50% of those who respond well to medications are nonadherent to their treatment regime“. Therefore, medical compliance is also a important challenge for patients who are suffering from a mental illness; and

HEALTHCARE COSTS – which could be reduced if more patients would take their pill properly. Consequences are both medical and financial. When a patient do not or, forgets to, take a pill, or do not follow the treatment as prescribed, his/her health may be worsened and this person may require treatment adjustment, more medicine, another hospitalisation or even a further surgery should there be a need to. In particular, this article indicates that the “loss that the taxpayer incurs when patients fail to take their medication, the cost of which is assumed to be at least $100 billion. According to an American report, these numbers could even be between $100 et $300 billion.

*  *  *
TECHNOLOGICAL ADVANCEMENT: YES.  BUT AT WHAT COST AND
TO WHAT EXTENT DOES THIS REMAIN A PROGRESS?

Although such technological advancement (connected pill to track patient’s medical compliance) is remarkable for healthcare costs reduction, not everybody agrees to it, especially within the medical profession. Moreover, it is legitimate to ask to what extent such technology can constitute a practical improvement, not just a scientific progress.

What value does this progress add for patients, the healthcare system and the society in general? What does it improve, is it better than before? If yes, how and what are the bad sides of it? What is the balance between the bad and good sides of this? Will the benefits for the patient override financial benefits?

Some people already rose their voice and expressed reluctance to Personal Health Monitoring (‘PHM’), which scientists have already looked into and published on this complex topic. (see additional notes on that topic at the end of this article).

Altough a few have called this practice “medical Big Brother (or biomedical Big Brother according to the New York Times), PHM raises a number of ethical questions, which can lead to at least 8 key  points and interrogations:

1. Privacy – for personal health monitoring, two types of privacy aspects can emerge, which are personal privacy and data privacy. This also relates to risk of interference in the private life of the patient by collecting and processing health (sensitive or even biometric) patient data. Is such data processing in compliance with explicit consent of the patient, who may not able to make a proper judgement?  This article describes very well some privacy aspects  that personal health monitoring are raising.

2. Visibility or  obstrusiveness – Visibility appears to refer to “the degree to which a PHM device is noticeable by the user and other individuals, both at home and in public“. In accepting the use of tracking devices for dementia patients, cognitively intact older adults identified ease of use, size and weight as important in accepting a tracking technology. One consider the patient differently, being seen as an ill human being. This may create a risk of discrimination by the society and the person might be more vulnerable;

3. (over)Medicalization – the devices have the effect of reminding the user or occupants of a medical condition in a non-medical environment. The home could be turned into a medical environment or “de facto intensive care unit” as well as creating stigmatization linked to the fact that the person feels under surveillance;

4. Social isolation – the patient monitored will reduce or cease going to the hospital or to see the physician for regular check-ups. Therefore, this could increase patient’s loneliness and social isolation with psychological and medical consequences with a lack of motivation and reduction of the mentality;

5. Autonomy what room remains to the patient with PHM to decide how to take the pill or not? What if the patient wishes to stop taking the pill, for good reasons? Where are we talking about pressure on the patient will?

6. Shame et identity – what consequences could there be on the personality of the patient, who may be perceived by the society as marginal human being, in particular when the treatment is visible?

7. Providing healthcare – with remote care, to what extent does this improve or reduce its effectiveness, especially when the patient does not move him/herself anymore? Is this an efficient manner to treat a patient, shall this remain the exclusive way of doing it or should we combine it with physical appointments?

8. Security and reliability of the technology. This element is obviously central for both privacy and health reasons.

Do these aspects reduce or delete the patient’s responsibility or does it create an over-responsibility? With or without benefits?

How about from an insurance point of view if the patient do not takes the pill while he/she is being monitored with or without worsening of his/her health? Suspension, reduction, cessation of the payment by the insurance or the medical measures? To what extent can the insurance have access to such information or personal health-related data?

________________________________

A PRIVACY PERSPECTIVE?

As this article pointed out, despite huge costs reductions (around 100 billion) and health benefits of this mHealth technology for the healthcare system and patients, patient’s privacy is an area of concern which is even more related to medtech technologies with Big data and IoT (Internet of Things) in the healthcare sector. Combined with the patch worn by the patient, the sensors that are embedded into the pill may provide far more data about the patient than just taking a pill or not.  The device may be used in a way to gather data from the patient’s body, such as the heart rate, how much the patient sleeps, how fit the patient is, etc.

