Category: News

Quit-Facebook-WhatsApp-NTIC-2021

WhatsApp forces users sharing data with Facebook: False alarm?

On 4 January 2021, WhatsApp pushed to all its users a notification screen to ACCEPT its updated terms of service (terms of use) and privacy policy (read “privacy notice”). The text displayed on users’ phone is pretty clear: accept to continue using the app or decline and stop using our service. For the time being, users can still say “not now” or continue using the App.

What are the deadlines?

WhatsApp first gave users until 8 February 2021 to decide to continue or quit the App, which was a very tight deadline. The text displayed on the user’s screen mentioned that the new terms would include sharing data with Facebook. As a result, millions of users switched to other so-called more “privacy friendly” apps. Some of them are Signal, Viber, Telegram (US), Olvid (FR) or Threema (CH) among others. After this event and huge users’ reactions, WhatsApp decided to offer a extended deadline until 15 May 2021. This would allow users to take more time to decide to continue or stop using the App.

So, what is this update all about? What are really the changes? Why would users switch or stay with WhatsApp? Are there really any privacy concerns? I will try to provide some response in this blog as a Q&A to make information easily accessible, concise, unambiguous, fair and transparent…Note that I recently moderated a webinar with international experts to discuss the changes to WhatsApp terms of service and privacy policy. Once online, I will share the link at the end of this article.

Covid-19

Covid-19 mini-series | Legal advice for Switzerland Privacy, Health & Technologies

With Covid-19, the world is facing a huge crisis and the economy will be massively impacted.

New coronavirus, known as “Covid-19“, spreads itself from China (Wuhan province) to Europe, and then to the world leading to unprecedented measures from authorities in various countries, including Switzerland. Public health issues combine health law, protection of personal data & Privacy and the use of new technologies to fight and help during this tough historical time. Remote work and the use of online conferencing tools has flourished and turned from B2B to B2C with down sides of using online tools in an urgency mode without proper diligence.

To support as much as we can on providing useful information, we have started a legal mini-series, including tips and downloadable documents for business and organizations. This series of guidance and materials aim at providing simple and practical information to better understand and tackle legal issues and economic repercussions due to the coronavirus.

Both public and private organisations are suffering. We intend to publish regular posts on our LinkedIn page and our dedicated Covid-19 website on datalex, our new digital legal platform for organizations seeking legal advice and services.

_______________________________

ABOUT OUR MINI LEGAL SERIES 

We are committed to providing legal advice and guidance to individuals and companies in connection with Covid-19.  As usual, this series is bilingual (FR/EN) with some episodes in Italian!  The first episode provides information on the application of the law on epidemics and its federal ordinance. For the other ones, here is the list of our episodes:

Episode 1Federal Act on Epidemics

Episode 2: Telemedicine & Law

Episode 3: Criminal sanctions: what are the risks?

Episode 4: Ethics guidelines: rules for triage of patients in intensive care units

_______________________________

DATA PRIVACY PERSPECTIVE FOR SWITZERLAND / GERMANY / BELGIUM

To provide further legal guidance on technology and data protection to businesses, we regularly participate webinars with law firms around the world that are part of the PrivacyRules network on data privacy matters. We have started with the following webinar in 4 parts, in collaboration with German and Belgian experts for comparative data protection considerations between these three countries.

Part 1What Data Protection Authorities are saying

Part 2Challenges and possible solutions

Part 3Top tips and advice for organizations

Part 4 What may happen post-Covid-19

Note that the episodes of this webinar are in English only.

_______________________________

IMPACT ON THE ECONOMY

While Switzerland’s historic decision to limit events to a maximum of 1,000 people intends to reduce the risk of the virus spreading, it has a major impact on event organisers and other sectors of industry. Employers have to deal with teleworking solutions and implement health and remote work policies and deal with travel and distance restrictions. Employers also need to ensure that they do not interrupt the supply of goods, and have to potentially deal with contract termination or damages for non-performance. This includes, where necessary, to invoke force majeure or reject force majeure arguments from suppliers who are under the impossibility to deliver their services.

The economic repercussions in Switzerland and around the world are enormous. The Watches and Wonders exhibition decied to cancel the event on 27 February 2020. After this, the lucrative Geneva International Motor Show (GIMS), took the same path on 28 February 2020. After this, the famous Cully Jazz Festival had to accounce cancellation of its 2020 Edition on March 10, 2020. The organisers of this festival declared that, except with donation and external financial support and given the considerable losses, this cancellation may jeopardise future editions.

