An international workshop was held in Leuven, Belgium, on June 19–20, 2023, to discuss the communication of genetic risk information within families in the context of personalized prevention. Organized as part of the Horizon Europe project PROPHET (PeRsOnalised Prevention roadmap for the future HEalThcare in Europe), the event gathered interdisciplinary stakeholders to explore the benefits and challenges of various policy approaches for returning genetic test results with implications for family members. Five key themes emerged from the discussions: (1) recognizing family communication as an ongoing process, (2) adopting a family-centered approach rather than an individual one, (3) clarifying roles and responsibilities in the communication process, (4) addressing the lack of clear guidelines and policies, and (5) ensuring sufficient resources. To enhance family communication of genetic risk information, participants emphasized the importance of improving pre-test counseling and follow-up procedures, implementing policies to clarify roles and responsibilities, and providing training for healthcare professionals both within and outside genetic services.
An international workshop was held in Leuven, Belgium, on June 19–20, 2023, to discuss the communication of genetic risk information within families in the context of personalized prevention. Organized as part of the Horizon Europe project PROPHET (PeRsOnalised Prevention roadmap for the future HEalThcare in Europe), the event gathered interdisciplinary stakeholders to explore the benefits and challenges of various policy approaches for returning genetic test results with implications for family members. Five key themes emerged from the discussions: (1) recognizing family communication as an ongoing process, (2) adopting a family-centered approach rather than an individual one, (3) clarifying roles and responsibilities in the communication process, (4) addressing the lack of clear guidelines and policies, and (5) ensuring sufficient resources. To enhance family communication of genetic risk information, participants emphasized the importance of improving pre-test counseling and follow-up procedures, implementing policies to clarify roles and responsibilities, and providing training for healthcare professionals both within and outside genetic services.
This paper explores the potential applications of high-fidelity synthetic patient data in the context of healthcare research, including challenges and benefits. The paper starts by defining synthetic data, types of synthetic data and approaches to generating synthetic data. It then discusses the potential applications of synthetic data in addition to as a privacy enhancing technology and current debates around whether synthetic data should be considered personal data and,therefore, should be subjected to privacy controls to minimise reidentification risks. This will be followed by a discussion of privacy preservation approaches and privacy metrics that can be applied in the context of synthetic data. The paper includes a case study based on synthetic electronic healthcare record data from the Clinical Practice Research Datalink on how privacy concerns due to reidentification have been addressed in order to make this data available for research purposes. The authors conclude that synthetic data, particularly high-fidelity synthetic patient data, has the potential to add value over and above real data for public health and that it is possible to address privacy concerns to make synthetic data available via a combination of privacy measures applied during the synthetic data generation process and post-generation reidentification risk assessments as part of data protection impact assessments.
BackgroundOesophageal cancer has significant morbidity and mortality but late diagnosis is common since early signs of disease are frequently misinterpreted. Project DELTA aims to enable earlier detection and treatment through targeted screening using a novel risk prediction algorithm for oesophageal cancer (incorporating risk factors of Barrett's oesophagus including prescriptions for acid-reducing medications (CanPredict)), together with a non-invasive, low-cost sampling device (CytospongeTM). However, there are many barriers to implementation, and this paper identifies key ethical and legal challenges to implementing these personalised prevention strategies for Barrett's oesophagus/oesophageal cancer.MethodsTo identify ethical and legal issues relevant to the deployment of a risk prediction tool for oesophageal cancer into primary care, we adopted an interdisciplinary approach, incorporating targeted informal literature reviews, interviews with expert collaborators, a multidisciplinary workshop and ethical and legal analysis.ResultsSuccessful implementation raises many issues including ensuring transparency and effective risk communication; addressing bias and inequity; managing resources appropriately and avoiding exceptionalism. Clinicians will need support and training to use cancer risk prediction algorithms, ensuring that they understand how risk algorithms supplement rather than replace medical decision-making. Workshop participants had concerns about liability for harms arising from risk algorithms, including from potential bias and inequitable implementation. Determining strategies for risk communication enabling transparency but avoiding exceptionalist approaches are a significant challenge. Future challenges include using artificial intelligence to bolster risk assessment, incorporating genomics into risk tools, and deployment by non-health professional users. However, these strategies could improve detection and outcomes.ConclusionsNovel pathways incorporating risk prediction algorithms hold considerable promise, especially when combined with low-cost sampling. However immediate priorities should be to develop risk communication strategies that take account of using validated risk algorithms, and to ensure equitable implementation. Resolving questions about liability for harms arising should be a longer-term objective.
