Healthcare AI 2025

AUSTRIA Law and Practice Contributed by: Harald Strahberger and Florian Sesztak, Kinstellar

2.5 Data Protection and Privacy AI in Austrian healthcare is subject to strict data pro - tection rules under the GDPR and the DSG. These laws apply to all stages of data handling in AI devel - opment and deployment (ie, data collection, storage, processing, and sharing). Health data is classified as special category personal data under Article 9 GDPR, and its use requires: • explicit consent from the data subject; or • an alternative legal basis under Article 9 (2) GDPR, such as public health interest or scientific research (with appropriate safeguards). Developers must conduct a Data Protection Impact Assessment (“DPIA”) under Article 35 of the GDPR for any AI system that is likely to pose high risks to indi - vidual rights, such as those involving automated deci - sion-making or profiling. Patients must be informed, in clear and accessible terms, whenever AI systems are used in care provision – this is both an ethical and legal requirement under Articles 13 and 14 GDPR. Data governance issues, such as training data qual - ity, de-identification, and cross-border transfers, are addressed in detail in 6. Data Governance in Health- care AI of this guide. 2.6 Interoperability and Standards In Austria, interoperability and technical standards for healthcare AI systems are guided by a mix of EU regu - lations, international standards, and national health IT policy frameworks. While there are no AI-specific interoperability laws at the national level, the use of AI in regulated medical contexts must adhere to the technical standards required under the MDR and enforced by the MPG. Mandatory standards include: • ISO 13485 for quality management systems; • ISO 14971 for risk management; • IEC 62304 for medical device software lifecycle; and • HL7/FHIR for health data interoperability. The Austrian electronic health record system “ELGA” is based on structured data exchange protocols. The technical specifications are defined in the Ordinance

on the Implementation and further in Development of ELGA (ELGA Verordnung 2015 – “ELGA-VO 2015”). Regulatory oversight of standards compliance is shared between the Austrian Federal Office for Safety in Health Care ( Bundesamt für Sicherheit im Gesund- heitswesen – “BASG”), which assesses technical documentation during certification, and institutional IT departments, which manage local integration and data security. The upcoming European Health Data Space Regulation (“EHDS”) will introduce mandatory EU-wide interoperability and transparency require - ments for AI in healthcare, further shaping the practice in Austria. 3. Regulatory Oversight of Healthcare AI 3.1 Regulatory Authorities In Austria, regulatory oversight of healthcare AI is shared between multiple authorities, depending on the function of the AI system, as outlined below. • BASG is the competent authority for medical devices under the MPG. BASG oversees conform - ity assessments, post-market surveillance, and vigilance reporting for AI systems classified as SaMD. • The Data Protection Authority ( Datenschutzbehörde – “DSB”) enforces GDPR and the DSG, especially where healthcare AI involves the processing of sensitive personal data. Coordination between these authorities is informal but increasing, particularly on cross-cutting issues like data protection during conformity assessments or data sharing in research. Under the AI Act, coordination is expected to be for - malised further through the designation of national supervisory authorities and an EU-level AI Board. 3.2 Pre-Market Requirements Before placing a healthcare AI system on the Austrian market, developers must ensure conformity with the MDR and the MPG. If the AI system qualifies as a medical device (eg, diagnostic, therapeutic, or deci -

21

CHAMBERS.COM

Powered by