Skip to main page content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Access keys NCBI Homepage MyNCBI Homepage Main Content Main Navigation
Review
. 2025 Jun 4:11:20552076251343959.
doi: 10.1177/20552076251343959. eCollection 2025 Jan-Dec.

Data privacy in healthcare: Global challenges and solutions

Affiliations
Review

Data privacy in healthcare: Global challenges and solutions

Andrew Kweku Conduah et al. Digit Health. .

Abstract

Purpose: This study explores global frameworks for healthcare data privacy, focusing on the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Protection of Personal Information Act (POPIA). It examines the challenges of regional regulatory disparities, systemic vulnerabilities identified through major health data breach case studies, and the potential of advanced technologies to enhance privacy protections.

Methods: A qualitative research approach was adopted, incorporating corpus construction and comparative analysis of legal and technical frameworks. The study also utilized case studies of significant health data breaches to identify vulnerabilities and evaluate the role of emerging technologies, such as artificial intelligence (AI) and machine learning (ML), in mitigating risks and enhancing regulatory compliance.

Results: Findings indicate that GDPR, CCPA, and POPIA set high standards for data protection but reveal significant variability in enforcement and technological adoption across regions. Challenges include inconsistent definitions of sensitive data, semantic discrepancies, a lack of standardized protocols, and limited information technology infrastructure in certain jurisdictions. Advanced technologies like AI and ML promise to address these gaps by improving data harmonization and security.

Conclusions: Addressing healthcare data privacy challenges requires harmonized global regulations, advanced technological tools, and international collaboration. Strengthening frameworks, enhancing information technology infrastructure, and employing semantic models and ontologies are essential for protecting sensitive data, ensuring compliance, and fostering public trust in digital healthcare systems.

Keywords: California Consumer Privacy Act (CCPA); Data privacy; General Data Protection Regulation (GDPR); Protection of Personal Information Act (POPIA); data security; healthcare.

PubMed Disclaimer

Conflict of interest statement

The authors declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.

Figures

Figure 1.
Figure 1.
Coding process for deriving theme. This diagram illustrates the coding process: starting with the compilation of a comprehensive table of studies, the three authors independently coded the data to identify recurring patterns. Discrepancies were resolved through consensus-based discussions, leading to the grouping of codes into thematic categories and ultimately deriving four main themes (2025).
Figure 2.
Figure 2.
Thematic framework for global healthcare data privacy. This diagram illustrates the four main thematic areas derived from our review: (1) regional variability in data privacy challenges, (2) technological vulnerabilities and systemic weaknesses, (3) best practices and proactive responses, and (4) innovative solutions and advanced technologies.
Figure 3.
Figure 3.
Key considerations to inform policy. Adopted from Health Information and Quality Authority, 2022.

Similar articles

References

    1. Marques IC, Ferreira JJ. Digital transformation in health: A systematic review of 45 years of evolution. Health Technol (Berl) 2020; 10: 575–586.
    1. Keshta I, Odeh A. Security and privacy of electronic health records: Concerns and challenges. Egypt Inf J 2021; 22: 177–183.
    1. Fraser R. Data privacy and security. Introduction to nursing informatics 2021: 267–293.
    1. World Health Organization (WHO). Health data privacy policy brief. Geneva: WHO, 2024. Available from https://www.who.int.
    1. UNESCO. Privacy policy. Paris: UNESCO, 2024. Available from: https://www.unesco.org

LinkOut - more resources