Introduction:Ethical and legal factors will have an important bearing on when and whether automation is appropriate in healthcare. There is a developing literature on the ethics of artificial intelligence (AI) in health, including specific legal or regulatory questions such as whether there is a right to an explanation of AI decision-making. However, there has been limited consideration of the specific ethical and legal factors that influence when, and in what form, human involvement may be required in the implementation of AI in a clinical pathway, and the views of the wide range of stakeholders involved. To address this question, we chose the exemplar of the pathway for the early detection of Barrett's Oesophagus (BE) and oesophageal adenocarcinoma, where Gehrung and colleagues have developed a "semi-automated", deep-learning system to analyse samples from the CytospongeTM TFF3 test (a minimally invasive alternative to endoscopy), where AI promises to mitigate increasing demands for pathologists' time and input.Methods:We gathered a multidisciplinary group of stakeholders, including developers, patients, healthcare professionals and regulators, to obtain their perspectives on the ethical and legal issues that may arise using this exemplar.Results:The findings are grouped under six general themes: risk and potential harms; impacts on human experts; equity and bias; transparency and oversight; patient information and choice; accountability, moral responsibility and liability for error. Within these themes, a range of subtle and context-specific elements emerged, highlighting the importance of pre-implementation, interdisciplinary discussions and appreciation of pathway specific considerations.Discussion:To evaluate these findings, we draw on the well-established principles of biomedical ethics identified by Beauchamp and Childress as a lens through which to view these results and their implications for personalised medicine. Our findings are not only relevant to this context but have implications for AI in digital pathology and healthcare more broadly.
For decades, medical researchers in the UK have highlighted difficulties accessing patient data for research. They have described multiple challenges: the parallel regulatory frameworks protecting personal data through data protection law (the ‘UK GDPR’) and common law protecting the disclosure of confidential information; the ethical principles enshrined in professional medical practice reinforcing the importance of medical confidentiality; and an undercurrent of public concern about potential for confidential patient information (CPI) to be exploited or abused. In March 2020, this complex landscape was disrupted through the publication of control of patient information or ‘COPI’ notices by the Secretary of State for Health and Social Care to mandate the sharing of CPI for COVID-19 purposes. After two years and four extensions, most of these notices have now been withdrawn. This experience provides a useful natural experiment for those who have been calling for streamlined governance of patient data for research purposes and suggests a number of lessons for future regulatory directions.
A large proportion of hospital inpatients are affected by cognitive impairment, posing challenges in the provision of their care in busy, fast-paced acute wards. Signs and symbols, known as visual identifiers, are employed in many U.K. hospitals with the intention of helping healthcare professionals identify and respond to the needs of these patients. Although widely considered useful, these tools are used inconsistently, have not been subject to full evaluation, and attract criticism for acting as a shorthand for a routinized response. In order for visual identifiers to be used effectively in acute care settings, thorough consideration must be given to the ethical and legal issues that are engaged in this context, and their potential benefits and harms must be weighed and balanced. This paper proposes a set of legal and ethical principles that can be used to guide the implementation of visual identifiers. Together, these principles provide a framework applicable in the design and implementation phases to systematically identify relevant considerations arising from the use of these tools. We outline some tensions that arise between principles and conclude that selecting a preferred moral framework could help to guide decision-making, as does clarity around the purpose and objectives of the identifier.
