Review and Inquiries on Ethics, Policies and Regulations of a Global Patient co-Owned Cloud (GPOC)

preprint OA: closed CC-BY-4.0
📄 Open PDF Full text JSON View at publisher

Abstract

Cloud-based personal health records have increased during the last thirty years across the globe. The concept of a Global Patient co-Owned Cloud (GPOC) of personal health records is presented in the GPOC series. It encompasses a systematic review and meta-analysis, a global survey among 100% of the UN member states and a technical sandbox. GPOC introduces patient co-ownership of personal health records. Here, we review the ethics, rights, privacy, co-ownership, policies, security, technique, initiatives, regulation, market, AI integration, and future challenges relevant to GPOC. We also included novel data from a series of over a hundred interviews with representatives of fifty national health ministries from all over the world and international organisations. Over 90% of the interviewees strongly endorsed the idea that co-ownership should be a human right. Similarly, consensus was attained for all the twelve reviewed aspects. Our hybrid approach, combining narrative review with interviews of senior state and organizational health experts, offers original insights and in-depth analysis of key aspects relevant to GPOC. Notably, the enthusiasm for the GPOC concept was unanimous. Moreover, we provide a comprehensive global overview of aspects of relevant human rights, ethics, privacy, policy, regulations, and integration initiatives by states and organisations. We also analysed the incumbent health record market, AI integration, and future challenges for a GPOC. Furthermore, we offer a holistic analysis of regulations, the global nature of AI, and its implications for healthcare. These discussions contribute to the ongoing discourse on the ethical and societal implications of emerging technologies in healthcare. Finally, the present study indicates that GPOC might result in a new human right to co-own one’s personal health information. GPOC could drive development and spread of artificial intelligence for healthcare globally. It may solve the lacking personal health record integration on a global scale. Thus, a decentralised GPOC with consensus from blockchain, may benefit global health.
Full text 144,043 characters · extracted from preprint-html · click to expand
Review and Inquiries on Ethics, Policies and Regulations of a Global Patient co-Owned Cloud (GPOC) | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Systematic Review Review and Inquiries on Ethics, Policies and Regulations of a Global Patient co-Owned Cloud (GPOC) Niklas Lidströmer, Joe Davids, Mohamed ElSharkawy, Hutan Ashrafian, and 1 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-4198485/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Cloud-based personal health records have increased during the last thirty years across the globe. The concept of a Global Patient co-Owned Cloud (GPOC) of personal health records is presented in the GPOC series. It encompasses a systematic review and meta-analysis, a global survey among 100% of the UN member states and a technical sandbox. GPOC introduces patient co-ownership of personal health records. Here, we review the ethics, rights, privacy, co-ownership, policies, security, technique, initiatives, regulation, market, AI integration, and future challenges relevant to GPOC. We also included novel data from a series of over a hundred interviews with representatives of fifty national health ministries from all over the world and international organisations. Over 90% of the interviewees strongly endorsed the idea that co-ownership should be a human right. Similarly, consensus was attained for all the twelve reviewed aspects. Our hybrid approach, combining narrative review with interviews of senior state and organizational health experts, offers original insights and in-depth analysis of key aspects relevant to GPOC. Notably, the enthusiasm for the GPOC concept was unanimous. Moreover, we provide a comprehensive global overview of aspects of relevant human rights, ethics, privacy, policy, regulations, and integration initiatives by states and organisations. We also analysed the incumbent health record market, AI integration, and future challenges for a GPOC. Furthermore, we offer a holistic analysis of regulations, the global nature of AI, and its implications for healthcare. These discussions contribute to the ongoing discourse on the ethical and societal implications of emerging technologies in healthcare. Finally, the present study indicates that GPOC might result in a new human right to co-own one’s personal health information. GPOC could drive development and spread of artificial intelligence for healthcare globally. It may solve the lacking personal health record integration on a global scale. Thus, a decentralised GPOC with consensus from blockchain, may benefit global health. global patient co-owned cloud GPOC personal health records medical ethics health policies medical regulation cloud-based health blockchains artificial intelligence in medicine Figures Figure 1 Figure 2 BACKGROUND The idea of a global, cloud-based, trustless, decentralised, multi-stakeholder, co-owned and secure cloud for healthcare was almost unimaginable a few decades ago. This idea embodies a global and securely blockchain protected, worldwide distributed and patient co-owned platform of personal health records (PHR, ISO/TR 14292:2012). This embodies our concept of a Global Patient co-Owned Cloud (GPOC) 1 . Prior to our recent systematic review and meta-analysis, no publications have delved into this topic, nor presented co-ownership models on a global scale. 1 The GPOC publication series commenced with a systematic review and meta-analysis of a dozen pivotal facets of a GPOC. 1 Hereafter, the concept’s necessity was explored in the GPOC Survey, revealing a global consensus 2 . This received answers from all key opinion leaders of 193+3 United Nations’ member states and the 18 largest international health care organisations. 2 Thus, the technical and mathematical foundations were shaped, resulting in a GPOC sandbox environment. 3 Subsequently, a GPOC Summit, conducted in a Delphi style, supplemented the survey findings, contributing to the ethical discourse on the GPOC concept. 4 At last, the series here contains an additional literature review of and interviews regarding the ethics and policies relevant for a GPOC. Core problems with personal health records are: 1) No or limited patient access, 2) No patient ownership, 3) No explicit right to share, 4) No integration or interaction across platforms, 5) Ineffective user interfaces, 6) Expensive, too expensive for many health economies. This is valid both locally and globally, but in some countries the patients have access. Moreover, there are security issues with current cloud-based PHR platforms. 1 Our hypothesis is that a Global Patient co-Owned Cloud (GPOC) of PHRs would solve the above conundrums. Moreover, a GPOC would be a large substrate for artificial intelligence development and dissemination, potentially democratising medicine across the globe. Though, carefully not to let any central power control the contents. The siloed use of AI on health data would be replaced by a global cloud resource. Today the UN Declaration on Human Rights forms the basis of humanitarian law as an integral component of global jurisprudence. 5 It consists of basic freedoms such as the right to liberty, security, one's own health and property. The modern human right concept and co-ownership of PHRs, may intertwine in our era of information dominance. However, owning one’s PHR is not stipulated as a human right. With GPOC a new human rights’ entity may come into fruition. Here, we extracted solely the co-ownership and security aspects from the GPOC systematic review. 1 Furthermore, we performed an additional literature overview of ethics with focus on human rights development, regulations, AI integration and the worldwide PHR market. See supplement S1. We supported his narrative review with a series of 100 interviews with regulators, relevant health organisations and government sources were conducted. Results have contributed to Table 2 that contains an overview of the global regulatory latticework. The interviews sought to answer the search questions, but also encompassed a wider and informative scope. See supplement S2 for the series’ structure and the state and organisation in interview participance. Hence, this is an overview of the ethical and juridical aspects of a GPOC. This to enable and facilitate its possible implementation in the near future. MAIN TEXT The GPOC Systematic Review and the Additional Review The GPOC systematic review of 9,362 articles retrieved 226 articles. It covered twelve facets relevant to the realisation of a GPOC. One-fifth dealt with ownership and data owners. 1 However, only two mentioned multi-ownership, but mentioned in a different context. 6,7 To our knowledge the exact term co-ownership does not appear in any published articles. In the GPOC Survey and GPOC Summit we introduced the concept. In both over 90% of respondents deemed it a human right to co-own PHRs. 2,4 We here present an overview of initiatives of regulatory bodies, ethical considerations and clinical limitations. The global latticework of regulations is found in Table 1, and global producers of PHRs in Table 2. Below, the results follow in twelve subentries (#1-12). Given the nature of the subjects, parts of the discussion will occur within these. Hence, the discussion entry ensuite summarises the overarching tendencies. 1: Relevant Human Rights Declarations Active participation in personal development is a human right in the United Nations’ Sustainable Development Goals (SDG) of 1986. 8 There are no UN declarations on PHRs. But in 2019 came the Declaration on Universal Health Coverage (UHC). Hitherto, it is the most wide-ranging attempt for universal health guarantees. 