Health Data Privacy in the Age of Machine Learning

Stud Health Technol Inform. 2025 Oct 3:330:947-972. doi: 10.3233/SHTI251469.

Abstract

This paper examines the protection of personal data within healthcare systems, analyzing historical, legal, and technological aspects of privacy and confidentiality in medical contexts. Beginning with the Hippocratic Oath, a symbol of the earliest ethical standards of medical confidentiality, the study focuses on contemporary challenges in safeguarding sensitive information, including the application of the General Data Protection Regulation (GDPR), the Council of Europe's Convention 108+, and other European Union legislative frameworks. Particular attention is given to data processing in the era of artificial intelligence and the Internet of Medical Things (IoMT), highlighting security risks and regulatory requirements. The paper provides guidelines for implementing the "need-to-know" principle and establishing data security management systems, such as Zero Trust Architecture, to ensure robust data protection practices.

Keywords: Convention 108+; GDPR; Internet of Medical Things (IoMT); Zero Trust Architecture; health data; privacy protection; selective access.

MeSH terms

  • Computer Security* / legislation & jurisprudence
  • Computer Security* / standards
  • Confidentiality* / legislation & jurisprudence
  • Confidentiality* / standards
  • Electronic Health Records* / legislation & jurisprudence
  • Electronic Health Records* / standards
  • Europe
  • Humans
  • Machine Learning*