Contemporary biomedical research heavily relies on secondary use of personal health data that were obtained in a different clinical or research setting. Under the European Union’s General Data Protection Regulation (GDPR), data controllers processing personal data must comply with the principle of purpose limitation, which restricts further processing of personal data beyond the purpose for which the data were initially collected. However, “further processing” is not explicitly defined, resulting in considerable interpretive ambiguities as to whether “secondary use” of data by researchers constitutes “further processing” under the GDPR. This ambiguity is problematic as it exposes researchers to potential non-compliance risks. In this article, we analyse the term “further processing” within the meaning of the GDPR, elucidate important aspects in which it differs from “secondary use”, and discuss the implications for data controllers’ GDPR compliance obligations. Subsequently, we contextualise this analysis within a broader discussion of regulating scientific research under the GDPR.
Where personal, usually pseudonymised, from health research or healthcare are made available for scientific purposes, especially across borders, it is unclear what GDPR roles apply. This is a persistent roadblock for accelerating data-driven scientific discovery or for establishing large research consortia.The assignment of GDPR roles is a matter of form and function (unless roles are assigned by law). A controller determines the purpose and essential means of processing. Essential means include determining the types of data, the categories of data subjects, the parties having access to data, and the length of data retention. Joint controllers arise where two or more parties jointly determine the purpose and essential means of processing through a common decision or converging decisions. We argue that a data user (research organisation) will normally be the sole controller for a research project accessing personal data, because the data user independently determines the purposes and means of the associated processing. A party that only provides data (hospital or research organisation) for the research project will not normally be a controller for the research project, unless it actively participates in the design of the research project or requires researchers to share ownership in derived intellectual property or enriched data. Data providers who require data users to remotely access data in a secure computing environment hosted by the data provider will generally be processors, not joint controllers.
Sequencing technology is increasing the scale of information that could benefit patients who have been tested in the past. This raises the question whether professionals have a duty to recontact such patients or their families. There is currently no clear basis for a legal duty to recontact, and professional guidelines are limited. We conducted interviews with 14 senior professionals from the Netherlands and UK to obtain a range of opinions on what obligations are estimated to be possible or desirable. There was (near) consensus that a lack of resources currently inhibits recontacting in clinical practice, that recontacting is less desirable in research, that information on recontacting should be part of informed consent, and that a legal duty should follow professional standards. There was a diversity of opinions on the desirability of a more systematic approach, potential obligations in hybrid clinical-research projects, and who should bear responsibility for seeking updates. Based on the literature, legal framework and these interviews, we conclude that a general duty to recontact is unlikely, but that in specific circumstances a limited duty may apply if the benefit to the individual is significant and the burden on professionals not too extensive. The variation in opinion demonstrates that further deliberations are desirable. The development of guidelines-a process the European Society of Human Genetics has begun-is important to ensure that the courts, in deciding a recontacting case, can take into account what professionals consider responsible standards in this field.
Systems based on artificial intelligence and machine learning that facilitate decision making in health care are promising new tools in the era of 'personalized' or 'precision' medicine. As the volume of patient data and scientific evidence grows, these computerised decision support systems (DSS) have great potential to help healthcare professionals improve diagnosis and care for individual patients. However, the implementation of these tools in clinical care raises some foreseeable legal challenges for healthcare providers and DSS-suppliers in Europe: How does the use of complex and novel DSS relate to professional standards to provide a reasonable standard of care? What should be done in terms of testing before DSS can be used in regular practice? What are the potential liabilities of health care providers and DSS companies if a DSS fails to function well? How do legal requirements for the protection of patient data and general privacy rights apply to likely DSS scenarios? In this article, we provide an overview of the current law and its general implications for the use of DSS, from a European perspective. We conclude that healthcare providers and DSS-suppliers will have the best chance of meeting legal challenges if: they are first tested in translational research with the patients' explicit, informed consent; DSS-suppliers and healthcare providers are able to clarify and agree on their individual legal responsibilities, and; patients are properly informed about privacy risks and able to decide themselves whether their data can be used for other purposes, or are stored and processed outside the EU. DSS developers and healthcare providers will need to work together closely to ensure compliance with national and European regulations and standards required for reasonable and safe patient care.RELEVANCE FOR PATIENTS:Advanced digital decision support systems have the potential to improve patient diagnosis and care. In this article we discuss key legal issues to support translational research using DSS and ensure that they meet the high standards for protection of patient safety and privacy in Europe.