9 Here, the gender representation is pivotal. The GPOC interview series has an exact 50% gender balance. Likewise, the GPOC Summit, that mirrored the GPOC Survey 2 had an equal gender representation (Table 2 and S2). In the GPOC interview series a dominant opinion is that patient co-ownership, access, sharing rights and global PHR interaction with patient control is on the level of a new human right. 92% of interviewees deemed it a human right to co-own one’s medical data. For all responses see Figure 1. 2: Ethical Principles Five ethical principles that are universal for healthcare are: autonomy, justice, nonmaleficence, beneficence and fidelity. These are constantly elaborated in ethical discussions to explore dilemmas and better understand conflicting issues. 10 Nearly all, 98% of interviewees, agreed on the core of the medical ethics principles relevant for this area. A patient co-owned PHR means shared information and increased autonomy. The medical facts in the PHR are based on both the medical history provided by the patient and on physical examinations and investigations. Both are patient centric. Hence, it is a question of justice with patient access and co-ownership. Co-ownership could then lead to a revenue stream to the patient from anonymized research on PHR contents. Healthcare providers informing the patient and being transparent in the PHR towards the patient are parts of both beneficence and fidelity. With GPOC healthcare should be more effective and not harmful, i.e., nonmaleficence. 4,10 A basic Kantian enlightenment concept is the categorical imperative – ‘act so that your actions can be translated into universal law.’ 11 Following this, then evidently patients should be informed about their health and co-own their PHRs. 4 However, in clinical care all information cannot be inserted into the PHR. For instance, if it causes risks to a third person. In studies of PHRs with patient access, it has been noted that this type of information may be kept in other parallel notes or verbally, which is not recommended. 12 Moreover, a co-owned PHR may strengthen access rights. Hence, it may lead to a more granular regulation. Currently, patients’ PHR access varies a lot geographically. 13 A global overview of regulations are outlined in table 1. 3: Co-Ownership Co-ownership may encourage patients to actively contribute to the PHR. Some patients may have an interest in monitoring or ‘gatekeeping’ the access log of the PHR. Co-owning parties would be able to correct misunderstandings in the medical history or faulty contents. 4 Communication deficit is the commonest cause of legal conflicts in healthcare 14 . Co-ownership would improve communication and overall connectivity. It may decrease mistakes based on inaccurate PHR information. 90% of interviewees deemed co-ownership to be positive for healthcare. The patient’s freedom of expression in healthcare is essential. Hitherto, the direct voice of the patient has been silent in the PHR. Co-ownership could emphasise the right to PHR contribution. Also, the rights to PHR migration and sharing with anyone deemed relevant. Hence, there are advantages in emergencies, travel and refugee situations. The GPOC concept embodies these as human rights principles. The ownership question is also highlighted with the outsourcing to cloud service providers and producers of PHR software, for an overview of the market see table 2. Co-ownership may be a step in the evolution of medical ethics. There is an increase in the informing of the patient about their health status. Until the 1950s the Hippocratic concept of not informing was dominant. There has been a global decrease of paternalism since then. 15 The last thirty years of information revolution, widespread smartphone uses and patient PHR access has meant a democratisation of medicine. 16 There are concerns over data ownership for cloud service providers and manufacturers of PHRs, see table 2. Individuals and healthcare providers could lose control of highly sensitive data. 6 To address this issue, robust encryption protocols and secure data access mechanisms can be implemented. Additionally, strict regulatory frameworks and transparent data governance policies are essential to safeguard patient privacy and data security. There are methods to fully decentralising and linking open data platform specifications. These grant patients’ real ownership of their data and give them a fine-grained access control to share their PHRs. 17 . Here, it's crucial to not only consider but also actively address the potential risks posed by authoritarian regimes, which may seek to exploit personal health data for surveillance and control purposes. 4: Privacy Aspects The sources of big data, privacy concerns, trust issues in organisations and complex regulations may all hinder the progress of AI in healthcare. 34 Cloud computing may have the strength of revolutionising healthcare, but the progress is slow. Strict regulations on patient information are hindrances. However, there are new cloud models with revised privacy issues generally associated with cloud service providers. These use Fully Homomorphic Encryption (FHE), enabling computations on PHRs without seeing the underlying data. 18 Recently a relevant European Commission call for Cloud, Data and Artificial Intelligence in the Digital Europe Programme (DIGITAL) was announced. 19 80% of the interview participants deemed that privacy protection can be feasible with new technical solutions for cloud based PHRs. The rest either agreed with reservations or were neutral. See Figure 2 and supplement S5 for details. 5: Policy Aspects Timely international policy guidelines could facilitate the GPOC concept. Almost 90% in the interview series thought it possible to agree on international regulations. These should cover end-user policies and regulations to identities and accesses. 1,2,4 (S2). But also, network resilience, agreements, computational power, ‘big data’ mining capacities, privacy and security. 3 There is such guidance for an ‘intelligent cloud-based electronic health record’ (ICEHR) in line with healthcare regulations. 1,20 For overview see Table 2. 6: Security Aspects There are PHRs allowing patients to store and share contents securely in the cloud. These few platforms allow doctoral referrals and also sharing with a medical research intent. 21 Though, patients’ information remains private. Such platforms facilitate sharing across borders. Notably, with different regulations in various countries. 21 For overview see table 1. To our knowledge none of the large system mentioned in Table 2 allow fully encrypted sharing with research intent. Over 90% of interviewees expressed awareness of relevant security issues for a GPOC, but also expressed that a technical solution must be possible. (S2) Large amounts of data are generated by PHR clouds. However, the most common drawback with these techniques may be the combination of their patient-centric nature and the lack of sufficient security with fine-grained access control. This is crucial to comply with regulatory requirements. 22 Notably, 92% of responders in the interviews believed PHR security ought to be improved in their states or organisations. In the construction of PHR infrastructures, cloud-based ecosystems are used ubiquitously. And a GPOC must have an impenetrably safe cloud using a distributed blockchain. Therefore, engagement between regulators and stakeholders at international fora likely may provide insights into shaping the most applicable technologies. 1,4,22 7: New Technical Solutions and Ethics Technical solutions exist to achieve the GPOC concept. For example, the co-ownership issue with abundant medical images. To increase clinical practicalities, single modality images can be fused to clear multimodality images. The spread of these fused medical images rises new matters of authentication and ownership. 23 The privacy-preserving and secure Service Oriented Architecture (SOA) can integrate PHRs. Herein, patients could be “partly owners” and share or edit their PHRs. SOA enables full ownership of integrated PHRs. Owners may decide to share with healthcare providers or even insurance companies. 24,25 Co-owners of the PHR would be the patient, together with its managers, which are the doctors and nurses and their respective hospitals and clinics. These three owners are likely the only relevant ones. There are concerns that a broader division of the ownership of PHRs could potentially lead to sensitive data leaks, if stored in a cloud environment. 26 Currently the healthcare organisations are the sole PHR owners. Of the interviewees 80% found it logical to have a trisected ownership and another 20% agreed with reservations to discuss. Now though, patients have only limited information about the contents and then only upon receiving discharge summaries or specific report letters etc. This was an evident problem during the COVID-19 pandemic. The need for patients’ control became more accentuated. 27 8: Initiatives by Regulatory Bodies and Organisations The 2021 Federal Drug Agency (FDA) industry guidance aims at speeding up medical product development and creating innovations quicker, so that patients will benefit earlier. It focuses on electronic PHRs for clinical trials that may impact regulatory decision making. 28 78% of the series participants pointed out that in their state or organisations there were ongoing or planned initiatives that strived to improve PHR integration. However, not all PHRs are electronic yet. For instance, in the UK the Medicines and Healthcare Products Regulatory Agency (MHRA) leads the nationwide NHS initiative to replace all paper records with electronic PHRs. At the centre are ethical and practical considerations for research, clinical trials, and best clinical practice. MHRA, the Health Research Authority (HRA) and the Information Commissioner's Office (ICO), have presented guidance for medical research processed on PHRs. It is recommended to be read alongside the Data Protection Impact Assessments (DPIAs). 