The major concern is the misuse of such sensitive data, which could be used by corporations or government to collect more personal and biometric information about citizens that they had consented to revealing. Furthermore, since the technology has only recently come into the public domain, very few regulations exist to police it, says this article. Misuse for marketing purposes, is one thing. Data breach, criminal intents, or cyberattack on the device itself are another thing with severe consequences for both patients’ health, privacy and reputations of tech and pharma organizations. Further, another study explains that it appears impossible to obtain informed consent from recipients of PHM because full understanding of the implications of using PHM cannot be gained without actually using the technology. Therefore, using the technology without informed consent, may be considered as illegal processing, which creates a vicious circle. This article suggests that piloting methods such as storytelling and prototyping may present a possible solution to this problem and avoid collecting personal data without the proper legal basis for processing.

________________________________

PRIVACY AND INFORMATION SECURITY 

From an EU and Swiss perspective, health-related data (health or biometric) is considered as a special category of personal data that we call “sensitive data“, where the processing is generally prohibited, unless the controller can demonstrate a legal ground for the processing, such as the patient’s explicit consent (art. 9 §2 (a) GDPR, art. 4 al. 5 and 13 al. 1 of the Swiss DPA), the provision of medical services by a health professional tied by a secrecy obligation (art. 9 §2 (h) and 9 §3 of the GDPR) or private overriding interests (art. 13 al. 2 of the Swiss DPA). As one can read in the press almost everyday now, cyberattacks can happen, and a data breach may lead authorities to impose hefty fines, with 4% of worldwide annual turnover according to article 83 of the GDPR, although fines should remain a last resort in the sanction mechanism applied by the authorities. I wrote a note in this article about the envisaged approach with fines and sanction pursuant to the GDPR.

In addition, the doctor would also have to require the patient’s prior explicit consent before sharing, or allowing any third party to access, any sensitive data . See my previous note on recommendations for outsourcing in the context of medical billing for healthcare professionnals.

There are many other obligations under these regulations, which this article does not intend to cover.

________________________________

CONCLUSION

This FDA approval sounds like a very good “signal” to pharmaceutical companies developing connected drugs and advanced digital life science technologies, mHealth and medical devices.  This can improve the life of many patients, while saving costs and improving efficiencies in the treatment.

There is no need for scaremongering. However, remaining careful using the device for the purpose of the treatment, informing the patient and gathering explicit consent, processing only the data that is necessary for the purpose of the treatment, working with ethics and respect for the individual, especially if these patients have a reduced of discernment, are some good steps to ensure the individual’s privacy.

_____________________

To read more on this topic:

  • Mittelstadt, Brent, Ben Fairweather, Mark Shaw and Neil McBride. “The Ethical Implications of Personal Health Monitoring.” IJT 5.2 (2014): 37-60.Web.4Feb.2018.doi:10.4018/ijt.2014070104.
  • Mittelstadt, B., Fairweather, N.B., McBride, N., Shaw, M., 2011. Ethical Issues of Personal Health Monitoring: A Literature Review, in: ETHICOMP 2011 Conference Proceedings, ETHICOMP 2011, Sheffield, UK.
  • Elin Palm, Anders Nordgren, Marcel Verweij and Göran Collste, Ethically Sound Technology? Guidelines for Interactive Ethical Assessment of Personal Health Monitoring, 2013, Interdisciplinary Assessment of Personal Health Monitoring, 105-114.
  • Nordgren, Anders. (2013). Privacy by Design in Personal Health Monitoring. Health care analysis : HCA : journal of health philosophy and policy. 23. . 10.1007/s10728-013-0262-3.
  • Data protection and privacy in connected health, an article from a blog for research and innovation relating to emerging technologies.
  • Information notice  from “Otsuka Pharmaceutical”, the manufacturer of Abilify Mycite.