When it came to Italy deciding on 9 March 2020 to quarantine the country, the EU population was in shock, realizing the seriousness of the facts. France decided to limit the events to a maximum of 1000 people. In Spain, the World Mobile Exhibition in Barcelona cancelled the event, which was expecting more than 110k visitors. Such event would generate around 492 million euros in local economic spin-offs, as well as more than 14,000 jobs. The same happened to the Formula 1 Chinese Grand Prix. Originally scheduled for April 19 2020 in Shanghai, they decided to postpone it.

A list of all the episodes in this series can be found on the publications page of this blog or on the dedicated page on datalex.ch.

_______________________________

FEDERAL vs CANTONAL COMPETENCES

On 28 February 2020, the Federal Council decided by means of a federal ordinance to ban large scale events involving more than 1,000 people. This decision resulted from the outbreak of the “Covid-19”. This is a measure that is normally under the responsibility of the cantons. However, in special emergency situations, the government must protect the population against communicable diseases.  In those case, the Swiss Confederation may enact measures by means of a federal ordinance. It has used such power to limit the gathering of people. Furthermore, the Federal Office of Public Health (‘FOPH’) explained, in a press release dated 28 February 2020, the different situations that can arise when dealing with a contagious disease that endangers public health.

(1) In normal situations

The cantons are competent to put in place the necessary measures to protect the population. These consist of quarantine and isolation measures.

(2) In special situations

The Federal Council may encroach on the autonomy of the cantons. This may be the case where: (a) the cantons can no longer exercise their prerogatives or take appropriate measures, should there be a (i) high risk of infection and spread to the population, a (ii) risk to public health or (iii) to the economy. This may also be the case if (b) the World Health Organization (WHO) declares an international health emergency threatening Switzerland.

(3) Extraordinary situations

They arise in the event of an “extraordinary threat to public health“. In such circumstances, the Federal Council may issue federal ordinances without the need for a legal basis in order to take rapid and targeted actions applicable to all Switzerland. The cantons may still have some room to implement them or to issue stricter rules. Pandemic situations may be considered as extraordinary situations, which the Federal Council may invoke to use its overriding powers.

By Gabriel Avigdor | NTIC.ch

Conference on telemedicine

On 4 October 2018, I was invited by Planète santé to speak at the assises de la médecine romande on the topic of telemedicine. The title of my conference was:

Telemedicine : legal framework for physicians

The Swiss health forum 2018, including the “assises de la médecine romande”, is global conference and Forum where more thatn 1’000 healthcare professionals and doctors meet and participate during a few days. This forum held a practical conference on the ‘digitalisation of the medical profession‘. I had the pleasure to speak along with Dr Jean-Gabriel Jeannot and other healthcare experts, including lawyers and physicians on digital in the context of healthcare.

Dr Jean-Gabriel Jeannot and I had the pleasure to develop thoughts and highlights challenges with this specialized audience in the context of telemedicine. For those who do not know him, Dr Jeannot is a Swiss physician specialized in internal medicine known for his digital initiatives to medical care, his numerous websites Medicalinfo, Medplus.ch, cabinetmedical.ch and his large amount of articles on his blog hosted by the local newspaper “Le Temps”. He spoke about the practical aspects of telemedicine for physicians, while I tackled the legal part of the topic. I mainly oriented my presentation for global awareness to healthcare professionals and doctors about legal issues which they may not find obvious, while offering practical recommendations.

_____________________

ISSUES RAISED BY TELEMEDICINE

Telemedicine is a wide topic.

Physicians and healthcare professionals have issued a few guidelines. Just to name a few, in the US, the American Telemedicine Association (ATA) and, in Europe, the Standing Committee of European Doctors (CPME) have created a useful documents, containing best practices for telemedicine services and remote healthcare.

Those guidelines are a first step to understand what a telemedicine project requires as a minimum. But a telemedicine project or initiative, may remain very simple (such as online or telephone medical consultations) or become extremely complex. Healthcare remains a heavily regulated environment, where laws are different in each country, with different practices and particularities, especially for cross-border projects. Moreover, there are many other aspects to take into consideration, such as from a regulatory perspective. Other issues relates to how securing contracts with third parties and partners in distant healthcare, how to tackle protection of health data and personal data under local laws, including the GDPR, as well as liability issues and how insurer can recognize distance medical services and reimburse them to  patient and pay doctors.