29 The World Health Organisation (WHO) carried out the Third Global Survey on eHealth in 2015 (GOE_Q144) to investigate PHRs globally. It collected data from 125 countries, with the then largest ever survey. 30 The WHO has produced a manual for developing countries on the implementation of PHRs. Here the requirements for the introduction, maintenance, content, staffing, ethics, and other regulatory considerations are presented, aiming at, e.g., staff of health ministries. 31 WHO has no global PHR project in under way, and GPOC entails a larger and wider concept. 1,2,3,4 (S2). In the USA the Office of the National Coordinator for Health Information Technology (ONC) works under the authority of the Health Information Technology for Economic and Clinical Health (HITECH) Act. The Department of Health has established improvement programs for healthcare quality, safety, including health IT and PHRs. 32 The Red Cross (ICRC) uses the Red Cross Health Information System (RCHIS) as the platform for emergency response, tailored for humanitarian situations. Here, medical personnel can manage patient information in the field. ICRC has also developed several apps for first aid and emergencies etc. Its main app RedSafe is a digital humanitarian platform that provides safe and secure services for people affected by conflict, migration and other crises. RedSafe also helps the ICRC to reach out to more people, in compliance with their own ICRC data protection standards. 33 The European Union (EU) published a synopsis of the members’ PHR laws and their compatibility with open internal border policies. 34 Under EU Law ‘Article 14 of Directive 2011/24/EU on the application of patients’ rights in cross-border healthcare,’ the eHealth Network aims at facilitating the interactivity between European PHRs. It aims to present pan-European guidelines for future cross-border transferability of PHRs. These need to conform with the existing EU data protection rules, including the General Data Protection Regulation (GDPR). A European Commission action plan aims to remove obstacles for integration and ‘a fully mature and interoperable eHealth system in Europe’. Although 24 of 30 surveyed states were not equipped for the EU vision of continental PHR interaction. 1,2,4,35 If realised, then a data substrate of such size may spark the development of AI integrated into PHRs. 1,4 Natural language processing and decision support systems woven in. 36 9: An Overview of Global Regulations The legislative, clinical and practical ramifications of co-ownership between the three involved parties (patients, clinicians and clinics), involves the resolution of some legal entanglements in the patient-doctor-clinic relationship across the world. For an overview of the global latticework of regulations see Table 1. The mentioned Global Data GDPR covers all 27 EU member states. Several other countries have been inspired. For instance, Nigeria with the Nigerian Data Protection Regulation (NDPR), which narrowly mirrors the GDPR. Across the world 66% of countries have data protection and privacy laws. Another 10% are drafting new legislation, 19% have no legislation, and for 5% of countries there is no data. 37 90% of interviewees deemed their state or organisation could integrate with international regulations and reach a global consensus. Table 1: Global Regulations Governing Data Privacy: A Comprehensive Overview An overview of the global latticework of regulations governing data privacy. Information collected from governmental sources in each country, and from a European Union overview of national member states’ legislation on PHRs. 38 (S1, S2) Source Data files are available in the article repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726 Table 2: Top Global Producers and Vendors of Personal Health Records (PHRs): A Comparative Analysis Global producers and vendors of PHRs. There are only four overlapping companies of the two top ten lists. Figures relate to the 1 st ranking. The 2 nd ranking is less exact. The USA dominance is equal in both lists. 39,40 (S1, S2) Source Data files are available in the article repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726 10: The Global PHR Market It is partly less clear which companies dominate this market. Table 2 attempts to overview the largest global PHR producers. Note the pronounced US dominance. Though, the regulation of PHRs is almost always coming from the country of implementation. An exception is when the PHR is part of a foreign aid program. Then the donor nation may influence the regulation. This can lead to legal imbalance or further dependency. There are also open-source solutions such as openEHR and Fast Healthcare Interoperability Resources (FHIR), which provide open standard specifications in health informatics. Notably, 64% of interviewees deemed the PHR market to be an oligopoly, another 12% agreed with some reservations and 20% were neutral. The producer overview is not complete though. There are also initiatives for nationwide platforms. For example, with the NHS in the UK, in the Nordics and in technically progressive Asian states, e.g., Japan, Singapore, and South Korea. These have demonstrated how clouds can be used to serve nationwide databases of PHRs, to backup both medical research and telemedicine. There are several such national cloud solutions for public health innovations relevant to a GPOC. 37 These existing national cloud-based solutions and data bases might provide a feasible foundation for a GPOC. 4 Globe Newswire estimates in their 2022 report that the total world PHR market will expand from the 2021 value of $32 billion to $34 billion in one year. The growth rate is then anticipated to be 8% per annum. It is further projected the global market will reach $44 billion in 2026 with an average annual growth rate (AAGR) of 7%. In contrast, a Grand View Research report, the total market size is estimated to $27 billion in 2021 and it anticipates a lower AAGR of 4% between 2022 and 2030. 42 11: Artificial Intelligence (AI) Integration 90% of interviewees regarded GPOC as a potentially positive force for health AI development and dissemination. Though, how AI can be optimally implemented into a GPOC is today a key policy conundrum. One component of this is how AI shall be able use data and interact with GPOC and generate results. Another is how GPOC and its anonymised PHR data becomes a substrate for global machine learning development. A third is under what conditions, for data protection, platform security management and product development. This will most likely depend on the users’ sharing and permissions. 1,2 Here we are faced with a novel online service paradigm that permits its users to share their health data. 43 Modern PHR software allow patients or caregivers to exchange or share contents. PHRs can now be fortified with AI to forecast patients' critical development enabling earlier therapeutic interventions. Moreover, electronic PHR are starting to be designed so they may interact with other healthcare platforms. However, currently a lot of them do not (Table 2). With older populations and increasing health budgets for the rest of the century this is needed. A GPOC, i.e., an AI empowered cloud-based PHR, designed to minimise medical mistakes may decrease costs by making healthcare more streamlined and qualitative. 44 Some of the aspects of a GPOC already exist in rare disease or oncological management. The creation of new oncological therapies is a global enterprise. The inclusion of patient experiences into clinical decision-making processes is focused thanks to the international regulatory and health policy communities. Symptoms of both diseases and therapies, and effects on functioning and life quality are essential. International regulatory scientists have identified topics to integrate Patient-reported outcome (PRO) measures into the regulatory and legislative processes. For instance, a GPOC would allow adverse effects reporting on a global scale. 45 The risks with cloud computing for PHRs may decrease if cloud providers complied with audits. Thus, regulation obedience for securing cloud data would lead to backups to protect against data loss. This is crucial as healthcare becomes dependent on AI integrated PHRs. 46 12: Future Challenges Challenging key factors affecting the adaptation to cloud PHR technologies in a Technology-organisation-Environment (TOE) are reliability, security, privacy, management support, hospital readiness, competitive situation, and the regulatory environment. 47 94% of interviewees deemed GPOC could play a pivotal role in future global TOE. Challenges include effective global regulatory engagement and development of policies relevant to a GPOC. Though, this may follow as a consequence of market evolution. This may be affected by a GPOC providing a large and anonymised source for global AI development. Hence, a GPOC could be self-sufficient and with co-owning patients receive revenue streams. Possibly a new microeconomy could arise. This may ignite the AI algorithm evolution and the global need for responsible AI health applications. 