By Gabriel Avigdor | NTIC.ch

Prescription support software are considered as medical device

Prescription support software is considered as medical device

On 7 December 2017, the European Court of Justice (‘ECJ’) made an important ruling in the French case SNITEM and Philips vs Premier Ministre des Affaires sociales et de la Santé (Case C-329/16). The Court followed its general advocate advice, who issued a non-binding recommendation on 28 June 2017, and defined for the first time under what conditions should medical software (standalone software) be qualified as a medical device pursuant to Directive 93/42/EEC on medical device.

In this decision, the ECJ considers that “software, of which at least one of the functions makes it possible to use patient-specific data for the purposes, inter alia, of detecting contraindications, drug interactions and excessive doses, is, in respect of that function, a medical device within the meaning of those provisions, even if that software does not act directly in or on the human body”. Therefore, software of which specific functions do not have a medical purpose, are not medical device and are out of the scope of the Directive.

__________________

CE marking is sufficient

The Court adds that once the software bears CE marking, a national authority cannot request the software developer to proceed to an additional requirement such as another certification, as CE marking is sufficient.

In this French case, a decree contained an obligation to get a specific certification for prescription support software according to art. L. 161-38 of the French Code of Social Security. The French authority maintained its position that such software cannot be considered as medical device and therefore, would require this specific certification. WRONG, says the ECJ who confirmed that the clear intention of Philips to use this software in the context of healthcare, and for medical use, makes the functions of this software a medical device. Certications issued by the “Haute Autorité de Santé” (‘HAS’) were compulsory and now are now anymore. Even more, the decree will certainly be either cancelled or amended after this ruling.

This is an important decision for the medical software industry and for innovation in that sector to place them on the EU market (and also in Switzerland), as ECJ clarifies that although it remains compulsorily to “bear the CE marking of conformity when it is placed on the market. Once the marking has been obtained, the product, having regard to that function, may be placed on the market and circulate freely in the European Union without having to undergo any additional procedure, such as a new certification”.

This EU ruling is a lightening in the process which will benefit the industry by save time and money when putting medical software on the market. This clarification allows companies to avoid engaging costs as compliance as a measure of prevention. Legally speaking, there may be a possibility for companies that are in the process of getting their medical software certified to stop the process, or even claim for reimbursement if the decree is cancelled or modified and becomes illegal as a result of the ECJ ruling. In addition, it is likely that this decision may have an impact in other Member States of the EU, which would also be transposable, not only for prescription support software, but also for other medical software, or mobile medical Apps.

__________________

Scope of this decision

What is the scope of this decision?

Firstly, this decision applies clearly to prescription support software, but not only. The the ECJ provided criteria that are broad enough for applying to other medical software if the objective pursues a specifically medical objective. This ruling may be applicable by analogy to all medical software with a medical objective, even with no interaction in or on the human body. It is however necessary to proceed to a specific analysis on a case by case basis for each functionality of the medical software or the mobile medical App.

Secondly, this decision also applies to hospitals developing medical software, as these institutions can be software developers even with no commercialisation, as though they are responsible for first placing on the market. It is therefore necessary for hospitals developing medical software or Apps to assess whether it requires complying with the EU medical device Directive.

From a geographic point of view, even if the decision comes from a European authority, it applies to Switzerland, with automatic recognition of CE marking thank to the international convention on mutual recognition in relation to conformity assessment dated 2002 with EU.

Finally, the fact that this ruling is based on the Directive 93/42/EEC will remain valid with its replacement by the EU Regulation 2017/745 on medical device that is going to replace as of 26 May 2020.

__________________

In deeper details – Background of the dispute

The dispute arose in relation to “Intellispace Critical Care and Anesthesia” (ICCA”) software developed by Philips, as this company focuses now into the software and IT projects in relation to the healthcare sector. The functions of the prescription support software makes it possible to use patient-specific data for the purposes, inter alia, of detecting contraindications, drug interactions and excessive doses.

The dispute opposed the national syndicate of medical technological industries (SNITEM in French) and Philips on one hand, against the French Minister of Social and Health Affairs on the other hand. Based on a local decree which imposes prescription support software companies to get a specific certification, the French authority argued that: (a) Philips’ software was not a medical device, (b) requires getting the additional specific certification for prescription support software, and therefore (c) cannot freely put into the market its software on the sole basis of the CE marking.