Structure of my conference

The main points of my talk related to three main pillars:

(1) Acts of telemedicine

The first part consisted in presenting the different acts of telemedicine that healthcare professionals my do. For each act, I have explained the typical contract that needs to be in place, highlighting the problem what issues may arise in each different scenario. A physician may provide four types or acts of telemedicine :

  • teleconsultations, which relate to the distant telephone or videoconferencing to provide a medical evaluation, including e-prescribing;
  • teleexpertise, where one physician instruct another physician that is answering remotely as an expert;
  • teleassistance, which applies in the event a doctor is unable to examine a patient on the site (emergency, distance, etc.) and a third person that is not a doctor assists the patient while communicating with the remote doctor based on his instructions; and
  • telesurveillance, which may involves remote biomonitoring of vital functions of the body, where a doctor is not present, or because there is no need for medical examination directly on the patient.

(2) Legal framework for physicians

The second part of my presentation was about the legal issues of telemedicine for doctors. It consisted in answering to a few questions, such as:

  • does telemedicine require a particular legal framework and how law applies to it?
  • who can practice telemedicine?
  • how to manage protection of health data?
  • telemedicine  and liability: how to minimize the risks?
  • how does the social insurance reimbursement work for telemedicine services?

(3) Recommendations

Finally, the last part had a main goal to provide practical guidelines and checklist for doctors and healthcare professionals, including insurance companies and innovators (start-ups and hospitals).

_____________________

TELEMEDICINE IS NOT A NEW METHOD, BUT A GROWING MARKET

A bit of history. It is not obvious to realize that the practice of medical services remotely is pretty ancient. The system of emergency medical hotline that associations of doctors have set up is a proof of it, as has been working for decades.

We can already find acts of telemedicine provided at the early 20th century.  Since the telephone invention in the late 19th, and television in early 20th century, doctors have provided medical services through different means, such as telephone (ECG and EEG), videoconferences in the context of psychiatry, virtual reality and with more modern tools after the invention of TCP/IP, etc. Four days before 9/11, the famous remote “Lindberg” surgery was a success, which demonstrated that technology could bring promising solutions remotely even to perform extremely sensitive acts of medicine.

In Switzerland, two main centers of telemedicine are in place since early 21st century, created by, and based on the model of, insurance companies such as Medgate and Medi24. These 2 providers mainly offer acts of teleconsultation (medical telephone calls). Other insurer now propose remote medical services, such the software myguide that the CSS insurance company provides to its clients.

Private initiatives, such as “heal-me” ” (“soignez-moi” in French) offer non-synchronized models (compared to synchronized). This online telemedicine platform allow patient to only pay CHF 39.- per consultation, with a assurance to receive a call from a doctor with a timeframe of 60 minutes. If the response takes longer, the medical consultation becomes free of charge, which becomes an incentive for the platform to ensure performance and availability for patients.

With respect to private clinics, the Aevis Victoria Group has massively invested telemedicine with acquisition of 40% of the share in MedGate, the Swiss leader in telemedicine. The Group also increased its participation in “LifeWatch AG” with an IPO in 2017. THis company is specialized in developing tools and devices for distant medicine. The Aevis Victoria Group continues to invest in other institutions or projects in the area.

_____________________

NOW WHAT?

Potential, but a probable slow growth. With such investments, and the potential of telemedicine, this market is likely to grow and complement ordinary medical care. One thing is sure, telemedicine will never replace ordinary physical examinations on patients. But it appears that physicians remain careful with distant medicine, probably for liability matters, or not knowing that most remote medical acts can be reimbursed by social insurances, by not using electronic communications, such as e-mail or text messages, or simply because they do not have the time or the need to change the way the provide healthcare to patient.

There are many ongoing initiatives, but as we saw, regulatory, legal, political barriers and reluctance from doctors. So this market remains full of potential, but is likely to grow slowly before becoming more in the daily practice and complement traditional care.

Some elements to consider. Patients use more electronic communication means. They have few time to go and visit the doctor. Nowadays, it is common that both parents work and struggle to organize to find medical appointments either for themselves or for their kids. They also prefer not to go to the doctor unless it becomes urgent. Sometimes, they even perform medical care on themselves. Now patients change their doctor more easily, or even have not a general physician: therefore telemedicine has all potential to match with a true market.

Now the players arriving with new ideas on the market will have to demonstrate that it is worth it from an economical and quality standpoint, while being able to reduce the costs of healthcare.

But maybe, digital medical office are not so far to come on the market…

To know more:

___________________________________________

You are launching a project in the context of digital health or distant healthcare? If you have questions or want to meet, go and check out our platform and schedule a meeting with us on datalex.

___________________________________________

Episode III: Privacy Shield – suspension until 1 September 2018 ?

Suspension of the Privacy Shield until 01 September 2018 ?

