Healthcare AI 2025

AUSTRIA Law and Practice Contributed by: Harald Strahberger and Florian Sesztak, Kinstellar

7. Intellectual Property Issues Regarding Healthcare AI 7.1 Patent Protection

Protection Impact Assessment due to the high-risk nature of health data processing. If obtaining consent is not feasible, data must be anonymised or robustly pseudonymised, and its use must comply with both the GDPR and national research law, eg, the Austrian Research Organisation Act ( Forschungsorganisationsgesetz – “FOG”). 6.3 Data Sharing and Access In Austria, the sharing of personal health data – whether between hospitals, research institutions, or commercial AI developers – is tightly regulated by the GDPR, supplemented by Sections 7 and 8 of the DSG. Any data sharing must be based on a lawful legal basis, such as patient consent, public interest, or research, and must adhere to purpose limitation and data minimisation principles. Before sharing data, organisations must conclude Data Processing Agreements (“DPA”) in accordance with Article 28 GDPR, clearly defining roles (controller v processor), security obligations, and permitted uses. The Austrian DSB provides guidance on the content of DPA as well as on controller–processor relationships in healthcare. Cross-border data transfers within the EU/EEA are permitted; however, transfers to third countries or international organisations are only permitted in accordance with Article 44 seqq. GDPR. 6.4 De-Identification and Anonymisation For the processing of personal data by AI systems, the GDPR rules apply. According to Recital 26 GDPR, anonymised data does not fall within the scope of data protection law. In contrast, pseudonymised data, ie, where identifiers are replaced but still reversible, is still considered personal data and remains fully regu - lated under GDPR. In Austria, there is no legal standard for anonymisation and/or pseudonymisation beyond the GDPR. Thus, the standards for anonymisation are derived from the guidelines 05/2014 of the Article 29 Data Protection Working Party and the guidelines of the European Data Protection Board.

In Austria, healthcare AI innovations can be protected under the Austrian Patent Act ( Patentgesetz – “Pat - entG”), as administered by the Austrian Patent Office (“ Patentamt ”). To qualify, inventions must meet the criteria of novelty, inventive step, and industrial appli - cability. While mathematical methods and abstract algorithms are excluded under Section 1 (3)(1) PatentG, AI sys - tems may be patentable if the algorithm is applied in a technical context, such as signal processing for diagnostics or medical device control. This mirrors Article 52 of the European Patent Convention (“EPC”), to which Austria is a contracting state. However, key challenges in patenting healthcare AI are: • proving a technical contribution beyond data pro - cessing; • complying with sufficiency of disclosure under Section 87a PatentG, especially when dealing with “black-box” models; and • differentiating between clinical decision support and therapeutic innovation. Developers in Austria often file utility model ( Gebrauchsmuster ) applications under the Utility Model Act ( Gebrauchsmustergesetz – “GMG”) for faster protection of AI-based health tech with shorter innovation cycles. 7.2 Copyright and Trade Secrets AI software, including source code and documenta - tion, is protected in Austria under the Austrian Copy - right Act ( Urheberrechtsgesetz – “UrhG”). Software is classified as a literary work pursuant to Section 2 (1) UrhG, and protection arises automatically upon crea - tion. Under Section 40a UrhG, this covers various forms of software expression, including source code and machine code, as well as development materials. However, this must be balanced with obligations under MDR and the AI Act, which require transparency

26

CHAMBERS.COM

Powered by