On the other hand, Philips argued that, its software is a medical device and “the requirement to adapt software to technical standards constitutes a measure having equivalent effect to quantitative restrictions on imports which, overlapping with the certification obligation for medical devices laid down in Directive 93/42, which is applicable to software, does not meet the requirements of necessity and proportionality”.

In other words, Philips claimed that CE marking was sufficient. Philips won the case on this question.

__________________

Challenges of this case and first precedent

The central question of this case is not the certification itself, but the question to know if ICCA software is be considered as a medical device or not in accordance with Directive 93/42/EEC on medical device. This question may appear somehow unoriginal. It is not. If a software is considered as a medical device, regardless of how it is classified, will need to comply with the EU medical device Directive requirements. In the German case Brain Products GmbH vs BioSemi VOF, the ECJ only provided an indirect reference to the criteria for software as a medical device (‘SaaMD’) qualification.  In that case, the ECJ mentioned that fitness Apps would probably not meet the definition of medical device, while software monitoring humain brain activity would.

The Philips case also refers to the MEDDEV 2.1/6 (Commission Guidelines on the qualification and classification of stand-alone software used in healthcare within the regulatory framework of medical devices) as explained by the advocate general in its recommendations dated 28 June 2017.

__________________

CONDITIONS AND EXAMPLES

ECJ reminds that it is not sufficient to use the software in a medical context; it is also necessary that the intended purpose, defined by the manufacturer, is specifically medical. Therefore, two cumulative conditions are necessary to consider a health-related software as a medical device, which are relating respectively to the objective pursued and the action resulting therefrom.

  1. Objective pursued: a medical device must be intended by the manufacturer for use in humans for the purposes, in particular, of the diagnosis, prevention, monitoring, treatment or alleviation of a disease, and the diagnosis, monitoring, treatment, alleviation of or compensation for an injury or handicap;
  2. Action resulting therefrom: ECJ interprets the Directive 93/42/EEC and considers that “although that provision provides that the main action of the medical device ‘in or on the human body’ cannot be obtained exclusively by pharmacological or immunological means, or by metabolism, it does not require such a device to act directly in or on the human body”.

Interesting to notice that, according to the ECJ’s argumentation, the second condition is not decisive. On the contrary, requiring that the action resulting from the device shall produce an effect or works directly in or on the body would mean that software with no effect on the body would not be subject to the Directive, which would be contrary to the intent of the EU legislature.

In the case of prescription support software, the European Court of Justice states (§25) that functions of such software: “that cross-references patient-specific data with the drugs that the doctor is contemplating prescribing, and is thus able to provide the doctor, in an automated manner, with an analysis intended to detect, in particular, possible contraindications, drug interactions and excessive dosages, is used for the purpose of prevention, monitoring, treatment or alleviation of a disease, and therefore pursues a specifically medical objective, making it a medical device within the meaning of Article 1(2)(a) of Directive 93/42”.

SaaMD or not? Examples:

The ECJ provides examples of prescription support software that may or may not be used as a medical device:

  • SaaMD: function that permits the use of data specific to a patient to help his doctor issue his prescription, in particular by detecting contraindications, drug interactions and excessive doses, even though it does not itself act in or on the human body;
  • Not a SaaMD: software for general purposes, when used in a healthcare setting, is not a medical device;
  • Not a SaaMD: software intended to indicate the contraindications mentioned by the manufacturer of that drug in its instructions for use;
  • Not a SaaMD: software that, while intended for use in a medical context, has the sole purpose of archiving, collecting and transmitting data, like patient medical data storage software, the function of which is limited to indicating to the doctor providing treatment the name of the generic drug associated with the one he plans to prescribe.

__________________

OUTCOME OF THIS RULING

After this ruling, there are at least three main take aways:

  • First, medical device regulation applies to functionalities of medical software where two cumulative conditions are met (medical purpose pursued by the manufacturer and the action pursued therefrom), with a focus on the first condition;
  • Second, such regulation only applies to functions of the software which are coded in a way to produce such effect, but do not apply to the source code in its entirety, even if the software has no effect in or on the human body;
  • Third, where the software, for that particular section of the source code, bears CE marking, it benefits from freedom of circulation of goods within the EU [and therefore in Switzerland as well] and can be placed on the market without any further certification or requirement.