According to this press release dated 12 June 2018, Members of the EU Parliament (MEP) have suggested to the EU Commission to suspend the Privacy Shield as it does not offer an adequate level of protection for the EU citizen. Therefore, the MEP ask the Commission to:

  1. suspend the data exchange deal unless the US complies with it by 1 September 2018; and
  2. keep suspension until the US authorities comply with its terms in full.

So here we come again: after the Safe Harbor’s invalidation on 6 October 2015, the Privacy Shield is put into question with a clear position from the EU Members of Parliament (MEP) to ask the Commission to suspend the agreement.

In fact, there were already doubts about how the Privacy Shield could actually meet the EU requirement to ensure an adequate level of protection for personal data transferred from the EU to the US, knowing the GDPR would come into force. In addition, the EU Model clauses, which is probably one of the most used tool for cross-border transfer is also put into question by Max Schrems in front of the European court.

(edit 06.07.2018) On 6 July 2018, the EU Parliament just voted, without any changes, a resolution to ask the EU Commission to suspend the Privacy Shield, unless the USA complies with the GDPR (in particular with some principles such as right to portability, privacy by default and by design, etc.), also fearing the consequences of the recent CLOUD ACT in the EU. This is never going to happen in a so short notice from political, economical, legal nor a business standpoint. Not only will the USA have to sit again with the EU to enter into an amendment to the framework, but also 3,000 companies that are part of the framework will have to ensure that they comply with the update to maintain their certification…Probably a nightmare for many companies during this Summer 2018.

So same story again? Well, yes same story, but with a different background and here is why.

________________________________

A little bit of context: what is it about

The Privacy Shield is an international convention clarifying rights and duties of US companies adhering to the Framework, which is supposed to ensure a valid transfer mechanism between US-EU (cross-border data transfer). This means that for any organization that adheres and declares to the FTC that they meet the requirements of the Privacy Shield, with a commitment to maintain the certification, these US companies are considered by the EU Commission as having an adequate level of protection. Therefore, when personal data are transferred from the EU to the US, the processing is valid without any further legal instrument (such as EU C2P/C2C model clauses, BCR, a contract or event consent) (by data ‘transfer’ I mean ‘processing‘ pursuant to the legal definition of art. 4 of the GDPR).

Useful, but dangerous. Why ?

________________________________

Consequences of such suspension

If a company takes the risk to rely only on the Privacy Shield, and not on, or in addition to, another appropriate safeguards (see article 46 of the GDPR), the suspension of this framework means that any cross-border transfer of personal data (= processing of personal data to a State outside the EEA) to the US becomes illegal.

This also means that it constitutes an infringement of the Regulation, with potential measures and sanction as referred to in articles 58, and 83 (5) (c) of the GDPR, and that you may be in breach of your contractual obligations, where you commit to transfer data as a data processor based on a valid mechanism, without backing you up with, let’s say, Model clauses. A data processing clause in a service contract often contains a clause to inform the controller about data breaches. But such contract may also impose the data processor to inform the controller if it becomes non-compliant, such as to ensure that the controller can take appropriate measures relating to the processing. So to avoid being in breach of both the Regulation and your contracts, you would better inform the business and ask your lawyer for some guidance.

Several facts may come into consideration to question the Privacy Shield and its validity. We’ve had other scandals, and obviously the GDPR has become enforceable. It strengthen the data subject’s rights to privacy and put more obligations on processors of personal data. There is also a possibility that the negotiators of the Privacy Shield have underestimated the switch between Directive 95/46/EC and the GDPR in order to satisfy the status quo and be compliant asap with Directive 95/46/EC. So Drafters of the Privacy Shield may have voluntarily, or not, avoided the gap between the two legislation to speed up the process, but also as a compromise. Also, it is worth noting that, at the time of the Privacy Shield becoming a valid instrument, Donald Trump was not elected yet. And it is an euphemism to say that the actual political direction taken by the USA, has changed from Obama’s administration.

________________________________

Recommendations

So what now ? Same story as with the Safe Harbor ? Essentially, yes.

If think you are already GDPR compliant, you should have a record of processing, with a mention of the transfer mechanism for your cross-border data transfer. So easy to find this information without going into all your contracts and check it out. If not, then do it now and you may want to apply some of my recommendations, if you want to follow the compliant path:

