Photo by Andrew Moca on Unsplash
This article summarises Privacy International's view on why a rights based approach to digital health is needed for privacy.
Governments and companies should take a rights-based approach to healthcare. That’s because people - and their rights - should be the central concern for the design of healthcare policy.
A human rights based approach (or HRBA) is a conceptual framework that puts human rights and corresponding state obligations at the heart of policy. It can be used as a tool to empower people to participate in decision-making processes and hold duty-bearers accountable.
Ensuring both that people are involved and engaged, and that states are adequately resourced, are necessary to prevent healthcare initiatives, especially digital health, from negatively affecting privacy.
Photo by Andrew Moca on Unsplash
Healthcare needs privacy. Sometimes this is obvious: patient-doctor confidentiality means that our conversations with healthcare providers must remain private. But there are deeper, more complex, and at times more contested, questions too. For example, over who should have access to what resources and what data, for what reasons, and at what cost.
Global and local inequalities in access to both healthcare and digital services adds to this complexity. Everyone has a right both to the highest attainable standard of healthcare, and to privacy. But people’s needs in relation to them can differ. What states must do to provide for those rights, so that they can both be achieved without unfair or unacceptable trade-off, needs careful consideration. Rolling out digital healthcare services may seem like a cost-efficient way to improve access to healthcare, but it can negatively affect people’s privacy, in particular when the private sector is relied on for delivery.
This article explores how taking a human rights-based approach to healthcare can help understand the challenges of improving healthcare while safeguarding privacy, and what steps can be taken towards an approach that meets everyone’s needs.
People - and their rights - should be the central concern for the design of healthcare policy. Decisions in healthcare affect people deeply and personally, and so people must be involved and able to engage in the process. This is needed to ensure that healthcare services are meeting all of peoples’ needs. Of course that includes the quality of healthcare itself, but it can also be crucial in directing decisions away from those that negatively impact people’s privacy.
Privacy is intimately connected to healthcare because healthcare is itself deeply intimate. Accessing treatment involves revealing sensitive information about our bodies, our minds and our lifestyles (such as what we look like under our clothes, who we have sex with, or how invasive thoughts affect our mood). Medical professionals have long taken confidentiality seriously, and the design of healthcare policy must also be serious about people’s right to privacy.
Within the world of development, the notion of taking a “human rights-based approach” (HRBA) means doing just that: foregrounding people, their rights, and their involvement in the design - and the execution - of projects, plans and policies. The core idea is that development activities should be about building resilient and fair communities who can participate in the world equally, and on their terms. After all, the availability and accessibility of good quality healthcare is not a gesture of charitable goodwill: it’s something that we all inherently deserve as human beings.
Taking an HRBA therefore demands a systemic approach. It’s about understanding and embracing the complexity and diversity of human lives, and building institutions which have the mandate and the resources to uphold human rights. That means putting in place the right kind of measures in the design of digital health interventions, with proper consideration of the following:
People should be treated as actors rather than mere recipients, with proper involvement in decisions that affect them. It is essential that everyone knows their rights and how to demand them, both for themselves and on behalf of others. Activities and actions should therefore be locally defined and led, ensuring relevance and ownership. This will require capacity building, which must operate as a two-way street. Duty-bearers (such as government departments and regulators) must also be empowered and adequately resourced. Lastly, participation is both a means and an end in itself - it can lead to better decisions, improves relationships and challenges power imbalances.
The patterns and root causes of inequality, discrimination and other power imbalances should be addressed and challenged. That requires transforming power relations (in particular between health providers, private companies building health tools and systems, and right-holders), as well as promoting equality and non-discrimination. In doing so, no-one should be left behind: human rights are universal, and this must be reflected in both policy and implementation. To achieve real inclusion, marginalised and excluded groups must be placed at the centre of decision-making and prioritised throughout. Taking an HRBA means:
The legal and political dimensions of human rights must also be properly accounted for. Because human rights are entitlements rather than simply preferences, fulfilling them is a matter of justice, not of goodwill. Human rights therefore make legal, political and moral demands and require legal, political, and institutional accountability. Those institutions must take the demands of human rights seriously: responding to the political demands about how society should be organised and governed. Doing so can also help to further them in the collective consciousness. At the same time, human rights are legal constructs, grounded in law and enforceable through the courts, where they must be heard and upheld.
The above aspects of taking a human rights based approach are sometimes described as the PANEL (or PLANET) principles, which stands for:
Organisations working on digital health issues, including PI, often call for governments and companies to take a rights-based approach to healthcare. That’s because we believe that people - and their rights - should be the central concern for the design of healthcare policy.
The purpose of the above measures is to ensure that wider views and considerations - including about privacy - are properly accounted for in the design and deployment of digital health. While the provision of healthcare necessarily entails investigation of intimate matters, that does not mean that the right to privacy and the right to health are always in tension. Instead it means that, properly understood, a rights-based approach to digital health requires thorough consideration of, and compatibility with, people’s privacy needs.
In practice, that means avoiding particular interventions that have an unacceptable level of privacy intrusion. The data intensive nature of many digital systems means special care is needed here. So, for example, strong and enforced rules around the use and protection of health data are needed. Its sensitivity - and its value in being shared for research and other purposes - mean that it warrants special and robust legal regimes. Law, policy and governance measures will also be needed to ensure that the privacy impacts of digital health tools are properly assessed and accounted for.
Context always matters - different situations will demand different degrees of protection. Who can access and use health data depends on both the identity and the motivation of the other party. You may expect that speaking to your GP about a health condition entails a certain loss of privacy, but that doesn’t mean that your data about that interaction can then be shared with third parties without your knowledge and permission. You might be happy for your data to be used carefully to support research into a disease that runs in your family, but that doesn’t mean you want identifiable information about you to support private profits or inform law enforcement. Maybe you find an app really useful to help you understand your health better, but that doesn’t mean that it’s ok for the data collected to be sold to advertisers.
The answer is not entirely about rules and regulation. People and communities must also be informed, educated, involved and empowered so that they can understand how digital health will impact them. Everyone must also be able to participate in digital health in ways that meet their needs. That may not always be straightforward and people will always have differing priorities and viewpoints, especially given the complexity and sensitivity of both healthcare interventions and data governance. But it is needed regardless of the context or part of the world in which digital health tools are being relied on.
Finally, digital health initiatives can have particular impact on already-marginalised communities. That can come about because of a lack of access to digital services (the digital divide), or where matters related to healthcare are criminalised or stigmatised (for example in relation to sexual health). In such circumstances, a HRBA demands care and sensitivity that such groups are not left behind and their position not inadvertently worsened. In these contexts, taking care to respect and protect privacy is especially crucial.
If the promises of digital health are to be met - promises of more widely available, more efficient, more personalised healthcare - a rights-based approach must be taken. People and communities must not be left out or left behind. And concerns over privacy must be acknowledged and addressed.
For national goverments, that means putting in place the required law and governance structures rather than rushing through new innovations. For public healthcare providers, it means facing up to the demands of learning about how new technology works and how it affects people. For National Human Rights Institutions, it means monitoring performance and providing resources. Global actors must also be supportive of these efforts. And the private sector has a role to play too - tech companies engaging in healthcare and health companies designing new tech also have human rights obligations, and should model best practice in the fulfillment of people’s rights.