48 Potential risk of adverse implementations might be insurance companies demanding access to personalised information. Authoritarian leadership making decisions based on individual data. In theory a future market for patient PHR revenue reimbursements could emerge in a microflow of passive income to the co-owners. One part could be reimbursed to the patient and the other corporate component of co-ownership revenue could divert back to the maintenance of GPOC. The interview series contained >100 interviews resulting in 50 fused annotations (#1-50) for 42 states and 8 international organisations. Twelve questions were asked, corresponding to the review’s twelve subheadings 1-12 above. Percentages are based on one unified answer per entity (1/50=2%). Countries were weighted so that number of interviews was balanced. Each result has been quoted under the respective paragraphs above. For detailed questions, responses and general comments see Supplement S5. Source Data files are available in the article repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726 Discussion Importantly, the origins of the GPOC concept partly stems from the idea that it is the patient’s natural right to co-own information about their own health status. This aligns with the evolving concept of human rights and the emerging notion of freedom of self-information as a fundamental global human right, as discussed earlier. Moreover, clinicians and caregivers also have the right to co-own and access documentation produced by themselves. For example, if a patient claims they have been wrongly treated, the clinician or caregiver must be able to access the PHR. Thus, it is one of the reasons why a patient cannot fully own the records. Furthermore, the clinic or hospital must also co-own and have access to the PHR, since they have a legally regulated role as a healthcare provider. The latter may be subject to fitness to practise proceedings by a regulatory body. In this scenario, the state-operated regulatory body would have the right to access data indirectly, via the clinic. This is the case in most legislatures globally. As was clearly seen in the WHO Third Global Survey on eHealth, large swathes of the world do not have any electronic PHRs whatsoever. 17 But the spread of smartphones since then has meant an unprecedented increase in individual access to digital healthcare, which could soon translate into AI-empowered PHRs. Here, the additional GPOC review and interviews with country representatives and organisations reveal an articulated will among regulators around the world to give patients’ co-ownership, access, and the right to share their PHRs. 1,2 The advantages are several, e.g., evidently for a travelling workforce or refugees managing chronic diseases whilst fleeing a conflict (S2). 4 The present legal latticework needs both more universal and granular legislation. Thus, giving a globally valid co-ownership regulation for patients, clinicians and clinics. Co-ownership may be regarded as a constituent of the universal human rights, along with the rights to good health, to be informed about one’s health, the right physical and psychological integrity, freedom from harm and the right to own property. Hence, everyone is ‘entitled to participate in, contribute to, and enjoy economic, social, cultural, and political development, in which all human rights and fundamental freedoms can be fully realised,’ as stipulated in the pioneering UN Declaration on the Right to Development, 1986. The geographic variations on the rulings of custodianship for data, ownership, sharing and security, have been bridged in the international banking sector and in many corporate examples. For instance, Spotify with its global reimbursement and revenue model for copyrighted material. 49 Perhaps, it may be inspiring to future self-sufficient GPOC models. There is a long list of international organisations and companies, with headquarters in one place, but with activities reaching far over the globe, with standard legal adaptation to local regulations. A GPOC would of course need terms of use, but such a global PHR platform would need to adapt to local regulations as well. The legislation would in other words need two layers, with caveats when indicated. Future GPOC terms of use may be inspired by the framework used today by open-source platforms. 50 In a world of free markets, a GPOC may also appear unexpectedly, or as a consequence of technical and economic evolutions. Then regulation would come hastily and ad hoc. This has been highlighted in many interviews, i.e., that market “macro trends” may be stronger than political initiatives. (S2) It should also be discussed at international fora, whether a GPOC should ideally be initiated, sponsored and regulated through international organisations, such as the UN and the WHO. These have some influential members with authoritarian rule though. Perhaps it should have the form of an international foundation. Its nature would likely be decentralised with a consensus from blockchain. It needs further debate on how decisions would be made for GPOC in the future. For instance, which quorum would be needed. More specifically: how can the need for future consensus algorithms be met? On what mathematical frameworks would those algorithms be based? The advancements of AI, cloud computing and blockchain technology have been rapid. These technical land winnings now enable the realisation of a GPOC concept. A globalised economy further sparks this development. A recent UN declaration attempts to charter universal health guarantees. As a result of human rights’ evolution, a new entity may entail the right to health information co-ownership. In medical ethics new terms appear, such as sharing and global movability of PHRs. Co-ownership may have pivotal importance for patient control of privacy. The patient may become an access gatekeeper. There is a global latticework of regulations of PHRs, with two thirds of countries having data protection and privacy laws in place. The global PHR producers are dominated by the US, but there are several other nationwide initiatives. The COVID-19 pandemic made the advantages of global PHR collaboration clearer. Several countries and organisations have launched initiatives for PHR regulation, digitalisation, cross-border integration and medical research. This may emanate in a consensus pointing towards benefits with GPOC for global health. CONCLUSIONS In conclusion, co-ownership must be trisected between patients, clinicians and clinics. The timing for relevant policy guidelines is now ripe. Novel technical solutions, such as fully homomorphic encryption, enable secure sharing and research on PHRs. Importantly, an AI-empowered GPOC of PHRs would bestow the world with an unprecedented substrate for medical science. It would provide a giant source for AI development, and dissemination. It would mean democratisation of healthcare and release the awesome power of deep medicine. Therefore, GPOC may have positive effects on global health. Declarations Ethics Approval and Consent to Participate Ethical approval for the GPOC Series was obtained from the Imperial College London University research ethics committee, IRAS Project ID 310441 . Prior to distribution, all participants provided informed consent in accordance with the guidelines outlined in the Nature Portfolio participant release form. Written ethics and consent declaration found in S3. Consent for Publication The GPOC featured image was purchased by the first author from Shutterstock under a license that includes a consent for publication from the individuals, whose faces are visible in the image. GPOC Featured Image License Information found in supplement S4. Availability of Data and Materials The data generated in this study are provided in the Supplementary Information . Source data are provided with this paper. Source data and raw data generated in this study, have been deposited in the article repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726. All data are available on the repository without restrictions. All data are free to use. Competing Interests All authors declare that they have no conflicts of interest. Funding This GPOC study series were supported by grants to Eric Herlenius (EH) from the Swedish Research Council (2019-01157 and 2023-02613), the Stockholm County Council (FoUI-966 449), the Swedish National Heart and Lung Foundation (2018-0505 and 2021-0579) and Freemasons Children's House foundations and Karolinska Institutet. Dr Niklas Lidströmer (NL) was partly supported by the Freemasons Children’s House Foundation Scholarship. The funders did not participate in the design or conduct of the study. Author Contributions Niklas Lidströmer (NL) conceived the background research, idea and concept. NL conducted the literature review. NL made the interviews. NL created the networks for invitations.NL performed data collection. NL performed data analysis. NL assembled and structured the source data. All authors (NL, Joe Davids (JD), Mohamed ElSharkawy (ME), Hutan Ashrafian (HA) and Eric Herlenius (EH) contributed to the data interpretation. EH provided critical intellectual input throughout the study. NL conducted statistical analyses. NL and EH contributed to the interpretation of results. NL wrote the manuscript with input from all co-authors. NL made all revisions of the manuscript with critical reviews from EH. All authors critically reviewed and approved the final version of the manuscript. NL created all tables, figures and assembled all source data into a repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726. Acknowledgements We acknowledge the Swedish Foreign Ministry, the Permanent Mission of Sweden to the United Nations in New York, the health ministries of all 193 member states of the United Nations, the two UN observer states (Palestine and the Holy See), the de facto independent non-UN member state (Taiwan), and 18 international organisations - the United Nations (UN), United Nations specialised agency World Health Organisation (WHO), United Nations High Commissioner for Refugees (UNHCR), United Nations Children's Fund (UNICEF), United Nations Educational, Scientific and Cultural Organization (UNESCO), and United Nations Programme on HIV/AIDS (UNAIDS), the international financial institution World Bank (WB) and the international non-governmental organisations International Committee of the Red Cross (ICRC), the World Economic Forum (WEF), Africa Health Organisation (AHO), Amnesty International, Center for Security and Emerging Technology (CSET), Freedom House, Centers for Disease Control and Prevention (CDC), Doctors Without Borders (Médecins Sans Frontières, MSF), Global Organisation Against Female Genital Mutilation, IPAS - Partners for Reproductive Justice, and Population Services International (PSI). References Lidströmer N et al, Systematic Review and Meta-Analysis for a Global Patient co- Owned