  • first check the news. if the Privacy is not declared invalid by the EU Commission, just do nothing. If it becomes invalid, then:
  • check out how many contracts you have that are ONLY relying on the Privacy Shield;
  • perform an assessment based on the criticality (harmfulness and sensitivity of such personal data for data subjects) of the personal data you are handling, transferring. Prioritize and take a decision on what to do with this issue based of your risk assessment;
  • ensure you put in place an appropriate safeguards (art. 46 GDPR). The very best security (but probably to time consuming) is to have two mechanisms in place, in case one of them becomes non-compliant (Privacy Shield or Model clauses);
  • you should inform data subjects that, in case of suspension of the Privacy Shield, and if you only rely on it, that US authorities may access their personal data. You may remind them their rights as data subjects or refer them to your brand new and fresh privacy notice recently updated for GDPR compliance;
  • you should inform your business partners about what you are going to do to address this issue in order to maintain a level a adequacy and avoid contractual liabilities, penalties or even termination. In practice, every one is in the same situation, but you should nevertheless be transparent and discuss this issue to find a rapid solution;
  • On 27 October 2015, I mentioned the recommendations provided by the Swiss Data Protection Commissioner, for entities relying on the Safe Harbor after the Safe Harbor’s invalidation. These recommendations are still valid.
  • On 10 February 2016, just a few months before the GDPR was signed and became law (24 May 2016), I provided some thoughts and recommendations in the context of the unpleasant adventures of data transfer mechanism between the two continents with the arrival of the new Privacy Shield Framework. This article remains also valid.

________________________________

So what next

The Privacy Shield was supposed to replace the Safe Harbor with a better protection of the EU citizens, but it remains a mechanism to allow data transfer with the US.

However, there is slight difference with the Safe Harbor’s invalidation, because we have the GDPR that has entered into force. Compared to Directive 95/46/EC or even national laws, the sanction mechanism is a bit stronger, and ultimately, the fines may be up to a maximum of €20M or 4% of annual turnover as a very last resort (article 83 (5) (c) GDPR), as infringing the provisions relating to data transfer are among the most severe. But everything is explained here on the sanction mechanism.

Last, it is also worth noting that the Standard Contractual Clauses (also called, ‘SCC’ or EU Model clauses) are also put into question by Max Schrems in front of the ECJ. This ruling may lead to an EU decision considering the model clauses are declared invalid for the same reasons as the Safe Harbor and Privacy Shield. The difference with data transfer based on the SCCs, is that such transfer is not limited to transfer to the US, but is a valid mechanism for a transfer to any country outside the EEA. Taking into account that this transfer mechanism is probably used by almost any company doing business with third countries (outside the EEA), the consequences may be dramatic as this article points out. So as a last advice, check what happens in the next couple of months with the SCC’s situation to prepare in case this mechanisms is also declared invalid.

Best of luck!

By Gabriel Avigdor | NTIC

Fines under the GDPR: How a DPA May act as of 26 May 2018

In February 2018, I shared some thoughts in an article titled: ‘3 months before the GDPR – what if you don’t comply? ‘, which intended to explain how the sanction regime under the GDPR may be applied by the data protection authorities (DPA), also indicating that fines may not be the only or preferred root for the authorities in case of non-compliance with Regulation (EU) 2016/679.

As many organizations are looking for answers on what may happen as of 25 May, here is an interesting infographic document designed by the IAPP showing that the approach to fines differs drastically from jurisdictions to jurisdictions.

And the attitude of data protection authorities is likely to have an impact on the way companies are taking the GDPR seriously or not, depending of where they are located, where they operate, offer goods and services, monitor data subjects’ behavior, in front of which data protection authority (DPA) data subjects may issue a complaint, etc.

Here are very different approaches taken from four different DPAs for the day after 25 May 2018:

  • there will be fines, and they will be significant…” (Helen Dixon, Irish DPA);
  • make sure compliance is focused throughout the company, it is a strategic question and has to raise all levels of the company and obey to a strategic decision from the top (Isabelle Falque-Pierrotian, French DPA);
  • “Voluntary compliance is still the preferred route, but we will back that up with tough action where it’s necessary” (Elisabeth Denham, British DPA); or
  • It’s not our first task to fine, it’s our first task to see if you’re compliant, and if you’re not compliant it will be a problem […]” (Andrea Jelinek, Austrian DPA)

These approaches are understandable if you think about what types of companies are located in which country. Many big players including the GAFAM have their data centers in Ireland and are known to have practices or services that have motivated regulators drafting the GDPR. While the French and British approaches seem to focus more on supporting compliance in a pragmatic way, the Austrian approach shows a more relaxed position, further from the Irish one. The naughty, supportive or more relaxed approach may also depend on each member States’ readiness, where a majority of them have not passed their legislative adaptation into their national laws.

You can track each national law exceptions to the GDPR country by country on this page.

