Skip to main content
Journal of the American Medical Informatics Association: JAMIA logoLink to Journal of the American Medical Informatics Association: JAMIA
. 2022 Jul 25;29(10):1818–1822. doi: 10.1093/jamia/ocac112

21st Century Cures Act: ethical recommendations for new patient-facing products

Brigitte N Durieux 1, Matthew DeCamp 2, Charlotta Lindvall 3,4,
PMCID: PMC9471700  PMID: 35876830

Abstract

Background

Recent legislation ensuring patient access to their electronic health records represents a promising national commitment to patient empowerment. Access and interoperability rules seek to empower individuals as well as increase opportunities for data sharing by hospitals, apps, and other parties for research and innovation. However, there are trade-offs between data accessibility and oversight. Some third-party apps may not be covered by federal regulations, and receiving records directly from individuals may render some services in possession of health data. To promote consumer trust, these services should follow ethical standards regardless of regulatory status.

Actionable Principles

This Perspective proposes 3 actionable principles, grounded in medical ethics, for services making use of health data: services should (1) provide informed, dynamic, regular consent, including control over data sharing, (2) promote inclusivity and equity, and (3) intentionally focus on consumer trust and the perception of value in the service provided.

Keywords: patient data, data privacy, informed consent, ethics

INTRODUCTION

To many patients receiving care, signing a release allowing their health information to be used for research purposes makes sense. Research and innovations frequently rely on aggregate health data1,2; many people are willing to share their information for research3,4 and understand its potential in improving their healthcare and contributing to important medical advances.5 People also generally trust that healthcare institutions and federal laws will protect their data privacy.6 Yet, many may be unaware that some releases allow their data to be shared outside of academic/healthcare institutions7 and sold as monetized, valuable business assets in a multibillion-dollar industry of health information brokers and technology companies.8

While the institutional sharing of health data with industry is not uncommon,9,10 where it falls ethically and legally has sparked debate. In the discussion of who owns health data, the legal consensus in the United States and other countries tends to hold that institutions have the legal right to share anonymized health data they collect.11 However, legal ownership rules do not necessarily line up with peoples’ beliefs that their personal information should be something they own (and multiple parties are recognized as being involved in the generation of data).12 As health information is both clinical and personal, it may be owned by an institution, but it still creates risks for an individual if the data are not properly handled or protected.13 Regulations and regulatory bodies such as the Health Insurance Portability and Accountability Act (HIPAA) and the Federal Trade Commission (FTC)14 in the United States and the General Data Protection Regulation (GDPR) in Europe15 do provide protections and ethical guidelines. But in the gray area of information exchange, personal data can still be shared and used for purposes that people have little control over.16 The lack of legal ownership means that people often little say in where it goes, what is done with it, and whether it ever gets deleted—illustrating the point, data can even be acquired by an entity a person does not trust (eg, Facebook).17,18

The circumstance of valuable, monetized health data raises ethical concerns on its own,19 but recent legislation ensuring patient access to their complete electronic health record (EHR) presents a new twist: individuals themselves, rather than healthcare institutions, will be more easily accessed as sources of medical data.20 As of October 6, 2022, the 21st Century Cures Act Final Rule designates that people must be delivered their EHR in a timely manner and in a secure, easily-understood, automatically updated format.21 This particular policy aims to empower Americans and improve their informed decision-making in healthcare, yet the task at hand requires more than simply turning over an EHR. People who have their records may still be confused around terminology, reasons for tests, and locating information, and could benefit from comprehension tools and aids.

To help address these gaps, and to fill a business niche, third-party services are being developed to help people aggregate, organize, and manage their EHRs.19 Some partner with existing EHR vendors, while other new services aim to market to individuals directly; importantly, some do not have business association agreements with providers, and thus fall outside the scope of HIPAA coverage.22 In this case, the health data involved fall into the same category of regulation as other personal identified information, such as cell phone location data, employment history, financial transactions, and other information that is generated and collected on individuals.23 This type of information is treated differently under different privacy models. In the United States, this personal information falls to regulation by the FTC. In other jurisdictions, such as the European Union, the GDPR provides more comprehensive and in many ways more stringent protections.24,25 These regulations recognize the importance of personal health data and its role in the data economy—something increasingly critical to consider as personal data collection is expanding.26

Ultimately, tools built within this up-and-coming niche can empower people in their healthcare and improve ease of use of EHRs. However, they also raise ethical concerns related to informed consent, privacy, and equity, as well as the potential exploitation of private health data if companies benefit disproportionately and unfairly from the relationship.27 Addressing these concerns is important not only for the success of new patient tools but also for general trust in data-sharing in healthcare.28 This Perspective proposes 3 principles, grounded in ethics concepts, that could guide the design of services making use of medical data such as EHRs.

