AI and medical ethics: what every healthcare professional must know
When the algorithm enters the care relationship Medical ethics is nothing new. The Hippocratic Oath, in its various modern versions,…
When a doctor dictates their report to an AI assistant, are they sending medical data to an American company? When a nurse uses a chatbot to look up a protocol, do they risk compromising a patient’s confidentiality? Can a hospital entrust the analysis of its records to an external algorithm without breaching medical confidentiality?
These questions are not paranoid. They are professionally legitimate, ethically serious, and legally important. And they deserve precise answers; not reassuring formulas as vague as “we’re GDPR-compliant.”
The reality is nuanced: yes, AI can be used with patient data, but under strict conditions, within well-defined frameworks, and with practices that differ according to the tools, the contexts and the types of data concerned.
Understanding these distinctions has become an essential professional skill for any caregiver who uses, or is considering using, AI tools in their practice.
The General Data Protection Regulation (GDPR), applied in France since 2018, classifies health data in the category of sensitive data, alongside genetic, biometric, religious data or data relating to sexual orientation. Their processing is in principle prohibited, unless one of the legal exceptions provided for by article 9 of the GDPR applies.
In healthcare, the main exceptions legitimising the processing of health data are:
In France, the CNIL (National Commission for Information Technology and Civil Liberties) is the competent supervisory authority. It has significant powers of sanction: up to 4% of a company’s global turnover, or €20 million.
This is data that makes it possible to directly identify a person: surname, first name, social security number, precise date of birth, address, telephone number. Coupled with medical information, it constitutes personal health data in the strictest sense.
Pseudonymisation consists of replacing direct identifiers with a code or an artificial identifier, while retaining the possibility of re-identifying the person if necessary. Pseudonymised data remains personal data within the meaning of the GDPR.
Anonymisation, in the strict sense of the GDPR, refers to the process by which any possibility of re-identification is irreversibly removed. Truly anonymised data is no longer personal data and can therefore be processed freely.
⚠ The problem? True anonymisation is technically difficult to achieve, especially in healthcare. Studies have demonstrated that it is possible to re-identify patients from seemingly anonymised data by cross-referencing different sources.
A healthcare professional who uses an AI tool in the context of the direct care of their patients may, under certain conditions, process health data with that tool. The main condition is that the tool be GDPR-compliant and that the processing of the data be covered by a Data Processing Agreement (DPA) with the provider.
This is where the risk is most often poorly assessed. Tools such as ChatGPT in its free or standard version, or other mainstream conversational AIs, are not GDPR-compliant processors for the processing of health data.
⚠ Entering a patient’s name, social security number, history, test results or any element allowing their identification into a mainstream tool constitutes a breach of the GDPR and a violation of medical confidentiality.
The practical rule is simple: if you need AI to write a letter, prepare a standard response, look up information or generate a generic document, you can use these tools by systematically replacing the patient’s information with generics (“the patient,” “the 65-year-old female patient with a history of type 2 diabetes,” etc.).
Several generative AI publishers offer versions specifically designed for professional uses, including suitable GDPR guarantees. This is the case for Microsoft Azure OpenAI Service, Claude for Enterprise from Anthropic, or French and European solutions such as Mistral AI and its professional offerings dedicated to the healthcare sector.
The Health Data Hub (HDH), created by the Ma Santé 2022 law, is the national platform that centralises and secures French health data to allow its exploitation for research and innovation purposes. Access to HDH data is subject to a strict authorisation process, managed jointly by the CNIL and the CESREES.
The GDPR is not the only applicable framework. Medical confidentiality, enshrined in article L. 1110-4 of the French Public Health Code, applies to all healthcare professionals.
Concretely, this means that:
Before using a new AI tool, systematically ask three questions: Where is the data I enter into it stored and processed? Is the publisher bound by a GDPR processing contract with my establishment or my structure? Can the data be used to train the model or transmitted to third parties?
Distinguish between uses with real data and generic uses. For anything that can be done without identifying data; looking up information, drafting letter templates, preparing therapeutic-education materials; you can use mainstream tools freely.
Consult your establishment’s DPO. All healthcare establishments are required to designate a Data Protection Officer.
Document your uses. The GDPR is based on a principle of accountability.
Train. The European Artificial Intelligence Act, which came into force in 2024, introduces new obligations for high-risk AI systems used in healthcare.
The European Regulation on artificial intelligence (AI Act), adopted in 2024 and whose provisions apply gradually until 2027, classifies AI systems used in healthcare in the “high risk” category.
For healthcare professionals as users, the AI Act does not create new direct obligations, but it strengthens the requirements placed on the publishers of the tools you use.
The question “can AI be used with patient data?” calls for a clear answer: yes, within a precise legal framework, with compliant tools, under the supervision of a responsible professional.
The good news is that this understanding can be acquired. It does not require in-depth legal training, but a few hours of structured learning are enough to transform a source of anxiety into a genuine professional skill.
Sources and references (10 sources cited, including the GDPR, the French Public Health Code, CNIL documentation, the Health Data Hub, and scientific articles)