__________________

What other consequences for software as a medical device?

When a software is qualified as a medical device, the manufacturer will have to assess its classification based on the degree of risk for the human body (classes from I to III) and will have to comply with its duties to declare Class I software to the regulation authority (national authorities in the EU and Swissmedic in Switzerland). For classes IIa, IIb and class III software, obligations are stricter.

Depending on the conditions that are applicable, there is a materiovigilance requirement (pre-market approval and then post-market surveillance/vigilance) by the manufacturer, as well as product security, quality control and quality assurance management, as well as other standards (such as ISO). For products coming from the EU, once they bear the CE marking, they benefit from the freedom of circulation in Switzerland and vice versa without any pre-market approval.

All standards that apply to medical devices, depending on the degree of risk, but also obligations, restrictions and potential sanctions of the authorities, will mutatis mutandis apply to software as a medical device. This is necessary to guarantee free circulation within the EU of safe and secure products for consumers or patient health.

Want to know more?

Outsourcing medical billing: a matter of transparency

What is required when outsourcing medical invoices to a third party?

_______________________________________________

In healthcare, it is frequent for medical professionals and health institutions to outsource medical billing to a third party. There are many financial and practical advantages to subcontract such service. First, outsourcing can increase efficiency, by reducing the cost of performing these kinds of tasks by the employees. Therefore, it saves work spaces and it is cost-effective, as the service is provided by experts within a company specialized in this area. Second, the responsibility and the costs for investing in this service, the employees’ management, staff training and keeping these skills up to date, are borne by the third party. Finally, one can expect regular reporting services and cooperation from the third party as part of the deal.

Where outsourcing contains many advantages, medical billing must comply with legal obligations, in particular with medical secrecy and data protection regulations, especially if the third party wishes to use the data for another purpose than medical billing. This would be the case if the personal health-related data are used for the supplier’s benefit (such as creating its own creditors and debtors database), or for the benefit of third parties (e.g.: selling the data to insurance companies).

Transferring health data of patients to a third party can infringe medical secrecy and data protection regulations. If the data are not used for the same purpose as for medical invoicing, the Swiss Criminal code (art. 321), the Swiss Federal Data Protection Act (DPA), and cantonal laws protect the medical secrecy by prohibiting undue disclosure without express consent of the patient.

Infringements observed by the Swiss Federal Commissioner

_______________________________________________

The Federal Data Protection and Information Commissioner (FDPIC) recently osbserved that third parties specialized in medical billing are using health data of patients to:

  • create their own database with individual’s solvency to categorize them; and
  • sell the data to third parties (such as health insurances).

According the FDPIC, healthcare professionals must reinforce their obligation to comply with transparency, which he states as follows:

Where healthcare professionals outsource medical billing services to third parties, they shall remain precise and draw attention of the individuals in a clear manner to where and to whom the data would be transferred, and for what purpose the supplier may process such data. This includes in particular using such health-related data to create unrelated databases and potential sales to third parties. In order to comply with this obligation, the healthcare professionals must get the individuals’ express consent“.

Medical secrecy and explicit consent

From a legal perspective, medical personal data – meaning health-related data from an identified or an identifiable individual – are sensitive data. This special category of personal data requires to get the patient’s explicit consent before the processing (art. 4 § 5 DPA), in writing , and before a transfer to a third party for another purpose than for medical invoicing. Therefore, it would be illegal to transfer and use of such data for another purpose without a valid written consent.

This practice complies with both art. 321 of the Swiss Criminal code and art. 10a § 1 let. b of the DPA to the extent the owner of the secret has released the health professional from the medical secrecy.

How do I draft my privacy clause in an outsourcing contract?