Although many people are mentioning 26th of May as the date where effects of the GDPR will occur, the GDPR will apply as of 25 May 2018 (not 24 or 26). Probably 26 is mentioned as “the day after”, because it is probably unrealistic to think that any organizations will receive an audit request, or be contacted by authorities ont that famous day and it takes at least one day to send a letter… Maybe some DPAs have already prepared their letters, audit requests and joint forces for a massive GDPR assault on the data protection beach, but this would be pretty surprising.

Finally, the GDPR institutes a consistency mechanism (referenced in particular in Recitals 135, 136, 138, 150, + article 63 and following), aiming to promote cooperation and align authorities’ approches to the application of the Regulation. This mechanism shall seek, among other goals, for lead and supervisory authorities, the Board and the Commission, to work together for a consistent application of the GDPR, including “to promote a consistent application of administrative fines” (rec. 150). In the course of time, this mechanism and global cooperation with EU authorities may polish these very different approaches to fines. This being said, each country will remain free to tackle privacy issues according to its culture.

Future will tell…

By Gabriel Avigdor | NTIC

Abilify connected pill: ethics and privacy aspects of Personal Health Monitoring

ABILIFY MYCITE: A FIRST FDA APPROVAL FOR mHEALTH AND CONNECTED MEDICAL DEVICES

On 13 November 2017, we have probably reached a historical new step in digital health (and mHealth) with this market approval from the FDA for “Abilify MyCite“, the first digital tracking-pill which sends data to your doctor. This connected pill is used to track whether patients sufferring from schizophrenia, bipolar I disorder, and depression have taken their medication, which is used for Personal Health Monitoring (‘PHM‘).

As mentionned by Pharmacytimes:

the approval of the pill and the sensor together represents a first for the FDA

even if the sensor itself that is used along with aripiprazole (substance used for patient suffering from schizophrenia) was first cleared for use by the FDA in 2012. As secondary or side effects, the clinical trials revealed adverse events such as nausea, vomiting, constipation, headache, dizziness, uncontrollable limb and body movements (akathisia), anxiety, insomnia, and restlessness. However, the common adverse events associated with the sensor were related to the patch, and were predominantly skin irritation.

Find more information on the website of the FDA.

________________________________

TECHNOLOGY AND FUNCTIONALITIES – How it works

On the technology side, the sensor embedded into the Ability MyCite pill syncs with a smartphone and sends an alert to the patient’s smartphone. The doctor receives also a notification through the App when the medication is ingested via a patch that is worn on the surface of the skin of the patient. If the patient shares its data with his practitioner, the latter has the ability to monitor whether the patient has ingested properly. According to the US TV channel PBS, researchers are also trying to manufacture ePills that collect and process other body-related data by monitoring internal heat of the body for several days long.

________________________________

TECHNICAL ASPECTS OF THE DEVICE

According to LiveScience, the technical aspects are as follows:

“It’s a partial power source, “the patient becomes the battery”. The pill integrates a silicon chip with a logic circuit and contains copper and magnesium.  The chip’s logic circuit makes a small modulated current — a graph of the current levels would look like a sine wave. Since the human body is conductive, the wearable sensor can pick up the changes. The modulated current can encode ones and zeroes, similar to an FM signal. “It works in a similar way as an EKG,” or electrocardiogram. These machines pick up on changes in electrical current in the body to monitor heartbeats. The wearable sensor does the same thing, though the current is smaller.” The pill is designed to work for only about 3 minutes. That’s just enough time for it to send a signal to the wearable sensor that it should wake up and start gathering data. That saves battery power and allows the wearable sensor to work for a week at a time.

The patch and sensor is manufactured by the company Proteus Digital Health and aripiprazole marketed by Otsuka Pharmaceutical.

________________________________

ETHICS AND LEGAL ISSUES

PATIENT MONITORING AND REDUCING HEALTH COSTS

Personal Health Monitoring (‘PHM ) contains at least two major advantages.

MEDICAL COMPLIANCE – being the “consistency and accuracy with which someone follows the regimen prescribed by a physician or other health professional“. In the context of mental disability, the physician must ensure that the patient suffering from a mental disorder takes the prescribed medication on a regular basis. This may be particularly interesting for patients who may find themselves incapable of making a proper judgement (such as elder people). In the USA, a study from the National center for biotechnology information showed that “an estimated 50% of those who respond well to medications are nonadherent to their treatment regime“. Therefore, medical compliance is also a important challenge for patients who are suffering from a mental illness; and

HEALTHCARE COSTS – which could be reduced if more patients would take their pill properly. Consequences are both medical and financial. When a patient do not or, forgets to, take a pill, or do not follow the treatment as prescribed, his/her health may be worsened and this person may require treatment adjustment, more medicine, another hospitalisation or even a further surgery should there be a need to. In particular, this article indicates that the “loss that the taxpayer incurs when patients fail to take their medication, the cost of which is assumed to be at least $100 billion. According to an American report, these numbers could even be between $100 et $300 billion.

