Digital tools are regularly used in the health care sector. This collective term covers a variety of applications, ranging from regular care ICT – such as the electronic patient record (“EPD”) and planning and invoicing software – to e‑health and other digital tools that are deployed directly to support care providers – such as triage tools or decision support software. If a care provider uses a digital tool (e.g. on its website), patients must be able to trust it is of good quality. This comes with responsibilities for the care provider who offers the tool.
In a previous article we discussed AI in health care and the demands set on it. The growing media attention for digital tools makes this a good time to examine the legal framework; what does it look like again?
Software as a medical tool
It is important that to establish what kind of digital tool we are talking about, since not every application is subject to the same legal framework. Some software only supports operations or administrative processes, while other digital tools have a substantive care function and may affect diagnoses, monitoring or treatment of patients. In the latter case it may qualify as software as a medical tool, which is subject to stricter rules.
Article 2 of the Medical Device Regulation (“MDR”) provides that software is a ‘medical device’ if it is intended by the manufacturer to be used for a medical purpose, such as diagnosis, monitoring, prediction, or treatment of disease. The intended purpose of the software is decisive, as appears from its functionality, the instructions for use or its presentation or marketing by the manufacturer.
In the Guidance [1] to the MDR, it is explained that software that actively analyses or interprets medical data for individual patients falls under the MDR. Examples are software that analyses ECG imagery or performs triages on patients on the basis of data entered. Software that only stores, transfers or represents data without any medical interpretation or analysis – such as the electronic record or a planning system – does not qualify as a medical device. Though the difference may seem small, it is of great legal importance to care providers because of the division of responsibilities. As soon as software is classified as a medical device, the obligations of the MDR apply. Some of these, such as obtaining a CE marking and, if applicable the involvement of a notified body, are primarily upon the manufacturer of the medical device.
Responsibility of care provider for medical devices
Pursuant to the Health Care Quality, Complaints and Disputes Act (Wet kwaliteit klachten en geschillen zorg (“Wkkgz”)) and the Medical Treatment Contracts Act (Wet geneeskundige behandelovereenkomst, “Wgbo”)), the care provider remains responsible for delivering good and safe care. The means that the care provider, when purchasing and deploying digital tools, has to examine whether:
- the software qualifies as a medical device, and if so, whether it bears a valid CE marking;
- the tool is used in accordance with its intended purpose and the terms of use of the manufacturer;
- the organisation has procedures in place for safe and responsible use.
Besides, the care provider must ensure that employees are capable of working with the digital tool. They have to understand the functioning and limitations of the tool and how results must be interpreted in light of the professional standard. This responsibility is in line with the Digital Care Assessment Framework of the Health and Youth Care Inspectorate, which elaborates the expectations set on care providers in their use of technologies pursuant to the Wkkgz and the requirement of good care. Patients must also be informed well of the use, the limitations and the risks of digital tools.
AI Regulation
When digital tools have an AI component, the AI Regulation is also relevant. These tools can then be classified as “AI systems”. Of the obligations set out in the AI Regulation, the majority applies to providers of AI‑systems. These are parties that market or develop, or instruct others to develop, the AI system to use it under their own name or brand. In view of this broad definition, a care provider may also be a provider of an AI system. AI systems that are used as medical devices or are a safety component of such devices are in principle classified as high-risk AI. Regarding such systems, the providers are subject to additional requirements in the field of risk control, transparency, data quality and human oversight.
If care providers are users of high‑risk AI, they will be responsible for the proper use of the system, compliance with the instructions for use, and identifying and reporting incidents. Here too, the deployment of AI does not replace the own responsibility for good care.
Other points of attention
Besides the requirements mentioned above, there are some broader points of attention that play an important role in the deployment of digital tools in health care.
Data protection
From the perspective of data protection there are certain requirements in place for care providers who use digital tools. This is likely to involve the processing of personal data, such as sensitive medical data of patients. The GDPR sets strict requirements on this processing of ‘special data’. Such processing is prohibited unless a statutory exception exists and a ground from the GDPR can be invoked, for example if the processing is necessary to provide care to a patient. Furthermore, the appropriate security of the data in the digital tool is essential, not only to prevent not just data breaches, but also liability for damage as a result thereof. In cases of increased risk to the privacy of patients, the additional obligation applies to perform a Data Protection Impact Assessment (DPIA) before using the digital tool.
New regulations
The European Union is very active in the field of digital care. Care providers should take into account upcoming regulations, such as the Cybersecurity Act (implementing the NIS2 Directive) and the Cyber Resilience Act. These regulations will impose additional obligations on both manufacturers and care providers, including in the fields of transparency, risk control and cybersecurity. We wrote about the NIS2 Directive in a previous article.
Conclusion
Digital tools offer great opportunities for health care, but they come with legal risks. The news about the digital triage tool underlines the essential importance of conscious and careful use. Deploying digital tools is possible, provided that they meet clear and strict requirements.
When purchasing or deploying digital tools as a care provider, you should ask yourself whether these qualify as a medical device, and if so, whether they have the certification required. It is important to note that the care provider always remains responsible for the quality and security of the care provided. This requires insight into the type of digital tool deployed, knowledge of the division of responsibilities between manufacturer and care provider, and attentiveness to safe use and privacy.
The article above is not a piece of advice; it offers insight in the main aspects of the topic in broad outline. Each application and each situation is different. Would you like to learn more about the use of AI in health care or medical devices, please call or mail Eline of Demi.