Cloud (GPOC), Nature Communications, (2024) 15:2186, DOI: 10.1038/s41467-024-46503-5. Lidströmer N et al, Necessity of a Global Patient co-Owned Cloud (GPOC), BMC Digital Health, DOI: 10.21203/rs.3.rs-3004727/v1 (Latest version: https://figshare.com/s/c0e7e94418ec7fbdcb00) Davids J et al Technical Sandbox for a Global Patient co-Owned Cloud (GPOC), BMC Digital Health, DOI: 10.21203/rs.3.rs-3004979/v2 (Latest version: https://figshare.com/s/f6f935bfd440258b50ce) Lidströmer N et al, A Summit on a Global Patient co-Owned Cloud (GPOC), BMC Digital Health, (Latest version: https://figshare.com/s/489c908e2f7e097fcf92) United Nations. Universal declaration of human rights (UDHR); 1948 Kandasamy V. and Papitha E., "Flexible access control for outsourcing personal health services in cloud computing using hierarchical attribute set based encryption," International Conference on Information Communication and Embedded Systems (ICICES), 2013, pp. 569-571, DOI: 10.1109/ICICES.2013.6508268. Zhu H, Huang R, Liu X, Li H, editors. SPEMR: A new secure personal electronic medical record scheme with privilege separation; 2014, DOI: 10.1109/ICCW.2014.6881281. UN General Assembly. Right to development, 4 December; 1986. United Nations Political Declaration on universal health coverage (UHC), 2019. Lehmann, L.S. (2022). Ethical Challenges of Integrating AI into Healthcare. In: Lidströmer, N., Ashrafian, H. (eds) Artificial Intelligence in Medicine. Springer, Cham, DOI: 10.1007/978-3-030-64573-1_337 Kant I. Grundlegung zur Metaphysik der Sitten (English: Groundwork of the Metaphysics of Morals); 1785. Mathioudakis A, Rousalova I, Gagnat AA, Saad N, Hardavella G. How to keep good clinical records. Breathe (Sheff). 2016 Dec;12(4):369-373, DOI: 10.1183/20734735.018016. Essén A. Patient access to electronic health records: Differences across ten countries. Health Policy and Technology. 2018; Volume 7, Issue 1, March 2018, Pages 44-56, DOI: 10.1183/20734735.018016. CRICO Strategies. National Comparative Benchmarking System (CBS) Report: Medication-related Malpractice Risks. 2016, Available at https://psnet.ahrq.gov/issue/medication-related-malpractice-risks-2016-crico-strategies-national-cbs-report on 30 th March 2024. Steven H Miles, The art of medicine Hippocrates and informed consent, The Lancet, Vol 374 October 17, 2009, DOI: 10.1016/s0140-6736(09)61812-2. Topol E. The Patient Will See You Now: The Future of Medicine Is in Your Hands. First edition. ed. 2016: Basic Books: New York, NY; 2016, ISBN: 978046505474 Ammar N, Bailey JE, Davis RL, Shaban-Nejad A. Implementation of a Personal Health Library (PHL) to Support Chronic Disease Self-Management. 2021. p. 221-6, DOI: 10.1007/978-3-030-53352-6_20. Kocabas O, Soyata T. Towards privacy-preserving medical cloud computing using homomorphic encryption. 2015. p. 213-46, DOI: 10.4018/978-1-4666-8662-5.ch007 European Commission, Cloud, Data and Artificial Intelligence (DIGITAL-2023-CLOUD-AI-04), Digital Europe Programme (DIGITAL), opened 11 May 2023, ending 22 November 2023. Khansa L, Forcade J, Nambari G, Parasuraman S, Cox P. Proposing an intelligent cloud-based electronic health record system. International Journal of Business Data Communications and Networking. 2012;8(3):57-71, DOI: 10.4018/jbdcn.2012070104. Au MH, Yuen TH, Liu JK, Susilo W, Huang XY, Xiang Y, et al. A general framework for secure sharing of personal health records in cloud system. Journal of Computer and System Sciences.90:46-62, DOI: 10.1016/j.jcss.2017.03.002. Shynu PG, Singh KJ. An enhanced ABE based secure access control scheme for E-health clouds. International Journal of Intelligent Engineering and Systems. 2017;10(5):29-37, DOI: 10.22266/ijies2017.1031.04. Anand A, Singh A K, SDH: Secure Data Hiding in Fused Medical Image for Smart Healthcare, in IEEE Transactions on Computational Social Systems, 2022, August, vol. 9, no. 4, pp. 1265-1273, DOI: 10.1109/TCSS.2021.3125025. Awad M, Kerschberg L, editors. Patient-centric secure-and-privacy-preserving Service-Oriented Architecture for health information integration and exchange, CEUR Workshop Proceedings, vol. 713, 5th International Conference on Semantic Technologies for Intelligence, Defense, and Security, STIDS 2010; Fairfax, VA; United States; 27 - 28 October; 2010. Ploner N, Neurath MF, Schoenthaler M, Zielke A, Prokosch H-U. Concept to gain trust for a German personal health record system using public cloud and FHIR. Journal of biomedical informatics. 2019;95:103212, DOI: 10.1016/j.jbi.2019.103212. Cao S, Wang J, Du X, Zhang X, Qin X, editors, CEPS: A Cross-Blockchain based Electronic Health Records Privacy-Preserving Scheme, ICC 2020 - 2020 IEEE International Conference on Communications (ICC), 2020, pp. 1-6, DOI: 10.1109/ICC40277.2020.9149326. George M, Chacko AM, A Patient-Centric Interoperable, Quorum-based Healthcare System for Sharing Clinical Data, 2022 International Conference for Advancement in Technology (ICONAT), 2022, pp. 1-6, DOI: 10.1109/ICONAT53423.2022.9725924. (FDA) Federal Drug Agency. Real-World Data: Assessing Electronic Health Records and Medical Claims Data To Support Regulatory Decision-Making for Drug and Biological Products - Draft Guidance for Industry. September 2021; Docket Number: FDA-2020-D-2307. Medicines and Healthcare products Regulatory Agency (MHRA) Inspectorate, Jennifer Martin, Electronic health records, 23 July 2019, MHRA Inspectorate; 2019, accessed on 10 th February 2024 on (https://mhrainspectorate.blog.gov.uk/2019/07/23/electronic-health-records/) (WHO) World Health Organisation.Third Global Survey on eHealth in 2015; 2015. (WHO) World Health Organisation. Electronic Health Records: Manual for Developing Countries. Pacific WROftW; 2006 HITECH Act Enforcement Interim Final Rule; 2009. (ICRC) International Committee of the Red Cross. R. RedSafe App, ICRC; 2022. Available at https://www.icrc.org/en/redsafe Accessed on 30 th March 2024. European Union. Overview of the national laws on electronic health records in the EU Member States and their interaction with the provision of cross border services; 2016, accessed on 10 th February 2024 on (https://health.ec.europa.eu/other-pages/basic-page/overview-national-laws-electronic-health-records-eu-member-states-2016_en) Programme EU-EH. Overview of the national laws on electronic health records in the EU Member States and their interaction with the provision of cross-border eHealth services - Final report and recommendations. Consumers, Health and Food Executive Agency (Chafea), 2014. Hecht J. The future of electronic health records. Nature. 2019;573, S114-S116, DOI: 10.1038/d41586-019-02876-y. Rudd, J., Igbrude, C. A global perspective on data powering responsible AI solutions in health applications. AI Ethics (2023) , DOI: 10.1007/s43681-023-00302-8. (EU) European Union. Overview of the national laws on electronic health records in the EU Member States; 2016. HospitalView annual report from DefinitiveHealthcare (definitivehc.com). Updated in June 2022. Globe Newswire’s report ‘Electronic Medical Records Global Market Report 2022’ (published on Reportlinker.com 23 rd September 2022). Raghavan, A.; Demircioglu, M.A.; Taeihagh, A. Public Health Innovation through Cloud Adoption: A Comparative Analysis of Drivers and Barriers in Japan, South Korea, and Singapore. Int. J. Environ. Res. Public Health 2021, 18, 334, DOI: 10.3390/ijerph18010334. Grand View Research. Electronic Health Records Market Size, Share & Trends Analysis Report By Product (Client-server-based, Web-based), By Type (Acute, Ambulatory, Post-acute), By End-use, By Business Models, By Region, And Segment Forecasts, 2022 - 2030); 2022, Report ID: 978-1-68038-394-2. Kumar S, Wajeed MA, Kunabeva R, Dwivedi N, Singhal P, Jamal SS, et al. Novel Method for Safeguarding Personal Health Record in Cloud Connection Using Deep Learning Models. Computational intelligence and neuroscience. 2022. 2022:3564436, DOI: 10.1155/2022/3564436. Khansa L, Forcade J, Nambari G, Parasuraman S, Cox P. Proposing an intelligent cloud-based electronic health record system. International Journal of Business Data Communications and Networking. 2012;8(3):57-71, DOI: 10.4018/jbdcn.2012070104. Kluetz PG, O'Connor DJ, Soltys K. Incorporating the patient experience into regulatory decision making in the USA, Europe, and Canada. The Lancet Oncology. 2018;19(5):e267-e74, DOI: 10.1016/S1470-2045(18)30097-4. Mxoli NA, Mostert N, Gerber M, Guidelines for secure cloud-based personal health records; IEEE; 2019. http://hdl.handle.net/10204/10967, DOI: 10.1109/ICTAS.2019.8703524. Sulaiman H, Magaireh A, Ramli R. Adoption of cloud-based E-health record through the technology, organization and environment perspective. International Journal of Engineering and Technology(UAE). 