Submitted:
12 January 2024
Posted:
12 January 2024
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Health Systems Strengthening - Policy Orientations and Initiatives
3. Can Blockchain Technology Fulfill the Needs of Health Systems Strengthening?
4. Blockchain Technology’s Reflections in Law and Human Rights
5. Addressing GDPR and Blockchain Conflicts: Potential Solutions
6. Conclusion
Author Contributions
Funding
Conflicts of Interest
References
- United Nations. Department of Economic and Social Affairs. Sustainable Development. SDGs2030. https://sdgs.un.org/goals Website 19 july 2023. Website accessed 29/10/2023.
- European Commission https://ec.europa.eu/commission/presscorner/detail/en/ip_22_7153. Website accessed 29/10/2023.
- World Health Organization. Health and Migration. https://www.who.int/tools/refugee-and-migrant-health-toolkit/essential-knowledge-health-and-migration. Website accessed 20/10/2023.
- European Commission International Partnerships.https://international-partnerships.ec.europa.eu/policies/human-development/strengthening-health-systems_en. Website accessed 20/10/2023.
- Charter of Fundamental Rights of the European Union (CFR) . Articles 8 and 35 – Protection of personal data. Website accessed 29/10/2023.
- General Data Protection Regulation (GDPR): Article 6(1) and Recital 40 - https://gdpr-info.eu/art-6-gdpr/. Website accessed 29/10/2023.
- California Consumer Privacy Act (CCPA): Section 1798.115 - https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.115.&lawCode=CIV. Website accessed 29/10/2023.
- Information Commissioner's Office (ICO) - Guide to Lawful Basis for Processing: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/. Website accessed 29/10/2023.
- European Data Protection Board (EDPB) - Guidelines on Consent under Regulation 2016/679: https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en.
- Unal Tatar a, Yasir Gokce b, Brian Nussbaum. Law versus technology: Blockchain, GDPR, and tough tradeoffs. Computer Law & Security Review.
- Health Insurance Portability and Accountability Act (HIPAA): https://www.hhs.gov/hipaa/index.html. Website accessed 29/10/2023.
- Personal Information Protection and Electronic Documents Act (PIPEDA): https://laws-lois.justice.gc.ca/eng/acts/P-8.6/. Website accessed 29/10/2023.
- Office of the Privacy Commissioner of Canada.Provincial health privacy laws (varies by province). https://www.priv.gc.ca/en/about-the-opc/what-we-do/provincial-and-territorial-collaboration/provincial-and-territorial-privacy-laws-and-oversight/. Website accessed 30/10/2023.
- Privacy Act 1988: https://www.legislation.gov.au/Details/C2021C00098. Perspect Health Inf Manag. 2021 Winter; 18(Winter): 1l. Published online 2020 Dec 7. Website accessed 29/10/2023.
- Theodos K, Sittig S. Health Information Privacy Laws in the Digital Age: HIPAA Doesn't Apply. Perspect Health Inf Manag. 2020 Dec 7;18(Winter):1l. PMID: 33633522; PMCID: PMC7883355.
- Act on the Protection of Personal Information (APPI): https://www.japaneselawtranslation.go.jp/law/detail_main?re=02&vm=02&id=174. Website accessed 29/10/2023.
- Act on Assurance of Medical Care for Elderly People: https://www.japaneselawtranslation.go.jp/law/de. Website accessed 29/10/2023.
- Presidência da República Secretaria-Geral LEI Nº 13.709, DE 14 DE AGOSTO DE 2018 Lei Geral de Proteção de Dados (LGPD) http://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13709compilado.htm. Website accessed 29/10/2023.
- Ng WY, Tan TE, Movva PVH, Fang AHS, A Hoo, Foo FSS, Zhe Xiao, Kai Sun, Tien Yin Wong, Alex Tiong-Heng Sia, Daniel Shu Wei Ting Blockchain applications in health care for COVID-19 and beyond: a systematic review. The Lancet Digital Vol 3 December 2021 https://www.thelancet.com/action/showPdf?pii=S2589-7500%2821%2900210-7. Website accessed 29/10/2023.
