Healthcare AI 2025

POLAND Law and Practice Contributed by: Barbara Kiełtyka, Jakub Gładkowski and Małgorzata Kiełtyka, Kieltyka Gladkowski KG Legal

8.3 Therapeutic and Treatment Planning From a technological level, the entire treatment pro - cess (treatment planning or therapeutic decision-mak - ing) can be supported by AI to make the process more effective. However, AI systems as tools – for example, those that recommend dosages, treatment protocols or surgical approaches or that are used in treatment planning or therapeutic decision-making – pose a risk of non-compliance with privacy standards for sensi - tive data (not just that of patients) or even liability for damages regarding fundamental personal rights such as patient health. Article 2 (1) of the MDR, defining a medical device, specifies that software can be a medical device, pro - vided it meets the other requirements set out there. It should be borne in mind when interpreting this provision that the therapeutic process encompasses activities and interactions, diagnoses and treatment phases, ie, therapies and progress evaluations. There - fore, it is not a process that takes place exclusively in a hospital or only at the stage following diagnosis and initial examination. A tool that aids in the inter - pretation of symptoms and diagnosis can serve as a medical application. This means that AI systems, as a tool or part of a tool used in a medical procedure, are subject to Article 5 and Article 10 of the MDR. Article 5 refers to Annex I (issues such as labelling). Article 10 introduces the requirement to monitor prod - uct quality. Annex VIII of the MDR, however, is a legal solution to a key issue for AI. It classifies diagnos - tic systems based on the potential consequences of their use. Essentially, a diagnostic software system is classified as Class IIa. If its use could result in death or irreversible damage, it is classified as Class III. In the event of significant deterioration or the need for surgical intervention, the device will be classified as Class IIb. If the software is not used for diagnostics, it belongs to Class I. 8.4 Remote Monitoring and Telemedicine Remote patient monitoring and telemedicine encom - pass the entire therapeutic process, including activi - ties and interactions, diagnosis and the treatment phase, ie, therapy and progress evaluation. Therefore, since platform-based and software-based AI sys - tems encompass all patient-physician relationships, access to medication and administrative supervision,

it is important that, from a healthcare regulatory per - spective, the legal term “therapeutic process” does not refer to a process that occurs solely in a hospi - tal or clinical setting. Any remote action using a tool, even one that merely supports the interpretation of initial symptoms or diagnosis, conducted remotely or automatically, will also be subject to all healthcare regulatory requirements, in addition to software sector regulations such as the AI Act. Since the status of a medical procedure is not related to the actual need for a hospital stay, all regulations regarding the legality of medical procedures and medical professional liability will apply to AI systems operating in a clinic or non-clinical setting, including very detailed and restrictive regulations regarding cybersecurity, the operation of IT platforms, and data processing. From the perspective of the fundamental GDPR, any medical procedure conducted by a healthcare AI device constitutes data processing. For example, the general requirement that a human factor ultimately makes the final decision in the decision-making chain remains in force; hence, electronic platforms employ AI-generated systems only for initial diagnostic pro - cedures. Patient interviewing via chatbot does not eliminate the obligation of a registered clinician to connect in person (in practice, by phone) and act as if the medical service were taking place in the clinic. Besides the consultation procedure and the use of the communication platform, additional issues include regulatory cybersecurity regulations and the regulato - ry framework of the EHDS – this concerns connecting to the IT system for online prescription issuance. Sen - sitive data in the cloud and GDPR are also considered. The AI Act does not explicitly mention remote patient monitoring and telemedicine. It only includes a ref - erence in the Preamble to AI systems intended for emergency reporting (Recital 58 of the AI Act). Annex III of the AI Act classifies such situations as high-risk AI systems. According to Article 6 of the AI Act, high- risk systems are also considered medical devices of Class IIa or higher (according to the MDR) that use AI for the diagnosis, monitoring, treatment or mitigation of diseases. Simple bots will typically be considered

103 CHAMBERS.COM

Powered by