_______________________________________________

Among the other contract clauses which are specific to the outsourcing agreement, the contract should at least contain the following:

For outsourcing in Switzerland:

  • a reference to the relevant DPA provisions;
  • a warranty from the billing company to comply with the DPA provisions;
  • a warranty of fulfilment of data protection claims of data subjects;
  • the prior consent of the data controller (health professionals) if the data processor decides to subcontract the service;
  • describe the purpose for the processing of the data;
  • an obligation for the employees, auxiliary personnel, freelancers etc. of the processor to comply with the DPA provisions;
  • an obligation for the data processor to comply with data security obligations;

For cross-border transfers to the third party:

  • If permitted by national law to transfer to a third party based in another country, include a provision to regulate cross-border transfers. If personal data are processed (accessed or transferred) in a country without a sufficient protection level for the processing, the data protection clause shall at least include:
    • an obligation to enter into standard contractual clauses, such as the C2P EU model clauses (or privacy shield, or Swiss transborder data flow agreement);
    • an obligation for the data processor to enter into such standard model clauses with its affiliates located in countries without an adequate protection level;
    • an obligation or the data processor to inform the data controller prior the transfer if the data are being subcontracted, including a right to object, and provide information to the controller about the subprocessors (identity, location) and engage the subprocessor with a contract containing the same level of contractual obligations.
  • For the Swiss Federal commissioner, Swiss Doctor should not allow a third party outside Switzerland to access medical records. If so, the Doctor may infringe medical secrecy which is protected by the Swiss Criminal code and by the DPA.

Practical recommendations

_______________________________________________

According to the FDPIC, it is not sufficient to inform the patient of such processing somewhere in the medical office, or a waiting room. Nor would it be sufficient to add a clause in small letters in a medical consent form. To comply with transparency, the patient shall receive a proper information to allow – or not – the processing on the basis of a written consent. The patient shall do this without any pressure of any kind.

This short note of the FDPIC reinforces the principle of transparency of the processing.

For the patients

This memo is a call for reinforcement of transparency in the healthcare sector. It explains that more supervision will occur in the future in that particular area to protect the individuals’ right to privacy, and from an undue processing when third parties wish to use the data for their own benefit.

As consent is required, the patient may withdraw its consent at any time. In such event, healthcare professionals and any third party using the data will have to stop using them and potentially delete them to comply with the patient’s request.

For healthcare professionals and hospitals

The principle of transparency, which comes from privacy regulations is not new. It is protected by the non-disclosure obligation for healthcare professionals relating to medical secrecy. But even with the consent to disclose medical information, privacy regulations do not allow anyone to use any personal data for whatever purpose. It would be a breach of the DPA and the processing would become illegal.

In practice, doctors and hospitals shall duly inform the patient to allow him/her to validly consent to sharing medical information for other purposes than for medical billing.

The service provider being a data processor, it has to comply with all the data controller (doctors and healthcare professionals) instructions and requirements, and is responsible for the processing, and to comply with the DPA.

To remain cautious, heathcare professionals should ensure that:

with regard to the service provider:

  • it does not use the data for other purposes than for medical billing;
  • it will comply with privacy regulations, as well as medical secrecy, as the service provider is not bound by medical secrecy;
  • include a paragraph for get the data back at any time, at no costs;
  • for cloud computing purposes, use only service providers based in Switzerland, and draft a contractual clause to prohibit any transfer of such data to a subcontractor or a third party outside Switzerland

with regard to the patient:

  • update the consent forms and add a clear clause – separated from medical related acts – to draw the patient’s attention that the processing may be done for other purposes than medical being (and explain which ones);
  • if the data may be used for other purposes than for medical billing:
    • get the consent after having duly informed the patient and before to process the data; or
    • inform the patient of such transfer in order for the patient to give or withdraw its consent on the processing.

For service providers

The Commissioner has not given its opinion on the supplier’s civil responsibility towards the patient for undue processing, or medical secrecy infringement, or both.

In order to protect the service provider for using the data for other purposes than medical billing, it may perform the following:

  • anonymize the data, whichever it will use the data for its own use or to sell the data to third parties. In this case, medical secrecy and privacy laws will not apply;
  • clarify with healthcare professionals for what other purposes it wishes to use the data;
  • request healthcare professionals to ensure, in the outsourcing agreement, that the patient has been informed of the processing validly given its consent to the processing;
  • include a specific exclusion of liability in case of a third party claim (for medical secrecy of privacy infringement);
  • add an indemnification clause for losses it may incur as a result of the breach of privacy laws or medical secrecy.