2018;7(4):609-16, DOI: 10.14419/ijet.v7i4.35.22923. Sounderajah, V., Ashrafian, H., Rose, S. et al. A quality assessment tool for artificial intelligence-centered diagnostic test accuracy studies: QUADAS-AI. Nat Med 27, 1663–1665 (2021), DOI: 10.1038/s41591-021-01517-0. Spotify. Spotify End-User Agreement, https://www.spotify.com/us/legal/end-user-agreement/; 2022. Open-Source. Open-Source Legal Guide, Available at https://opensource.guide/legal/ on 30 th March 2024. Tables Table 1: Global Regulations Governing Data Privacy: A Comprehensive Overview Countries Applicable Legal Framework Remarks Australia Two legal systems - Federal Law and State or Territorial Laws Australia has several laws on both territorial and state/federal levels regarding protection of privacy and personal data. On the highest levels there are also general guidelines. Information Privacy Acts, Information Acts, Privacy, Data Protection Acts, Personal Information Acts, etc. (several similar wordings for each state). Only relevant to the respective states and territories, but two laws are federal: the APPs (Australian Privacy Principles) and the FPA (Federal Privacy Act). Both were introduced in 1988. Brazil Brazilian General Data Protection Law (LGPD) The Brazilian equivalence to the European Union’s GDPR. Both laws have an extraterritorial scope. Canada Personal Information Protection, Identity Theft Prevention Act, Personal Information Protection Act, the Privacy Act, etc. (several similar wordings for each state). As with Australia, Canada has state level laws for privacy and data protection. Personal Information Protection & Electronic Documents Act This law applies to organisations operating inter-provincially or globally. China China lacks a state law regulating data privacy. The below laws cover most cases. Recently China introduced several major data protection laws, especially from September 2021. People’s Republic of China Cybersecurity Law These laws demand both the local storage of any data harvested about people residing in China by both domestic and foreign enterprises and forbids any foreign export of data technology. Personal Information Protection Law & Data Security Law, and a plethora of guidelines on the protection of personal identity New Chinese framework, legislated in 2021/2022. Several guidelines or directives, both local and national have recently been published. Draft for: ‘National Standard of Information Security Technology’ Law in draft: to secure, among other, Chinese national security. EU General Data Protection Regulation (GDPR) – its ‘primary goals’ Stipulating the privacy of “personal data as a fundamental human right .” Legislating on the basic credentials of personal privacy. Standardising the privacy rule application for the EU. General Data Protection Regulation (GDPR) – ‘Protections included’ Includes the regulation of Personally identifiable information (PII),which encompasses personal names, identity, and facts connected with it such as street address, various numbers, etc. It also covers web related facts, such as email, cookies, ID addresses, and finally also biological or biometric facts relevant to PHRs such as genetics, DNA, fingerprints, and medical record contents. Singapore Personal Data Protection Act (PDPA) All of Singapore’s applicable laws; here relevant laws are collected in one single act. South Africa Protection of Personal Information Act (POPIA) The POPIA is one of the latest data protection laws, the intention of which is to strengthen the privacy rights of individuals in a data-dominated society. USA Federal Trade Commission Act A federal regulation on privacy protection and prohibits, e.g., fake advertising. Children’s Online Privacy Protection Act Stipulates how data about children can be collected. Health Insurance Portability and Accounting Act (HIPAA) This is the most relevant law about PHRs in the USA, and covers, e.g., storing and usage of health data. Gramm Leach Bliley Act Covers personal data used by, e.g., banks. Fair Credit Reporting Act Covers the usage of information related to credits. Data Privacy Laws on US state levels There are several federal guidelines, but 25 US states also have local rules on data and privacy. California Consumer Privacy Act (CCPA) CCPA applies to personal data: provided directly by users in online forms or collected by tracking tools and related technologies Table 2: Top Global Producers and Vendors of Personal Health Records (PHRs): A Comparative Analysis # PHR Producer Ranking 1 39 Origin Legislation Installations Global % PHR Producer Ranking 2 40 1st Epic Systems Corporation WI, USA US or local Ca. 2,400 Ca. 37% Epic Systems Corporation 2nd Oracle Cerner Corporation TX, USA US or local Ca. 1,500 Ca. 23% Oracle Cerner Corporation 3rd MediTech MA, USA US or local Ca. 900 Ca. 14% AdvancedMD Inc. & CureMD Healthcare 4th Evident, a CPSI Company GA & AL (CPSI), USA US or local Ca. 500 Ca. 8% EClinicalWorks & GE Healthcare 5th MedHost TN, USA US or local Ca. 250 Ca. 4% Greenway Health 6th Altera Digital Health (Harris) BC, CA & FA, USA (Harris) US or local Ca. 200 Ca. 3.5% McKesson Corporation & NextGen Healthcare Inc. 7th Netsmart Technology KS, USA US or local Ca. 150 Ca. 2% GoodWill & Modernising Medicine Inc. 8th Proprietary software Many different countries Local Ca. 100 Ca. 1.8% Neusoft & PCCW Solution 9th AthenaHealth MA, USA US or local Ca. 80 Ca. 1.2% AthenaHealth 10th Allscripts Healthcare IL, USA US or local Ca. 40 Ca. 0.6% Allscripts Healthcare Additional Declarations No competing interests reported. Supplementary Files S1AdditionalEthicsPolicyRegReviewDocumentation.pdf S2EthicsPolicyRegGPOCInterviewsandSupplementaryWrittenCorrespondence2.pdf S5GPOCInterviewSeriesSourceDataEthicsReview.xlsx FeaturedImageGPOC.jpeg Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-4198485","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Systematic Review","associatedPublications":[],"authors":[{"id":286165915,"identity":"9bd5b3ff-7a16-4fee-8ef5-c932fc87b96e","order_by":0,"name":"Niklas Lidströmer","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA+klEQVRIie3QPWrDMBiA4U8EpEXprNI0uUJNhlAIPYtMwF56AG+RKahTd+cinb9gcBdDD6ClIZAuGdKtg6CRjckQsLx20LsICT3oByAU+o+NKEE3TCjIboVpwAHSbuCOENWu8GqAQEfgQkTiBwtGJf5a4Dcs/d5n2ft0sTnECHbZSx5fKG7ftLsYP0Z5XZv5xCSIRPcf9VAyhWPliHgmea5NXNylCokqvWRrbUPSXUPWxe2Hchf78xCKpfsuR2TUECkERQSKPiLLey3at2xUbaKCJxJjveonn1W0O9rldPaafv2ozMwEq+ank33qJV3iai6HQCgUCoW8nQH+s1ekEuJ2SAAAAABJRU5ErkJggg==","orcid":"","institution":"Karolinska Institutet, CMM","correspondingAuthor":true,"prefix":"","firstName":"Niklas","middleName":"","lastName":"Lidströmer","suffix":""},{"id":286165919,"identity":"3e561a51-b1a0-4e50-99f6-660e7b5966f0","order_by":1,"name":"Joe Davids","email":"","orcid":"","institution":"Imperial College London","correspondingAuthor":false,"prefix":"","firstName":"Joe","middleName":"","lastName":"Davids","suffix":""},{"id":286165921,"identity":"bf59de06-9919-4c33-833c-40b5f170bc60","order_by":2,"name":"Mohamed ElSharkawy","email":"","orcid":"","institution":"Imperial College London","correspondingAuthor":false,"prefix":"","firstName":"Mohamed","middleName":"","lastName":"ElSharkawy","suffix":""},{"id":286165923,"identity":"d81ce9c5-557c-41a4-b318-60087fb36add","order_by":3,"name":"Hutan Ashrafian","email":"","orcid":"","institution":"Imperial College London","correspondingAuthor":false,"prefix":"","firstName":"Hutan","middleName":"","lastName":"Ashrafian","suffix":""},{"id":286165924,"identity":"27dc5961-5486-44fd-93b3-f990047f926b","order_by":4,"name":"Eric Herlenius","email":"","orcid":"","institution":"Karolinska Institutet, CMM","correspondingAuthor":false,"prefix":"","firstName":"Eric","middleName":"","lastName":"Herlenius","suffix":""}],"badges":[],"createdAt":"2024-04-01 06:12:34","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-4198485/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-4198485/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":54164150,"identity":"9f3efce0-5bfb-497c-b552-29b1a2292769","added_by":"auto","created_at":"2024-04-05 13:17:10","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":220715,"visible":true,"origin":"","legend":"\u003cp\u003eResponses to the Twelve Key Questions in the Interview Series\u003c/p\u003e\n\u003cp\u003eThe interview series contained \u0026gt;100 interviews resulting in 50 fused annotations (#1-50) for 42 states and 8 international organisations. Twelve questions were asked, corresponding to the review’s twelve subheadings 1-12 above. Percentages are based on one unified answer per entity (1/50=2%). Countries were weighted so that number of interviews was balanced. Each result has been quoted under the respective paragraphs above. For detailed questions, responses and general comments see Supplement S5.\u003c/p\u003e","description":"","filename":"Figure1.png","url":"https://assets-eu.researchsquare.com/files/rs-4198485/v1/f8a73e362fd6723eb4ff0c7b.png"},{"id":54162288,"identity":"49102f47-000f-4f20-9b81-c208f01d9e12","added_by":"auto","created_at":"2024-04-05 13:09:10","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":381980,"visible":true,"origin":"","legend":"\u003cp\u003eThe 54 Nations and International Organisations Inquired about GPOC Aspects\u003c/p\u003e\n\u003cp\u003eThe interview series’ participating states (n=42) in dark blue and international organisations (n=8) with logotypes. Note Luxemburg and Maldives not clearly visible in the map. In light blue four states (Belize, Brazil, Honduras and Tanzania), which only participated in the GPOC Summit, but not in the structured interview series. They were inquired in depth about aspects relevant for GPOC, and contributed to Table 1, but were not included in the percentages under the respective paragraphs above.\u003csup\u003e4\u003c/sup\u003e For details see supplement S2.\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e","description":"","filename":"2.png","url":"https://assets-eu.researchsquare.com/files/rs-4198485/v1/a67c9d2c587cac4dec537960.png"},{"id":54164153,"identity":"c386cda2-2fd9-4fff-aebc-3b779b3c4daf","added_by":"auto","created_at":"2024-04-05 13:17:16","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":878237,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-4198485/v1/973e82f8-9c31-453c-8d4a-dfbea92b9826.pdf"},{"id":54162284,"identity":"bf1d6738-ec0c-4c59-8d73-d7fd75633c97","added_by":"auto","created_at":"2024-04-05 13:09:08","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"supplement","size":182504,"visible":true,"origin":"","legend":"","description":"","filename":"S1AdditionalEthicsPolicyRegReviewDocumentation.pdf","url":"https://assets-eu.researchsquare.com/files/rs-4198485/v1/ab3634e6e72c2189996e0e50.pdf"},{"id":54162347,"identity":"dacc468c-ba5d-4192-be0a-d75c448f2e26","added_by":"auto","created_at":"2024-04-05 13:09:13","extension":"pdf","order_by":2,"title":"","display":"","copyAsset":false,"role":"supplement","size":283131,"visible":true,"origin":"","legend":"","description":"","filename":"S2EthicsPolicyRegGPOCInterviewsandSupplementaryWrittenCorrespondence2.pdf","url":"https://assets-eu.researchsquare.com/files/rs-4198485/v1/fe2b892162f354cf6ea5c6e3.pdf"},{"id":54162286,"identity":"aee9f738-a9e0-44f1-aeee-8a604e0998cd","added_by":"auto","created_at":"2024-04-05 13:09:09","extension":"xlsx","order_by":3,"title":"","display":"","copyAsset":false,"role":"supplement","size":17590,"visible":true,"origin":"","legend":"","description":"","filename":"S5GPOCInterviewSeriesSourceDataEthicsReview.xlsx","url":"https://assets-eu.researchsquare.com/files/rs-4198485/v1/5c0a0628817ea9b762f2d258.xlsx"},{"id":54162285,"identity":"7912d674-c3bf-49d2-970a-8593839bef8c","added_by":"auto","created_at":"2024-04-05 13:09:08","extension":"jpeg","order_by":4,"title":"","display":"","copyAsset":false,"role":"supplement","size":953705,"visible":true,"origin":"","legend":"","description":"","filename":"FeaturedImageGPOC.jpeg","url":"https://assets-eu.researchsquare.com/files/rs-4198485/v1/dcc894668ce4cb4f781e4217.jpeg"}],"financialInterests":"No competing interests reported.","formattedTitle":"Review and Inquiries on Ethics, Policies and Regulations of a Global Patient co-Owned Cloud (GPOC)","fulltext":[{"header":"BACKGROUND","content":"\u003cp\u003eThe idea of a global, cloud-based, trustless, decentralised, multi-stakeholder, co-owned and secure cloud for healthcare was almost unimaginable a few decades ago.