Healthcare AI 2025

CHINA Law and Practice Contributed by: Gil Zhang, Diana Li, Muran Sun and Yongqi Tao, Fangda Partners

• Basic security requirements: If healthcare AI sys - tems directly interact with patients, the national standard GB/T 45654-2025 Basic Security Requirements for Generative AI Services requires AI developers to pay close attention to user noti - fication, content moderation and safety require - ments for both large language model (LLM) train - ing and outputs, as well as overarching primary security measures. • Pre-training and training data: The national stand - ard GB/T 45652-2025 Security Specification for Generative Artificial Intelligence Pre-Training and Fine-Tuning Data sets requirements for the pre- training and optimisation of training data used in GenAI, as well as the processing activities involved. • AI-generated content (AIGC) labelling: Label - ling includes both explicit and implicit labelling. Explicit labelling refers to adding visible cues to AIGC to clearly alert the public and prevent confu - sion or misidentification. Implicit labelling involves metadata-based tagging. Specific requirements are further elaborated in the Measures for Labeling AI- Generated or Composed Content and the national standard GB 45438-2025 Labeling Method for Content Generated by Artificial Intelligence. In addition to GenAI services, healthcare AI systems are also subject to the following technical require - ments and standards. • Full-cycle personal health data processing: Vari - ous standards (including but not limited to GB/T 35273-2020 Personal Information Security Specifi - cation, GB/T 39375-2020 Health and Medical Data Security Guidelines) specify principles and secu - rity requirements for personal information-related activities such as collection, storage, use, sharing, transfer, public disclosure and deletion. • Telemedicine platforms, information access and data exchange: GB/T 44792-2024 Informa - tion Access and Data Exchange of Telemedicine Platform and certain other standards focus on the architecture of telemedicine platform data access and exchange, including technical requirements for front-end gateway data exchange, personal health device connectivity and audio/video integration. • Specific scenario-based applications: Industry and group standards have already been developed for

various AI applications in different medical treat - ment scenarios, such as lung image analysis tools, coronary computed tomography (CT) imaging software, surgical assistance devices and systems using robotic technologies, multicentre medical data collaborative analysis platforms and glaucoma screening systems. National standards are normally developed by stand - ardisation institutions and sectoral administrations, such as the National Information Security Standardi - zation Technical Committee (TC260) and the NMPA, while group standards are often led by the China Communications Standards Association, with super - vision and direction by regulatory agencies like the Cyberspace Administration of China (CAC), the Minis - try of Industry and Information Technology (MIIT) and the NMPA. 3. Regulatory Oversight of Healthcare AI 3.1 Regulatory Authorities Regulators can be categorised by sectoral administra - tion and supervision mandates as: • medical sector regulators, where the NMPA gov - erns medical device registration, technical reviews and post-market surveillance for healthcare AI products, and the National Health Commission supervises medical institutions and their usage of AI products and/or services; • technology regulators, where CAC and MIIT govern cybersecurity, AI-related matters and data compli - ance; and • ancillary regulators, where the State Administration for Market Regulation monitors advertising compli - ance, while the National Development and Reform Commission and Ministry of Commerce supervise foreign investment. Inter-agency co-ordination occurs through specialised law enforcement campaigns. CAC and MIIT, as tech - nology regulators, lead these efforts, but in practice will defer to sector-specific authorities such as the NMPA for healthcare oversight.

43

CHAMBERS.COM

Powered by