Medical genetic testing, 'next generation sequencing', is increasingly generating data that could become useful for patients after they have been discharged from care. If new information is discovered that links a disease to a specific mutation, do health professionals have a legal duty to recontact their patients? Apart from other concerns (such as respecting the patient's right not to know), in many cases, this would require re-evaluation or re-analysis of the data. Taking such issues into account, we conclude that, at least at this point in time, it is not arguable that there is an unconditional duty of this kind. Health professionals should always do what can be reasonably expected from them to do justice to the patient's right to information. When there is reason to believe that recontacting would be of significant clinical relevance for the patient, they should do so, unless efforts and costs involved would be disproportional.
Quality-of-care registries have been shown to improve quality of healthcare and should be facilitated and encouraged. The data of these registries are also very valuable for medical data research. While fully acknowledging the importance of re-using already available data for research purposes, there are concerns about how the applicable privacy legislation is dealt with. These concerns are also articulated in the new European law on privacy, the ‘General Data Protection Regulation’ (GDPR) which has come into force on 25 May 2018. The aim of this review is to examine what the implications of the new European data protection rules are for quality-of-care registries in Europe while providing examples of three quality-of-care registries in the field of cardiology and cardiothoracic surgery in Europe. A general overview of the European and national legal framework (relevant data protection and privacy legislation) applying to quality-of-care registries is provided. One of the main rules is that non-anonymous patient data may, in principle, not be used for research without the patient’s informed consent. When patient data are solely and strictly used for quality control and improvement, this rule does not apply. None of the described registries (NHR, SWEDEHEART, and NICOR) currently ask specific informed consent of patients before using their data in the registry, but they do carry out medical data research. Application of the GDPR implies that personal data may only be used for medical data research after informing patients and obtaining their explicit consent.
Genome-wide sequencing technologies are beginning to be used in projects that have both clinical diagnostic and research components. The clinical application of this technology, which generates a huge amount of information of varying diagnostic certainty, involves addressing a number of challenges to establish appropriate standards. In this article, we explore the way that UK law may respond to three of these key challenges and could establish new legal duties in relation to feedback of findings that are unrelated to the presenting condition (secondary, additional or incidental findings); duties towards genetic relatives as well as the patient and duties on the part of researchers and professionals who do not have direct contact with patients. When considering these issues, the courts will take account of European and international comparisons, developing guidance and relevant ethical, social and policy factors. The UK courts will also be strongly influenced by precedent set in case law.
Currently, there is no single, Europe-wide regulation of biomedical research using human samples and data. Instead, the law that applies spans a number of areas of law, such as data protection, clinical trials, and tissue regulation. In the absence of harmonized regulation, there is considerable scope for national legal variation. This article analyzes the legislative frameworks that apply to biobanking activities to identify differences in legal requirements between the BioSHaRE-EU project countries: Finland, France, Germany, the Netherlands, Norway, and the United Kingdom. This article highlights the primary role of consent and accompanying governance mechanisms, such as research ethics committee oversight, which enable consent exemptions in the context of research. Our analysis identifies a complicated legal landscape, whereby broadly similar provisions are contained in varied sources of law in each jurisdiction. The challenge for researchers is locating the applicable legal provisions within each national legal framework.
The United Kingdom is a leader in genomics research, and the presence of numerous types of biobanks and the linking of health data and research within the UK evidences the importance of biobank-based research in the UK. There is no biobank-specific law in the UK and research on biobank materials is governed by a confusing set of statutory law, common law, regulations, and guidance documents. Several layers of applicable law, from European to local, further complicate an understanding of privacy protections. Finally, biobanks frequently contain data in addition to the samples; the legal framework in the UK generally differentiates between data and samples and the form of the data affects the applicability of legal provisions. Biobanks must be licensed by the Human Tissue Authority; certain projects must be reviewed by Research Ethics Committees, and all projects are encouraged to be reviewed by them. Data Access Committees in biobanks are also common in the UK. While this confusing array of legal provisions leaves privacy protections in biobanking somewhat unclear, changes at the EU level may contribute to harmonization of approaches to privacy.