*  *  *
TECHNOLOGICAL ADVANCEMENT: YES.  BUT AT WHAT COST AND
TO WHAT EXTENT DOES THIS REMAIN A PROGRESS?

Although such technological advancement (connected pill to track patient’s medical compliance) is remarkable for healthcare costs reduction, not everybody agrees to it, especially within the medical profession. Moreover, it is legitimate to ask to what extent such technology can constitute a practical improvement, not just a scientific progress.

What value does this progress add for patients, the healthcare system and the society in general? What does it improve, is it better than before? If yes, how and what are the bad sides of it? What is the balance between the bad and good sides of this? Will the benefits for the patient override financial benefits?

Some people already rose their voice and expressed reluctance to Personal Health Monitoring (‘PHM’), which scientists have already looked into and published on this complex topic. (see additional notes on that topic at the end of this article).

Altough a few have called this practice “medical Big Brother (or biomedical Big Brother according to the New York Times), PHM raises a number of ethical questions, which can lead to at least 8 key  points and interrogations:

1. Privacy – for personal health monitoring, two types of privacy aspects can emerge, which are personal privacy and data privacy. This also relates to risk of interference in the private life of the patient by collecting and processing health (sensitive or even biometric) patient data. Is such data processing in compliance with explicit consent of the patient, who may not able to make a proper judgement?  This article describes very well some privacy aspects  that personal health monitoring are raising.

2. Visibility or  obstrusiveness – Visibility appears to refer to “the degree to which a PHM device is noticeable by the user and other individuals, both at home and in public“. In accepting the use of tracking devices for dementia patients, cognitively intact older adults identified ease of use, size and weight as important in accepting a tracking technology. One consider the patient differently, being seen as an ill human being. This may create a risk of discrimination by the society and the person might be more vulnerable;

3. (over)Medicalization – the devices have the effect of reminding the user or occupants of a medical condition in a non-medical environment. The home could be turned into a medical environment or “de facto intensive care unit” as well as creating stigmatization linked to the fact that the person feels under surveillance;

4. Social isolation – the patient monitored will reduce or cease going to the hospital or to see the physician for regular check-ups. Therefore, this could increase patient’s loneliness and social isolation with psychological and medical consequences with a lack of motivation and reduction of the mentality;

5. Autonomy what room remains to the patient with PHM to decide how to take the pill or not? What if the patient wishes to stop taking the pill, for good reasons? Where are we talking about pressure on the patient will?

6. Shame et identity – what consequences could there be on the personality of the patient, who may be perceived by the society as marginal human being, in particular when the treatment is visible?

7. Providing healthcare – with remote care, to what extent does this improve or reduce its effectiveness, especially when the patient does not move him/herself anymore? Is this an efficient manner to treat a patient, shall this remain the exclusive way of doing it or should we combine it with physical appointments?

8. Security and reliability of the technology. This element is obviously central for both privacy and health reasons.

Do these aspects reduce or delete the patient’s responsibility or does it create an over-responsibility? With or without benefits?

How about from an insurance point of view if the patient do not takes the pill while he/she is being monitored with or without worsening of his/her health? Suspension, reduction, cessation of the payment by the insurance or the medical measures? To what extent can the insurance have access to such information or personal health-related data?

________________________________

A PRIVACY PERSPECTIVE?

As this article pointed out, despite huge costs reductions (around 100 billion) and health benefits of this mHealth technology for the healthcare system and patients, patient’s privacy is an area of concern which is even more related to medtech technologies with Big data and IoT (Internet of Things) in the healthcare sector. Combined with the patch worn by the patient, the sensors that are embedded into the pill may provide far more data about the patient than just taking a pill or not.  The device may be used in a way to gather data from the patient’s body, such as the heart rate, how much the patient sleeps, how fit the patient is, etc.

The major concern is the misuse of such sensitive data, which could be used by corporations or government to collect more personal and biometric information about citizens that they had consented to revealing. Furthermore, since the technology has only recently come into the public domain, very few regulations exist to police it, says this article. Misuse for marketing purposes, is one thing. Data breach, criminal intents, or cyberattack on the device itself are another thing with severe consequences for both patients’ health, privacy and reputations of tech and pharma organizations. Further, another study explains that it appears impossible to obtain informed consent from recipients of PHM because full understanding of the implications of using PHM cannot be gained without actually using the technology. Therefore, using the technology without informed consent, may be considered as illegal processing, which creates a vicious circle. This article suggests that piloting methods such as storytelling and prototyping may present a possible solution to this problem and avoid collecting personal data without the proper legal basis for processing.