To go further, see the following notes on the website of the Swiss Federal Commissioner:

  • This note in French, German or Italian on outsourcing in the context of healthcare
  • This note in French, German or Italian on the use of service providers for keeping medical records in the cloud
  • This note in French, German or Italian on security in medical offices
  • Guide on processing of personal data in the context of healthcare

Gabriel Avigdor | NTIC.ch

Cells

Celine case: Bayer not liable for Yasmin contraceptive pills

WHAT THE CASE IS ABOUT

On Wednesday, 21 January 2015, the Swiss-German press reported the verdict handed down by the Swiss Federal Court in the Celine Case, better known to the media as the Yasmin Pills Case. This is a case that created a scandal in the canton of Zurich, as well as at the national level, concerning the use of the latest generation of contraceptive pills in Switzerland. In this case, the Swiss Supreme Court found that Bayer AG did not breach the Swiss Product Liability Act for lack of information in the medication leaflet.

This article outlines the key legal issues relating to drug liability under the Swiss framework and compares the situation between Switzerland and the US in particular from lawsuits perspective involving 4th generation contraceptive pills.

* * *

In 2008, a 16-year-old girl was hospitalized in an emergency and found herself paralyzed following a pulmonary embolism. The consequence was a lack of oxygen leading to severe head injury. Yet it had only been two months since this young woman started taking the contraceptive “Yasmin”, a prescription-based “4th generation” contraceptive pill that many women around the world use. As a result of this serious disability, the young woman represented by her mother, as well as her health insurer, CSS Assurances, brought the case before the courts claiming CHF 5.3 million for tort and CHF 400,000 for moral damage. In the end, the Swiss Supreme Court upheld the previous decisions and dismissed the appeal of the girl and her health insurance, declaring that the drug manufacturer, Bayer AG, could not be held liable. However, Bayer waived its right to claim reimbursement of the appellant’s costs and expenses to Celine, which amounted to CHF 120,000 as a result of the duration of the proceedings, including attorney and courts fees. CSS Insurance did not get this chance.

_____________________

LIMITED INFORMATION DUTY OF THE PHARMACEUTICAL COMPANY

In this case, Bayer was accused of not mentioning in the patient package insert that the risk of undergoing pulmonary embolism was twice as high with the “Yasmin” pill as with other similar contraceptives. In essence, the Federal Court considered, in its judgment of 5 January 2015 (4A_365/2014 and 4A_371/2014 (in German)), that the German pharmaceutical company was not liable for this lack of information for patients, the mere fact that doctors had access to this information being sufficient. The Federal Court pointed out that the placing of a medicinal product on the market and the standards for obtaining the necessary authorisations from Swissmedic for their marketing do not oblige a pharmaceutical company to inform patients of a higher risk than other equivalent products. With regard to prescription drugs, the patient is not in a position to judge the risks involved, so it is up to doctors to evaluate the benefits and risks of the various products on the market to redirect the patient to the appropriate medical treatment.

Thus, the Federal Court acknowledged that the drug was not defective and that the company could not be held liable under the Swiss Federal Product Liability Act (PLA). The “causal liability” mechanism of this law allows the victim of a defective product to claim damages from the manufacturer, without any fault (art. 1 § 1 PLA). However, the product must be considered defective for the manufacturer to be liable for the damage caused.

In particular, the distinctions between manufacturing defects, design defects and presentation defects can be found in the famous “coffee maker case“, where the Supreme court clarifies the causes of a defect for products that have been validly placed on the market.

_____________________

INEQUALITIES IN LOCAL LEGISLATION: COMPARISON BETWEEN SWISS AND US LITIGATION

Market access authorisation framework and liability for defective drugs:

The case of Switzerland

The authority shall grant a market access authorisation for a drug for a renewable period of 5 years and must comply with the legal requirements of the Swiss Federal Therapeutic Products Act (TPA), in particular requiring the approval of Swissmedic.

Market access shall only be granted where a pharmaceutical company:

How the pharmaceutical company decides to label its product and the way in which the information is highlighted in the leaflet are also essential conditions for obtaining such authorisation (Art. 11 § 1 let. f TPA). However, to the extent those conditions are met, the manufacturer cannot be held liable for a defective product, unless its market access
authorisation was not granted properly. The responsibility for defective drug usually extends to suppliers, i.e. distributors and importers, but this excludes the medical liability of doctors or pharmacists.