\u003c/p\u003e\n\n\u003cp\u003eThis idea embodies a global and securely blockchain protected, worldwide distributed and patient co-owned platform of personal health records (PHR, ISO/TR 14292:2012). This embodies our concept of a Global Patient co-Owned Cloud (GPOC)\u003csup\u003e1\u003c/sup\u003e. Prior to our recent systematic review and meta-analysis, no publications have delved into this topic, nor presented co-ownership models on a global scale.\u003csup\u003e1\u003c/sup\u003e\u003c/p\u003e\n\n\u003cp\u003eThe GPOC publication series commenced with a systematic review and meta-analysis of a dozen pivotal facets of a GPOC.\u003csup\u003e1\u003c/sup\u003e Hereafter, the concept\u0026rsquo;s necessity was explored in the GPOC Survey, revealing a global consensus\u003csup\u003e2\u003c/sup\u003e.\u003csup\u003e \u003c/sup\u003eThis received answers from all key opinion leaders of 193+3 United Nations\u0026rsquo; member states and the 18 largest international health care organisations.\u003csup\u003e2\u003c/sup\u003e Thus, the technical and mathematical foundations were shaped, resulting in a GPOC sandbox environment.\u003csup\u003e3\u003c/sup\u003e Subsequently, a GPOC Summit, conducted in a Delphi style, supplemented the survey findings, contributing to the ethical discourse on the GPOC concept.\u003csup\u003e4\u003c/sup\u003e At last, the series here contains an additional literature review of and interviews regarding the ethics and policies relevant for a GPOC.\u003c/p\u003e\n\n\u003cp\u003eCore problems with personal health records are: 1) No or limited patient access, 2) No patient ownership, 3) No explicit right to share, 4) No integration or interaction across platforms, 5) Ineffective user interfaces, 6) Expensive, too expensive for many health economies. This is valid both locally and globally, but in some countries the patients have access. Moreover, there are security issues with current cloud-based PHR platforms.\u003csup\u003e1\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eOur hypothesis is that a Global Patient co-Owned Cloud (GPOC) of PHRs would solve the above conundrums. Moreover, a GPOC would be a large substrate for artificial intelligence development and dissemination, potentially democratising medicine across the globe. Though, carefully not to let any central power control the contents. The siloed use of AI on health data would be replaced by a global cloud resource.\u003c/p\u003e\n\n\u003cp\u003eToday the UN Declaration on Human Rights forms the basis of humanitarian law as an integral component of global jurisprudence.\u003csup\u003e5\u003c/sup\u003e It consists of basic freedoms such as the right to liberty, security, one\u0026apos;s own health and property. The modern human right concept and co-ownership of PHRs, may intertwine in our era of information dominance. However, owning one\u0026rsquo;s PHR is not stipulated as a human right. With GPOC a new human rights\u0026rsquo; entity may come into fruition.\u003c/p\u003e\n\n\u003cp\u003eHere, we extracted solely the co-ownership and security aspects from the GPOC systematic review.\u003csup\u003e1\u003c/sup\u003e Furthermore, we performed an additional literature overview of ethics with focus on human rights development, regulations, AI integration and the worldwide PHR market. See supplement S1.\u003c/p\u003e\n\n\u003cp\u003eWe supported his narrative review with a series of 100 interviews with regulators, relevant health organisations and government sources were conducted. Results have contributed to Table 2 that contains an overview of the global regulatory latticework. The interviews sought to answer the search questions, but also encompassed a wider and informative scope. See supplement S2 for the series\u0026rsquo; structure and the state and organisation \u003cs\u003ein \u003c/s\u003einterview participance.\u003c/p\u003e\n\n\u003cp\u003eHence, this is an overview of the ethical and juridical aspects of a GPOC. This to enable and facilitate its possible implementation in the near future.\u003c/p\u003e"},{"header":"MAIN TEXT","content":"\u003cp\u003e\u003cstrong\u003eThe GPOC Systematic Review and the Additional Review\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe GPOC systematic review of 9,362 articles retrieved 226 articles. It covered twelve facets relevant to the realisation of a GPOC. One-fifth dealt with ownership and data owners.\u003csup\u003e1\u003c/sup\u003e However, only two mentioned multi-ownership, but mentioned in a different context.\u003csup\u003e6,7\u003c/sup\u003e To our knowledge the exact term co-ownership does not appear in any published articles. In the GPOC Survey and GPOC Summit we introduced the concept. In both over 90% of respondents deemed it a human right to co-own PHRs.\u003csup\u003e2,4\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eWe here present an overview of initiatives of regulatory bodies, ethical considerations and clinical limitations. The global latticework of regulations is found in Table 1, and global producers of PHRs in Table 2. Below, the results follow in twelve subentries (#1-12). Given the nature of the subjects, parts of the discussion will occur within these. Hence, the discussion entry ensuite summarises the overarching tendencies.\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e1: Relevant Human Rights Declarations\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eActive participation in personal development is a human right in the United Nations\u0026rsquo; Sustainable Development Goals (SDG) of 1986.\u003csup\u003e8\u003c/sup\u003e There are no UN declarations on PHRs. But in 2019 came the Declaration on Universal Health Coverage (UHC). Hitherto, it is the most wide-ranging attempt for universal health guarantees.\u003csup\u003e9\u003c/sup\u003e Here, the gender representation is pivotal. The GPOC interview series has an exact 50% gender balance. Likewise, the GPOC Summit, that mirrored the GPOC Survey\u003csup\u003e2\u003c/sup\u003e had an equal gender representation (Table 2 and S2). In the GPOC interview series a dominant opinion is that patient co-ownership, access, sharing rights and global PHR interaction with patient control is on the level of a new human right. 92% of interviewees deemed it a human right to co-own one\u0026rsquo;s medical data. For all responses see Figure 1.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e2: Ethical Principles\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eFive ethical principles that are universal for healthcare are: autonomy, justice, nonmaleficence, beneficence and fidelity. These are constantly elaborated in ethical discussions to explore dilemmas and better understand conflicting issues.\u003csup\u003e10\u003c/sup\u003e Nearly all, 98% of interviewees, agreed on the core of the medical ethics principles relevant for this area.\u003c/p\u003e\n\u003cp\u003eA patient co-owned PHR means shared information and increased autonomy. The medical facts in the PHR are based on both the medical history provided by the patient and on physical examinations and investigations. Both are patient centric. Hence, it is a question of justice with patient access and co-ownership. Co-ownership could then lead to a revenue stream to the patient from anonymized research on PHR contents. Healthcare providers informing the patient and being transparent in the PHR towards the patient are parts of both beneficence and fidelity. With GPOC healthcare should be more effective and not harmful, i.e., nonmaleficence.\u003csup\u003e4,10\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eA basic Kantian enlightenment concept is the categorical imperative \u0026ndash; \u0026lsquo;act so that your actions can be translated into universal law.\u0026rsquo;\u003csup\u003e11\u003c/sup\u003e Following this, then evidently patients should be informed about their health and co-own their PHRs.\u003csup\u003e4\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eHowever, in clinical care all information cannot be inserted into the PHR. For instance, if it causes risks to a third person. In studies of PHRs with patient access, it has been noted that this type of information may be kept in other parallel notes or verbally, which is not recommended.\u003csup\u003e12\u003c/sup\u003e Moreover, a co-owned PHR may strengthen access rights. Hence, it may lead to a more granular regulation. Currently, patients\u0026rsquo; PHR access varies a lot geographically.\u003csup\u003e13\u0026nbsp;\u003c/sup\u003eA global overview of regulations are outlined in table 1.\u003csup\u003e\u0026nbsp;\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e3: Co-Ownership\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eCo-ownership may encourage patients to actively contribute to the PHR. Some patients may have an interest in monitoring or \u0026lsquo;gatekeeping\u0026rsquo; the access log of the PHR. Co-owning parties would be able to correct misunderstandings in the medical history or faulty contents.