Riou Christine, El Azzouzi Mohamed, Hespel Anne, Guillou Emeric, Coatrieux Gouenou, Cuggia Marc
University Hospital of Rennes, 2 rue Henri Le Guilloux, Rennes, 35000, France, 33 0299284215.
DOMASIA, LTSI, UMR INSERM, University of Rennes, Rennes, France.
JMIR Med Inform. 2025 Apr 17;13:e63754. doi: 10.2196/63754.
The European Union's General Data Protection Regulation (GDPR) has profoundly influenced health data management, with significant implications for clinical data warehouses (CDWs). In 2021, France pioneered a national framework for GDPR-compliant CDW implementation, established by its data protection authority (Commission Nationale de l'Informatique et des Libertés). This framework provides detailed guidelines for health care institutions, offering a unique opportunity to assess practical GDPR implementation in health data management.
This study evaluates the real-world applicability of France's CDW framework through its implementation at a major university hospital. It identifies practical challenges for its implementation by health institutions and proposes adaptations relevant to regulatory authorities in order to facilitate research in secondary use data domains.
A systematic assessment was conducted in May 2023 at the University Hospital of Rennes, which manages data for over 2 million patients through the eHOP CDW system. The evaluation examined 116 criteria across 13 categories using a dual-assessment approach validated by information security and data protection officers. Compliance was rated as met, unmet, or not applicable, with criteria classified as software-related (n=25) or institution-related (n=91).
Software-related criteria showed 60% (n=15) compliance, with 28% (n=7) noncompliant or partially compliant and 12% (n=3) not applicable. Institution-related criteria achieved 72% (n=28) compliance for security requirements. Key challenges included managing genetic data, implementing automated archiving, and controlling data exports. The findings revealed effective privacy protection measures but also highlighted areas requiring regulatory adjustments to better support research.
This first empirical assessment of a national CDW compliance framework offers valuable insights for health care institutions implementing GDPR requirements. While the framework establishes robust privacy protections, certain provisions may overly constrain research activities. The study identifies opportunities for framework evolution, balancing data protection with research imperatives.
欧盟的《通用数据保护条例》(GDPR)对健康数据管理产生了深远影响,对临床数据仓库(CDW)具有重大意义。2021年,法国率先由其数据保护机构(国家信息与自由委员会)建立了一个符合GDPR的CDW实施国家框架。该框架为医疗机构提供了详细指南,为评估健康数据管理中GDPR的实际实施提供了独特机会。
本研究通过在一家大型大学医院实施法国的CDW框架,评估其在现实世界中的适用性。它确定了卫生机构实施该框架的实际挑战,并向监管机构提出了相关调整建议,以促进二次使用数据领域的研究。
2023年5月在雷恩大学医院进行了系统评估,该医院通过eHOP CDW系统管理超过200万患者的数据。评估采用了由信息安全和数据保护官员验证的双重评估方法,检查了13个类别的116条标准。合规情况分为符合、不符合或不适用,标准分为软件相关(n = 25)或机构相关(n = 91)。
软件相关标准的合规率为60%(n = 15),28%(n = 7)不符合或部分符合,12%(n = 3)不适用。机构相关标准在安全要求方面的合规率为72%(n = 28)。主要挑战包括管理基因数据、实施自动存档和控制数据导出。研究结果揭示了有效的隐私保护措施,但也突出了需要监管调整以更好支持研究的领域。
对国家CDW合规框架的首次实证评估为实施GDPR要求的医疗机构提供了宝贵见解。虽然该框架建立了强大的隐私保护,但某些规定可能会过度限制研究活动。该研究确定了框架演变的机会,平衡了数据保护与研究需求。