Ensuring GDPR Compliance and Security in a Clinical Data Warehouse: Challenges and Insights from a University Hospital (Preprint)

Author:

Riou ChristineORCID,El Azzouzi MohamedORCID,Hespel AnneORCID,Guillou EmericORCID,Coatrieux GouenouORCID,Cuggia MarcORCID

Abstract

BACKGROUND

The digital transformation of health data has enabled the utilization of advanced data analytics and Artificial Intelligence (AI) techniques, which are crucial for driving innovation in healthcare. Countries such as France, the UK, Germany, and the US have adopted strategies to secure and ethically manage health data. In France, the Health Data Hub and clinical data warehouses (CDWs) within hospitals are central to this effort. However, the stringent regulatory framework, including the GDPR and French Data Protection Act, presents significant implementation challenges

OBJECTIVE

This paper aims to evaluate the applicability of the French CNIL CDW framework through an experiential analysis of its implementation and operational challenges in university hospitals within the French Great Western region . The study seeks to provide insights into the encountered obstacles and propose areas for improvement to enhance compliance and facilitate research.

METHODS

A detailed evaluation was conducted in may 2023 at the University Hospital of Rennes (CHU de Rennes) on the compliance of their eHOP CDW with the CNIL framework. The study categorized the framework’s requirements into those applicable to the eHOP software and those relevant to the institution's implementation. Each criterion was assessed by technical managers and data protection officers, with validation by information security officers.

RESULTS

Out of 116 criteria in the CNIL framework, 25 were identified as relevant to the eHOP software, with 15 criteria fully compliant, 7 non-compliant or partially compliant, and 3 not applicable. Institutional responsibilities covered 91 criteria, with several key areas identified as non-compliant or partially compliant, primarily involving security and governance measures. Notably, challenges in data retention management, encryption of sensitive genetic data, and robust authentication mechanisms were highlighted.

CONCLUSIONS

The study underscores both the benefits and challenges of implementing the CNIL CDW framework, emphasizing the need for technological and organizational adaptations to meet compliance requirements. Proposed adjustments aim to streamline research processes while maintaining stringent data protection. This evaluation offers valuable insights for other institutions and frameworks aiming to balance rigorous data protection with research and innovation needs. Future research should extend the scope to include multiple institutions and CDW technologies to validate and generalize these findings.

Publisher

JMIR Publications Inc.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3