Data privacy in healthcare: Global challenges and solutions
- PMID: 40475296
- PMCID: PMC12138216
- DOI: 10.1177/20552076251343959
Data privacy in healthcare: Global challenges and solutions
Abstract
Purpose: This study explores global frameworks for healthcare data privacy, focusing on the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Protection of Personal Information Act (POPIA). It examines the challenges of regional regulatory disparities, systemic vulnerabilities identified through major health data breach case studies, and the potential of advanced technologies to enhance privacy protections.
Methods: A qualitative research approach was adopted, incorporating corpus construction and comparative analysis of legal and technical frameworks. The study also utilized case studies of significant health data breaches to identify vulnerabilities and evaluate the role of emerging technologies, such as artificial intelligence (AI) and machine learning (ML), in mitigating risks and enhancing regulatory compliance.
Results: Findings indicate that GDPR, CCPA, and POPIA set high standards for data protection but reveal significant variability in enforcement and technological adoption across regions. Challenges include inconsistent definitions of sensitive data, semantic discrepancies, a lack of standardized protocols, and limited information technology infrastructure in certain jurisdictions. Advanced technologies like AI and ML promise to address these gaps by improving data harmonization and security.
Conclusions: Addressing healthcare data privacy challenges requires harmonized global regulations, advanced technological tools, and international collaboration. Strengthening frameworks, enhancing information technology infrastructure, and employing semantic models and ontologies are essential for protecting sensitive data, ensuring compliance, and fostering public trust in digital healthcare systems.
Keywords: California Consumer Privacy Act (CCPA); Data privacy; General Data Protection Regulation (GDPR); Protection of Personal Information Act (POPIA); data security; healthcare.
© The Author(s) 2025.
Conflict of interest statement
The authors declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Figures



Similar articles
-
Regulatory challenges of digital health: the case of mental health applications and personal data in South Africa.Front Pharmacol. 2025 Apr 30;16:1498600. doi: 10.3389/fphar.2025.1498600. eCollection 2025. Front Pharmacol. 2025. PMID: 40371347 Free PMC article.
-
Data stewardship and curation practices in AI-based genomics and automated microscopy image analysis for high-throughput screening studies: promoting robust and ethical AI applications.Hum Genomics. 2025 Feb 23;19(1):16. doi: 10.1186/s40246-025-00716-x. Hum Genomics. 2025. PMID: 39988670 Free PMC article. Review.
-
Federated Machine Learning, Privacy-Enhancing Technologies, and Data Protection Laws in Medical Research: Scoping Review.J Med Internet Res. 2023 Mar 30;25:e41588. doi: 10.2196/41588. J Med Internet Res. 2023. PMID: 36995759 Free PMC article.
-
Data Obfuscation Through Latent Space Projection for Privacy-Preserving AI Governance: Case Studies in Medical Diagnosis and Finance Fraud Detection.JMIRx Med. 2025 Mar 12;6:e70100. doi: 10.2196/70100. JMIRx Med. 2025. PMID: 40072927 Free PMC article.
-
Challenges and Progress in General Data Protection Regulation Implementation in Romanian Public Healthcare.Cureus. 2025 Jan 26;17(1):e78008. doi: 10.7759/cureus.78008. eCollection 2025 Jan. Cureus. 2025. PMID: 40007929 Free PMC article.
References
-
- Marques IC, Ferreira JJ. Digital transformation in health: A systematic review of 45 years of evolution. Health Technol (Berl) 2020; 10: 575–586.
-
- Keshta I, Odeh A. Security and privacy of electronic health records: Concerns and challenges. Egypt Inf J 2021; 22: 177–183.
-
- Fraser R. Data privacy and security. Introduction to nursing informatics 2021: 267–293.
-
- World Health Organization (WHO). Health data privacy policy brief. Geneva: WHO, 2024. Available from https://www.who.int.
-
- UNESCO. Privacy policy. Paris: UNESCO, 2024. Available from: https://www.unesco.org
Publication types
Associated data
LinkOut - more resources
Full Text Sources