USA Law and Practice Contributed by: Nadia de la Houssaye, Andy Lee, Jason Loring and Graham Ryan, Jones Walker LLP
decision-making processes rather than defaulting to fully automated systems; • override capabilities – AI systems must provide healthcare providers with clear, easily accessible mechanisms to override algorithmic recommenda - tions when clinical judgment suggests alternative approaches; • competency and training – healthcare providers using AI systems must be provided with the tools to achieve system competency through ongoing training and education programmes; and • quality assurance – healthcare organisations must implement robust quality assurance programmes that monitor AI system performance and healthcare provider usage patterns. 6. Data Governance in Healthcare AI 6.1 Training Data Requirements Training data for healthcare AI systems must meet stringent standards in order to provide meaningful information and outcomes. • Data quality: Healthcare AI systems require com - plete, accurate, consistent and relevant training data that accurately represents the clinical condi - tions and patient populations for which the AI will be used. • Representation, diversity and bias: Training data - sets must include adequate representation across demographic groups, clinical conditions and healthcare settings to ensure AI system generalis - ability. Likewise, AI developers must systematically identify and document potential biases in training data and implement bias-mitigation strategies. • Data provenance and lineage: Comprehensive doc - umentation of data sources, collection methods and processing steps enables proper evaluation of training data quality and potential limitations. 6.2 Secondary Use of Health Data The transfer of PHI and other sensitive information should occur only under specific rules that protect patient privacy and address the following. • Legal frameworks for data reuse: Healthcare data collected for clinical purposes may be reused for
AI training and development under specific legal frameworks that address consent, privacy protec - tion and data use limitations. • Consent requirements: Organisations must obtain appropriate consent for secondary use of health data in AI development, with consent requirements varying based on data sensitivity, intended use and applicable legal frameworks. • Research and development exemptions: Certain research activities may qualify for exemptions from standard consent requirements. These exemptions typically require IRB approval and implementation of appropriate privacy safeguards. • Data use agreements: Secondary use of health data for AI development typically requires formal data use agreements that specify permitted uses, privacy protections and data handling require - ments, as well as restrictions on further disclosure or use. 6.3 Data Sharing and Access Data sharing activities should address the following: • collaborative research frameworks, including federated learning approaches, secure multiparty computation and other technologies that enable data sharing across institutions while maintaining privacy protections; • cross-border data transfer restrictions that com - ply with federal, state and international laws and regulations that may limit where health data can be processed or stored during AI development; • data sharing agreements that specify the terms and conditions for collaborative AI development projects, including data access rights, use limita - tions, intellectual property ownership, regulatory compliance and liability allocation; and • the role of industry consortia in facilitating AI devel - opment through shared datasets and collaborative research initiatives. 6.4 De-Identification and Anonymisation To better ensure appropriate safeguards for, and ano - nymity of, health data, the following must be taken into account. • HIPAA de-identification standards: Healthcare organisations must comply with HIPAA de-identi -
135 CHAMBERS.COM
Powered by FlippingBook