THREE ACTIONABLE PRINCIPLES

1. Provide informed, dynamic, regular consent: Give people accurate and accessible information about the service up-front, allow for multiple consent options, and require reconsenting on a regular timeframe; inform users of the nature of potential data transfers (ie, sharing for research) and provide discrete mechanisms and timepoints for controlling information flow.

Perceptions of choice and control over personal data use are crucial for public trust.29 User data collection is quite common,30 as the practice allows technology firms to develop new analytics, and is a critical part of some business models31 (revenue generated from collected data allows companies to offer services at lower or no cost). However, current practices among health apps are largely inadequate regarding treatment of data and are not always in line with guidelines and legal regulations.32 Most services include information about data collection within their Terms of Service agreement, but few people read this agreement before signing (consenting).33 Additionally, most user data-sharing agreements are broad and vague; though simplicity in consent forms is preferred by service providers and users alike, broad consent forms tend to leave signatories underinformed, and many people do not favor broad consent for research or data sharing.34

In accordance with the ethics principle of respect,35 services which make use of health data should not seek to obtain consent via a one-time text-heavy form, but rather value consent on principle. This value could be reflected by ensuring that consent processes are informed, future-oriented, and reflective of a person’s choice. This involves giving users information about the service and data use up-front (rather than tucked into a lengthy terms-of-service agreement), asking questions like “do you still want to share your data?” at regular time intervals (no less than once per year), and giving users multiple consent options reflecting real choice (eg, allowing users to opt out of certain data uses—as people feel differently about their data being used for different purposes36). It also involves dynamic consent processes to allow users access to services regardless of whether they have consented to sharing their data with third parties. Existing models for informed, dynamic, future-oriented consent could be adapted for this purpose.37,38 As sensitive medical data are increasingly available and valuable, respecting and empowering patients means valuing their consent.

2. Promote inclusivity and equity:Monitor user base demographics/consumer-facing practices and promote equitable access to the service, with the aim of not furthering (and ideally, reducing) disparities in care quality among the target user population.

As empowering all people in their healthcare should be a shared goal among all in healthcare, it implies that third-party services should provide benefits equitably; that is, benefits should not be offered to or preferentially favor one demographic group over another (while recognizing that health apps which targets individuals with specific diseases may not have a broadly inclusive user base). Intended and unintended biases can be present in customer service interactions39,40 and within media and materials generated by a service41,42; these can be propagated by institutional hiring practices and culture.43 Providing inclusive, equitable services will require managing these biases. Services intended to empower will only widen disparities if they are built for, cater to, and are adopted by only wealthy, white, English-speaking individuals who have attained higher education and trust the healthcare system.44 Equity and inclusivity require that services seek to empower all equally, lest they unintentionally disempower some while empowering a select subset of those already privileged by the healthcare system.

Similarly, a commitment to justice means that services designed to empower patients should not further disparities in access to quality healthcare. To meet this commitment, services should (1) consider the barriers people may have to accessing the service due to cost; (2) be sensitive to the ways marketing and customer service practices can affect their users and those users’ perceptions of the service41 (eg, using all one race of individuals in pictorial advertising materials, limiting recruitment, or marketing of the target population by factors such as race or sexual orientation that are not relevant to the purpose of the service, etc.42); and (3) periodically evaluate their user base to determine whether it is representative of their target population, and/or whether additional outreach efforts should occur.

3. Ensure provision of value in the service provided, intentionally focus on consumer trust:Report performance outcomes; oversee that health data acquisition is necessary for service delivery.

