Digital health: Apps, the GDPR and medical confidentiality

The Royal Free London NHS Foundation Trust recently published an audit we carried out into the Streams app. The Streams app is provided by DeepMind and used by clinicians at the Royal Free to deliver improved care to patients with acute kidney injury.

The audit was carried out in response to undertakings given by the Royal Free to the Information Commissioner in July 2017.

Our conclusion is that the Royal Free’s use of Streams is lawful and complies with data protection laws, though there are areas in which improvements could be made. The audit addresses a number of interesting legal issues, including:

  • the circumstances in which it is lawful to use live patient data for testing;
  • the interaction between the General Data Protection Regulation and the Data Protection Act 2018 when processing special category personal data for healthcare purposes; and
  • a detailed review of the laws of confidence, particularly in relation to the concept of implied consent to direct care and the use of patient data for testing. The Information Commissioner is continuing to review our analysis and may provide further guidance in due course. 

The press release from the Royal Free is available here.