- Lee D, Lee SH, Masoud N, Krishnan MS, Li VC. (2021) Integrated digital twin and blockchain framework to support accountable information sharing in construction projects. Automation in construction 127, 103688. [CrossRef]
- World Trade Organization. Digital Technologies and trade. 2023. https://www.wto.org/english/tratop_e/dtt_e/dtt_e.htm. Website accessed 29/10/2023.
- World Customs Organization and World Trade Organization. 2022. Study Report on Disruptive Technologies. June 2022. https://www.wto.org/english/res_e/booksp_e/wco-wto_e.pdf. Website accessed 29/10/2023.
- Corte-Real, A; Nunes, T; Santos C, Cunha, PR. (2022) Blockchain technology and universal health coverage: Health data space inglobal migration Journal of Forensic and Legal Medicine 89 102370.
- Philip Storz, Sandra Wickner, Benjamin Batt, Johannes Schuh, Denise Junger, Yvonne Mo ̈ller, Nisar Malek and Christian Thies. bwHealthApp: A Software System to Support Personalized Medicine by Individual Monitoring of Vital Parameters of Outpatients HEALTHINF 2021 - 14th International Conference on Health Informatics https://d-nb.info/1270413503/34.
- Toubiana R, Macdonald M, Rajananda S, Lokvenec T, Kingsley, Romero Brufau S. (2022) Blockchain for Electronic Vaccine Certificates: More Cons Than Pros. Front. Big Data. Sec. Medicine and Public Health. Volume 5. [CrossRef]
- Juskalian (2018) Inside the Jordan refugee camp that runs on blockchain. MIT Technology Review. https://www.technologyreview.com/2018/04/12/143410/inside-the-jordan-refugee-camp-that-runs-on-blockchain/. Accessed 20/10/2023.
- Forthergill T, Knight W, Stahl BC, Ulnicane I. (2019) Responsible Data Governance of Neuroscience Big Data.Volume 13 - 2019 | . [CrossRef]
- Hallamaa J, Kalliokoski T. (2022) AI Ethics as Applied Ethics.Front. Comput. Sci., Volume 4. [CrossRef]
- Gonçalves RC, Dilva MM, Cunha PR. (2023) Olympus: a GDPR compliant blockchain system International Journal of Information Security. [CrossRef]
| EUROPE | USA | CANADA | AUSTRALIA | JAPAN | BRAZIL | ||||
| GDPR | HIPAA | CCPA | PIPEDA | Privacy Act 1988 | APPI | AAMCEP | LGPD | ||
| Public target | European Union and EU citizens |
Health institutions and health insurance activities in EUA | Businesses in California and California citizens | Commercial activities in Canada | Government agencies and private-sector organizations | Institutions in Japan | Elderly residents in Japan | Institutions in Brazil | |
| Organization sector | All | Health | Business | Private | Private and Public | All | Geriatric Institutions and stakeholders | All | |
| Personal Consent | Requirements | Specific | Informed and recommended for sensitive data | Specific | Flexible | Specific | Flexible | Specific | Specific |
| Informed and explicit for sensitive data | Informed and explicit for sensitive data | Mandatory for sensitive data | Informed and explicit for sensitive data | Informed and explicit for sensitive data | Mandatory for sensitive data | Informed and explicit for sensitive data | |||
| Timeframe | Before collecting, using or disclosing medical data | Not required, but recommended | Before collecting, using or disclosing medical data | Not required, but recommended | Not required, but recommended | x | Not required, but recommended | ||
| Access data | x | x | x | x | x | x | x | x | |
| Request data correction and deletion | x | x | x | x | x | x | x | x | |
| Withdraw consent | x | - | - | x | - | - | - | x | |
| Transparency | x | x | x | x | x | x | x | x | |
| Accountability | x | x | x | x | x | x | x | x | |
| Impact assessments | Specific risks Required | x | Specific risks Required | Specific risks Recommended | x | x | x | Specific risks Recommended | |
| Data Breach Notification (within specific timeframes) | Supervisory authority | Local authority | No specific authority | No specific authority | AAMCEP’s authority | Supervisory authority | |||
| Fines for non-compliance | Non-compliance, reputational damage and legal impact | Fines for non-compliance | |||||||
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2024 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).