Trust is a critical concept in both the setting of healthcare delivery and that of business, especially when it comes to collecting and using sensitive data.45 Trust between patients and clinicians is necessary for quality medical care46; trust between users and a service makes for better business outcomes.47 While third-party health services are outside the realm of healthcare (ie, the 2 are legally distinct), patients may not distinguish the 2 during their personal journey managing their care. This means that trust in healthcare institutions could be affected by individuals’ experiences with third-party services, and vice versa. For people whose valuable records have the potential to generate revenue for a service, to trust and continue using third-party health apps will benefit both the user and the service—provided the relationship and consumer trust is prioritized. Many people are wary about the current surveillance-oriented, big data era.48 Managing the provision of the service value promised and not abusing patient trust and private data will be important for all parties involved.

The principles of honesty, respect, responsibility, and dependability within business ethics emphasize providing a service as it has been marketed, and acting as a trustworthy entity for consumers; these align with the ethics principles of beneficence and nonmaleficence, which emphasize maximizing benefit and minimizing harm. To act in accordance with transparently providing benefit to people who have uploaded sensitive personal health data, services making use of patient EHRs should regularly publish public reports on their performance regarding both (1) effective service provision and service-related outcomes and (2) consumer acceptability metrics such as trust and experience ratings. While an outside watchdog entity would best ensure unbiased reporting (as well as be able to confirm that data collection has been essential for the service), apps in-development are in the best position to implement robust systems and strategies for feedback reporting.

A FRAMEWORK FOR RESEARCH MOVING FORWARD

While third-party services and the developers of applications are in the best position to take these principles into account, researchers have an important role in monitoring the businesses, services, and practices that have emerged32,49 and will continue to as people’s medical records become increasingly accessible. Figure 1 outlines a conceptual framework for researchers, highlighting factors that may impact the protection of consumers and their personal information and illustrating relationships and areas of interest among the parties involved.

Figure 1.

Figure 1.

Conceptual framework for researchers depicting (A) imbalances in consumer protection and factors involved in impacting protections and (B) simple relationships between the parties involved in patients’ use of health apps, and domains or concepts involved which warrant research attention. (A) Regulatory environment and principles, public dissent and demonstrated need for policy change, data profitability, complicated legal identities regarding data and ownership, consumer trust, and public satisfaction ratings are all factors which may have the power to impact protections to consumers’ personal data. Factors which may decrease protections include competing stakeholders and priorities (privacy vs profit) and logistical difficulties to regulation. Factors which contribute to increasing protections involve the principles behind regulation, demonstrated need for increased regulation (harm shown), and public demand for increased protections. (B) Consumers interact with service-providing companies, which in turn interact with regulatory bodies. While research in the sphere of healthcare aims to bring forward patient voices and perspectives, consumers’ opinions on third-party health apps and their data collection practices is not as widely researched. As time goes on and more services are developed, it will be important to guide investigations into, for example, consumers’ knowledge and acceptability of data practices, the landscape of consent practices, how well target audiences are represented among app users, and what strategies best produce customer trust and satisfaction.

CONCLUSION

As medical records received directly from individuals can render a third-party service in possession of personal health data, such services should adhere to ethical standards. Patients, clinicians, and the third-party and business associates of health systems should be proactive and aware—from the businesses and developers who have the power to follow these principles, to the clinicians who share responsibility for educating patients about the benefits and drawbacks of sharing their EHR with third parties, to the researchers whose work is required to investigate this practice to understand its full nature, extent, and consequences.

FUNDING

This research received no specific grant from any funding agency in the public, commercial, or not-for-profit sectors.

AUTHOR CONTRIBUTIONS

All authors made substantial contributions to the conception, design, drafting, and editing of the work.

CONFLICT OF INTEREST STATEMENT

None declared.

Contributor Information

Brigitte N Durieux, Department of Psychosocial Oncology and Palliative Care, Dana-Farber Cancer Institute, Boston, Massachusetts, USA.

Matthew DeCamp, Division of General Internal Medicine, Center for Bioethics and Humanities, University of Colorado, Aurora, Colorado, USA.

Charlotta Lindvall, Department of Psychosocial Oncology and Palliative Care, Dana-Farber Cancer Institute, Boston, Massachusetts, USA; Harvard Medical School, Harvard University, Boston, Massachusetts, USA.

Data Availability

No new data were generated or analyzed in support of this research.

REFERENCES

Associated Data

This section collects any data citations, data availability statements, or supplementary materials included in this article.

Data Availability Statement

No new data were generated or analyzed in support of this research.


Articles from Journal of the American Medical Informatics Association : JAMIA are provided here courtesy of Oxford University Press

RESOURCES