1) provides evidence that the drug or a manufacturing process is of high quality, safe and effective;

2) holds an authorisation as a manufacturer, importer or wholesaler issued by the competent authority; and

3) has its domicile or its registered office in Switzerland, or has established a subsidiary in Switzerland (Art. 10 TPA).

In summary, the manufacturer’s liability for defective product it is a rather difficult to obtain, especially when a consumer has to pay very large amounts of legal fees and expenses in advance. Therefore, as a result of this case Bayer was not convicted in Switzerland by the Federal Court, which sets a precedent for pharmaceutical companies active in selling 4th generation contraceptive pills.

Situation in the USA

Mass compensation

Since 2013, the German pharmaceutical company has already paid out around USD 1.4 billion in the United States to compensate victims of similar cases by way of settlement in legal proceedings involving a total of more than 6,760 plaintiffs (the figures are not uniform, see the following reports here). These US trials are more broadly related to 3 contraceptive pills “Yaz”, “Yasmin” and “Ocella”. In the USA, the U.S. Food and Drug Administration (FDA), the authority responsible for approving and marketing consumer products, including medicines (which is the equivalent to Swissmedic in Switzerland), must ensure that a drug meets two requirements:

  • Manufacture of safe drugs with precise statements of any potential risks; and
  • Precisely warns under what circumstances the drug may or may not be used.

Le Monde.fr recently mentioned the impressive figure of 15,000 legal actions filed against the pharmaceutical group. The American judicial system allows, thanks to class actions and specific ethical rules on the legal profession (pactum de quota litis), to have a different means of pressure on large companies than in Switzerland where each individual must find their way alone to a long and costly trial.

Position of patient advocates

Pharmaceutical trials in the United States are particularly fascinating for civil law lawyers. For example, the drugwatch website provides information on lawsuits related to pills sold by Bayer and arguments that the attorneys may raise in court against the German manufacturer. The challenges and costs of those trials as well as the risks for manufacturers are so hihg, that some law firms become specialists defending clients in trials for those pills. They do not hesitate to document their willingness to defend the victims with explanatory videos motivating patients to consult and hire them free of charge as long as the pharmaceutical company do not pay anything to compensate any damage caused to them. You can also find links to a free medical assessment form intended for assessing the medical situation of a relative or read sentences such as: “If your loved one has died as a result of using these contraceptives, you may be able to file a wrongful death lawsuit“. There is also an American website specific to the Yaz & Yasmin trials.

On another level related to conspiracy, press articles try to establish a link between FDA members and the German manufacturer. Also from the the FDA we can find reporting risks associated with Beyaz, Safyral, Yasmin and Yaz in highly technical reports.

It’s hard to find your way around in this American romantic universe…!

_____________________

CONCLUSIONS AND LESSONS LEARNED FROM THE SWISS DECISION

The Federal Court’s decision highlights several elements:

  1. A pharmaceutical company is not required to inform patients that its drug presents a higher risk compared to other competing therapeutic products.
  2. The Swiss Supreme Court implicitly confirms the principle that a physician has an obligation to inform the patient of the nature of the risks and the degree of danger associated with taking such a drug. Indeed, the consumer does not have access to the same information as his doctor and is not in a position to make a decision without consulting him and having a free and informed opinion.
  3. Prescription drugs are not treated in the same way as those that do not require them to obtain them. Indeed, when a prescription is mandatory, the doctor must intervene to prescribe the drug in question to his patient, who has the knowledge to refer the patient, supported by a medical record. It is therefore up to the doctor to assess the risk and appropriateness of the patient taking a medicinal product on the basis of information intended for health professionals. The assessment of a pharmaceutical company’s liability for a non-prescription drug would probably be different if the risks are not sufficiently indicated.
  4. Obtaining compensation from the manufacturer of a drug for lack of information is not easy. Where appropriate, and under certain conditions, the civil and/or criminal medical liability of a doctor, or even a pharmacist or other health professionals may be incurred where, as a result of insufficient information, a damage to health occurs which could have been avoided if adequate information had been provided.

The information in the Yasmin pill package insert and contraindications are available on the website of the Swiss Compendium of Medicines.

By Gabriel Avigdor | NTIC.ch