Healthcare AI 2025

AUSTRIA Law and Practice Contributed by: Harald Strahberger and Florian Sesztak, Kinstellar

cal errors, software malfunctions, and data breaches, respectively. Insurers assess AI-related risk based on: • MDR classification (eg, class IIa or IIb); • clinical validation data; • cybersecurity protocols; and • post-market monitoring practices. To date, no Austria-specific insurance policies exclu - sively for AI have been established. However, some EU-based insurers offer tailored products for digital health or AI-based tools. Healthcare providers using third-party AI should verify that vendors maintain ade - quate product liability coverage and that institutional policies extend to AI-related malpractice. Risk premiums may be higher for systems that involve autonomous recommendations or have limited explainability. Insurers favour systems with human- in-the-loop oversight, proven performance metrics, and clear documentation. 10.4 Best Practices for Implementation Successful implementation of healthcare AI in Aus - trian institutions requires: • establishing a dedicated implementation team with IT, clinical, legal, and data privacy experts; • creating standard operating procedures (SOPs) for AI usage, monitoring, and escalation; • ensuring comprehensive clinician training, focusing on AI capabilities, limitations, and human oversight; and • providing ongoing support, with feedback loops for updates and performance review.

Change management strategies should address work - flow integration, staff trust-building, and ethics train - ing. Integration with existing IT infrastructure, includ - ing interoperability with electronic health records, is critical. Institutions should also allocate time for clini - cal pilots before full-scale deployment to refine the Deploying healthcare AI across jurisdictions raises challenges related to MDR conformity, GDPR com - pliance, and national health laws. In Austria, cross- border deployment within the EU requires: • ensuring CE certification is valid across EU/EEA states; • implementing data transfer mechanisms (eg, SCCs) for non-EU destinations; and • aligning with local clinical practice standards and liability rules. utility of AI and manage expectations. 10.5 Cross-Border Considerations Diverging interpretations of GDPR or MDR in other jurisdictions may necessitate local legal represen - tation, custom data governance frameworks, or adjustments in software functionalities. Multinational organisations should maintain a compliance matrix that tracks key regulatory differences and develop a modular approach to adapt deployments to each jurisdiction. Participation in EU harmonisation projects, such as the European Health Data Space (EHDS), will facilitate cross-border compliance in the future.

30

CHAMBERS.COM

Powered by