HEALTH DATA REGULATION

Ana Maria de Almeida

by Luísa Rego
translation Arisai Vogel
photograph Luísa Ferreira

 

“IT IS IMPORTANT TO LET THE DATA SPEAK FOR ITSELF ”

 


Devices that support the monitoring of health conditions, or which are themselves part of the treatment — such as pacemakers or other implanted devices — are becoming increasingly common. Medical data is stored — but access to it needs to be regulated.


 


Ana 1

  

Nature makes revelations,” said the poet Drummond de Andrade. This maxim also applies to researchers in mathematics, computing and complexity sciences, who seek to be amazed by every project and who believe that data not only answers questions, but also tells its own stories. Let’s learn to listen to them.

 

How does Artificial Intelligence raise concerns when we talk about medical devices?

The interaction between AI and medical devices allows researchers to extract knowledge from device data and detect abnormal conditions. Under the Artificial Intelligence Act (AI Act), there must be a standardised interface for interaction. This does not refer to the device itself, as that is covered by engineering standards. The issue is having official technical standards for what data we can process and how to process it. And they aren’t actually in place yet!

 


Whatever device we use, such as an insulin pump, we know that we are being monitored.


  

What needs to be done?

The European Union (EU) already has a broad standardization framework for AI applications, but healthcare really needs its own specific rules. We are working with an international team to build this medical standard, which we will present soon to global organizations.

 

Will it be a standard?

Yes. It establishes rules on how devices should connect to patients, what can and cannot be done with the extracted data, how to store it, and who has access for clinical purposes... All of this takes into account that we are in Europe, where we have the General Data Protection Regulation (GDPR) and the AI Act, which require transparency, accountability, and tracking exactly who accesses data and which applications use it. Even if a patient makes their data available, an AI system must specify what it used, when, for what purpose and how. And some forms of data processing aren’t allowed at all. This standard will bring together the regulatory rules, the technical side, and the use of these platforms in everyday clinical practice.

 

Is Iscte’s AI Health (AIH) project part of an ongoing international effort?

Yes. I am also involved in another EU-funded project where various expert panels
— I sit on the Artificial Intelligence group —are working to establish true interoperability. We are trying to coordinate efforts across Europe, Canada, the US and China so that, when standards are established, they are truly global. Our project aligns with a major shift in how medical and pharmacological data is handled, known as ’distributed learning.’ Sensitive medical data — now referred to as ’special categories’ — must remain as private as possible.

Whatever device we use, such as an insulin pump, we know we are being monitored (all sensor-equipped devices can be tracked remotely). In the Portuguese National Health Service (SNS), patients have to visit the hospital periodically to have their device data extracted and analyzed. This will no longer be necessary, as the data can now be streamed and used remotely in real time.

 

But what is “distributed learning”?

The current trend in medicine and pharmacology is acknowledging that data is “local”. This is where on-device computing comes in. The data stays right there on the sensor, the machine, or the patient’s smartphone — it stays with the person. When something out of the ordinary happens, the system sends an alert to a central server. This approach adds an extra layer of security and prioritizes patient privacy. This feeds directly into distributed learning: the AI applications run locally on the user’s hardware, and only essential data points are shared. It creates a highly robust security layer. On top of that, our standard leverages blockchain technology to create immutable logs of everything that happens to that patient data. But to make this work globally, we have to standardize the process of distributed learning and clearly specify what information can be transmitted from time to time and exactly how it is sent.

 

Do you see the Portuguese government adopting a standard like yours as a benchmark for best practice?

Yes, exactly. It follows the same model the government uses when implementing ISO standards. The idea is to create a blueprint that states and governments can integrate into their own AI governance frameworks. There is already an ISO standard for AI, albeit in its infancy, but it does not cover all possibilities.

 

Aren’t there any bodies monitoring and guiding the development of AI?

Actually, Europe is leading the way with the AI Act alongside related laws like our broader digital regulations. Attempts are being made to set up supervisory authorities, but this requires standards and guidelines. I am a European expert on ethical issues and have been following the whole process.

 


Ethical issues are fundamental, not least because they define who we are; they are our humanity. Without ethics, we are not human.


   

Why are you also drawn to ethical issues?

Ethics are fundamental, not least because they define our humanity. This is extraordinarily important because any scientist setting out to do something wants to do something good, for the betterment of society. That doesn’t mean that the resulting research can’t be misused or steered in harmful directions.

Science has long recognized that code of conduct and ethics are vital to our practice. And, in fact, everything we are developing in the fields of computer science and AI can easily be misused. Hence the concerns about cybersecurity, hackers, and so on.

 

Should there be training in ethics as part of technology courses?

Ethical concerns are part of who we are, although they have historically been left out of university curricula in the STEAM (Science, Technology, Engineering, Arts and Mathematics) fields. It would be good to introduce dedicated modules on ethics.

I really like the idea that says: “Ethics is not about distinguishing between right and wrong, but about knowing what one can do for good and for evil.” Ethics needs to be discussed at length because it is easy to carry out research without considering the impact it will have. In European projects within physics, mathematics, or astronomy, it is often argued that a project won’t have an impact because it does not involve ethical principles. Of course it does! Research that apparently has a neutral impact can easily be applied, for instance, in security or healthcare, and therefore it no longer has a neutral impact.

 

You’ve called yourself “a curious explorer of the universe.” What first drew you to complexity science, math, and data?

I’ve always been deeply curious about how the world works, ever since childhood. I think I get that from my father — he was a very restless person who constantly encouraged us to figure things out and ask: “why are things the way they are?”

The language of the world around us is mathematics, so entering the field felt inevitable. There’s a void there, and any structural flaw could bring the whole framework crashing down. So, I started searching. From human biology to massive societal networks, everything interacts in ways we don’t fully understand. What makes our brains work? What is intelligence? We don’t know! But trying to find some mathematical explanation for things made me realise that they are even more beautiful than I could ever have imagined. I’ve always gone down that path, trying to simplify what seems complex, always asking: “Why? But why is it like that?”

 

You write papers on topics ranging from the stock market to domestic energy, megalithic monuments, the power of social media, start-ups, and hotel searches. What connects them?

Yes, the subject areas are diverse, but the tools are always within my area of expertise: I’m not developing theory just for the sake of the algorithm or the theorem — I want the practical application. That is why I strongly advocate for a direct connection between academia and society.

 

What advice would you give to a researcher who hasn’t had much exposure to data science?

The algorithmic side can feel far too technical at first. But the real key is simply understanding the data — look at it, and instead of forcing it to say what you want, let it tell its own story. This applies to anyone, regardless of whether they know advanced math or not. That’s the core of it: more and more, we have to ask why things are the way they are. All information carries meaning, but when you break it down into smaller pieces, it reveals even more. We also need to remain open to evolving our tools, always keeping that “why” perspective in mind, always questioning: “where does this come from?” Guided by curiosity and a spirit of exploration, we can always push boundaries. We must never lose our sense of wonder. 

 


Ana P

 

Ana Maria de Almeida

ISTAR-Iscte
Information Sciences, Technologies and Architecture Research Centre

 

 

 

AIH

The surge in digital health devices makes it vital to create guidelines for data storage and AI application processing.