________________________________

PRIVACY AND INFORMATION SECURITY 

From an EU and Swiss perspective, health-related data (health or biometric) is considered as a special category of personal data that we call “sensitive data“, where the processing is generally prohibited, unless the controller can demonstrate a legal ground for the processing, such as the patient’s explicit consent (art. 9 §2 (a) GDPR, art. 4 al. 5 and 13 al. 1 of the Swiss DPA), the provision of medical services by a health professional tied by a secrecy obligation (art. 9 §2 (h) and 9 §3 of the GDPR) or private overriding interests (art. 13 al. 2 of the Swiss DPA). As one can read in the press almost everyday now, cyberattacks can happen, and a data breach may lead authorities to impose hefty fines, with 4% of worldwide annual turnover according to article 83 of the GDPR, although fines should remain a last resort in the sanction mechanism applied by the authorities. I wrote a note in this article about the envisaged approach with fines and sanction pursuant to the GDPR.

In addition, the doctor would also have to require the patient’s prior explicit consent before sharing, or allowing any third party to access, any sensitive data . See my previous note on recommendations for outsourcing in the context of medical billing for healthcare professionnals.

There are many other obligations under these regulations, which this article does not intend to cover.

________________________________

CONCLUSION

This FDA approval sounds like a very good “signal” to pharmaceutical companies developing connected drugs and advanced digital life science technologies, mHealth and medical devices.  This can improve the life of many patients, while saving costs and improving efficiencies in the treatment.

There is no need for scaremongering. However, remaining careful using the device for the purpose of the treatment, informing the patient and gathering explicit consent, processing only the data that is necessary for the purpose of the treatment, working with ethics and respect for the individual, especially if these patients have a reduced of discernment, are some good steps to ensure the individual’s privacy.

_____________________

To read more on this topic:

  • Mittelstadt, Brent, Ben Fairweather, Mark Shaw and Neil McBride. “The Ethical Implications of Personal Health Monitoring.” IJT 5.2 (2014): 37-60.Web.4Feb.2018.doi:10.4018/ijt.2014070104.
  • Mittelstadt, B., Fairweather, N.B., McBride, N., Shaw, M., 2011. Ethical Issues of Personal Health Monitoring: A Literature Review, in: ETHICOMP 2011 Conference Proceedings, ETHICOMP 2011, Sheffield, UK.
  • Elin Palm, Anders Nordgren, Marcel Verweij and Göran Collste, Ethically Sound Technology? Guidelines for Interactive Ethical Assessment of Personal Health Monitoring, 2013, Interdisciplinary Assessment of Personal Health Monitoring, 105-114.
  • Nordgren, Anders. (2013). Privacy by Design in Personal Health Monitoring. Health care analysis : HCA : journal of health philosophy and policy. 23. . 10.1007/s10728-013-0262-3.
  • Data protection and privacy in connected health, an article from a blog for research and innovation relating to emerging technologies.
  • Information notice  from “Otsuka Pharmaceutical”, the manufacturer of Abilify Mycite.

By Gabriel Avigdor | NTIC.ch

Swiss Digital Day: 21-11-2017

The first Swiss Digital Day happens today 21 November 2017 at several main points, such as Geneva Gare Cornavin and Zurich mainstation. It can be followed via the traditional social media under #Digitalday!

__________________

Inform, entertain and instigate discussions

This great event led by the association “digitalswitzerland” is the first Swiss national digital day and aims to make Switzerland a “leading digital innovation hub, worldwide”, according to its founders.

Indeed, Switzerland not only is a country of innovation, but also of innovators with a huge number of startups and a creative mindset. The Global Entrepreneurship Index (GEI), which measures the quality and dynamics of entrepreneurship ecosystems at a national and regional level, ranked Switzerland eighth according to a 2016 survey!

Switzerland has all the keys to raise the bar even higher to empower itself and remain a pioneer in Xtechs (any tech) whether disruptive of a global reference for the digital age! We can make the difference in adopting a different approach to digital. The Swiss tradition of “waiting for others to make mistakes” is outdated in the digital age. Both private and public sectors should not be afraid to innovate.

We know that the power of the Swiss expertise, values and tradition is an asset. Let’s take the benefit of this worldwide uncontested reputation for developping a digital Swissness!

If you missed this unique event covered by Swiss medias and many other stakeholders, have a look at #digitalday on social media.

Share your thoughts and be creative, innovative, let’s empower the Swiss digital potential!

#Digitalday #innovation #legaltech