\u003csup\u003e4\u003c/sup\u003e Communication deficit is the commonest cause of legal conflicts in healthcare\u003csup\u003e14\u003c/sup\u003e. Co-ownership would improve communication and overall connectivity. It may decrease mistakes based on inaccurate PHR information. 90% of interviewees deemed co-ownership to be positive for healthcare.\u003c/p\u003e\n\u003cp\u003eThe patient\u0026rsquo;s freedom of expression in healthcare is essential. Hitherto, the direct voice of the patient has been silent in the PHR. Co-ownership could emphasise the right to PHR contribution. Also, the rights to PHR migration and sharing with anyone deemed relevant. Hence, there are advantages in emergencies, travel and refugee situations. The GPOC concept embodies these as human rights principles. The ownership question is also highlighted with the outsourcing to cloud service providers and producers of PHR software, for an overview of the market see table 2.\u003c/p\u003e\n\u003cp\u003eCo-ownership may be a step in the evolution of medical ethics. There is an increase in the informing of the patient about their health status. Until the 1950s the Hippocratic concept of not informing was dominant. There has been a global decrease of paternalism since then.\u003csup\u003e15\u003c/sup\u003e The last thirty years of information revolution, widespread smartphone uses and patient PHR access has meant a democratisation of medicine.\u003csup\u003e16\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eThere are concerns over data ownership for cloud service providers and manufacturers of PHRs, see table 2. Individuals and healthcare providers could lose control of highly sensitive data.\u003csup\u003e6\u003c/sup\u003e To address this issue, robust encryption protocols and secure data access mechanisms can be implemented. Additionally, strict regulatory frameworks and transparent data governance policies are essential to safeguard patient privacy and data security. There are methods to fully decentralising and linking open data platform specifications. These grant patients\u0026rsquo; real ownership of their data and give them a fine-grained access control to share their PHRs.\u003csup\u003e17\u003c/sup\u003e. Here, it\u0026apos;s crucial to not only consider but also actively address the potential risks posed by authoritarian regimes, which may seek to exploit personal health data for surveillance and control purposes.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e4: Privacy Aspects\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe sources of big data, privacy concerns, trust issues in organisations and complex regulations may all hinder the progress of AI in healthcare.\u003csup\u003e34\u003c/sup\u003e Cloud computing may have the strength of revolutionising healthcare, but the progress is slow. Strict regulations on patient information are hindrances. However, there are new cloud models with revised privacy issues generally associated with cloud service providers. These use Fully Homomorphic Encryption (FHE), enabling computations on PHRs without seeing the underlying data.\u003csup\u003e18\u003c/sup\u003e Recently a relevant European Commission call for Cloud, Data and Artificial Intelligence in the Digital Europe Programme (DIGITAL) was announced.\u003csup\u003e19\u003c/sup\u003e 80% of the interview participants deemed that privacy protection can be feasible with new technical solutions for cloud based PHRs. The rest either agreed with reservations or were neutral. See Figure 2 and supplement S5 for details.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5: Policy Aspects\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eTimely international policy guidelines could facilitate the GPOC concept. Almost 90% in the interview series thought it possible to agree on international regulations. These should cover end-user policies and regulations to identities and accesses.\u003csup\u003e1,2,4\u003c/sup\u003e (S2). But also, network resilience, agreements, computational power, \u0026lsquo;big data\u0026rsquo; mining capacities, privacy and security.\u003csup\u003e3\u003c/sup\u003e There is such guidance for an \u0026lsquo;intelligent cloud-based electronic health record\u0026rsquo; (ICEHR) in line with healthcare regulations.\u003csup\u003e1,20\u003c/sup\u003e For overview see Table 2.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e6: Security Aspects\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThere are PHRs allowing patients to store and share contents securely in the cloud. These few platforms allow doctoral referrals and also sharing with a medical research intent.\u003csup\u003e21\u003c/sup\u003e Though, patients\u0026rsquo; information remains private. Such platforms facilitate sharing across borders. Notably, with different regulations in various countries.\u003csup\u003e21\u003c/sup\u003e For overview see table 1. To our knowledge none of the large system mentioned in Table 2 allow fully encrypted sharing with research intent. Over 90% of interviewees expressed awareness of relevant security issues for a GPOC, but also expressed that a technical solution must be possible. (S2)\u003c/p\u003e\n\u003cp\u003eLarge amounts of data are generated by PHR clouds. However, the most common drawback with these techniques may be the combination of their patient-centric nature and the lack of sufficient security with fine-grained access control. This is crucial to comply with regulatory requirements.\u003csup\u003e22\u003c/sup\u003e Notably, 92% of responders in the interviews believed PHR security ought to be improved in their states or organisations.\u003c/p\u003e\n\u003cp\u003eIn the construction of PHR infrastructures, cloud-based ecosystems are used ubiquitously. And a GPOC must have an impenetrably safe cloud using a distributed blockchain. Therefore, engagement between regulators and stakeholders at international fora likely may provide insights into shaping the most applicable technologies.\u003csup\u003e1,4,22\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e7: New Technical Solutions and Ethics\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eTechnical solutions exist to achieve the GPOC concept. For example, the co-ownership issue with abundant medical images. To increase clinical practicalities, single modality images can be fused to clear multimodality images. The spread of these fused medical images rises new matters of authentication and ownership.\u003csup\u003e23\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eThe privacy-preserving and secure Service Oriented Architecture (SOA) can integrate PHRs. Herein, patients could be \u0026ldquo;partly owners\u0026rdquo; and share or edit their PHRs. SOA enables full ownership of integrated PHRs. Owners may decide to share with healthcare providers or even insurance companies.\u003csup\u003e24,25\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eCo-owners of the PHR would be the patient, together with its managers, which are the doctors and nurses and their respective hospitals and clinics. These three owners are likely the only relevant ones. There are concerns that a broader division of the ownership of PHRs could potentially lead to sensitive data leaks, if stored in a cloud environment.\u003csup\u003e26\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eCurrently the healthcare organisations are the sole PHR owners. Of the interviewees 80% found it logical to have a trisected ownership and another 20% agreed with reservations to discuss. Now though, patients have only limited information about the contents and then only upon receiving discharge summaries or specific report letters etc. This was an evident problem during the COVID-19 pandemic. The need for patients\u0026rsquo; control became more accentuated.\u003csup\u003e27\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e8: Initiatives by Regulatory Bodies and Organisations\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe 2021 Federal Drug Agency (FDA) industry guidance aims at speeding up medical product development and creating innovations quicker, so that patients will benefit earlier. It focuses on electronic PHRs for clinical trials that may impact regulatory decision making.\u003csup\u003e28\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e78% of the series participants pointed out that in their state or organisations there were ongoing or planned initiatives that strived to improve PHR integration.\u003c/p\u003e\n\u003cp\u003eHowever, not all PHRs are electronic yet. For instance, in the UK the Medicines and Healthcare Products Regulatory Agency (MHRA) leads the nationwide NHS initiative to replace all paper records with electronic PHRs. At the centre are ethical and practical considerations for research, clinical trials, and best clinical practice. MHRA, the Health Research Authority (HRA) and the Information Commissioner\u0026apos;s Office (ICO), have presented guidance for medical research processed on PHRs. It is recommended to be read alongside the Data Protection Impact Assessments (DPIAs).\u003csup\u003e29\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eThe World Health Organisation (WHO) carried out the Third Global Survey on eHealth in 2015 (GOE_Q144) to investigate PHRs globally. It collected data from 125 countries, with the then largest ever survey.\u003csup\u003e30\u003c/sup\u003e The WHO has produced a manual for developing countries on the implementation of PHRs. Here the requirements for the introduction, maintenance, content, staffing, ethics, and other regulatory considerations are presented, aiming at, e.g., staff of health ministries.\u003csup\u003e31\u003c/sup\u003e WHO has no global PHR project in under way, and GPOC entails a larger and wider concept.\u003csup\u003e1,2,3,4\u003c/sup\u003e (S2).\u003c/p\u003e\n\u003cp\u003eIn the USA the Office of the National Coordinator for Health Information Technology (ONC) works under the authority of the Health Information Technology for Economic and Clinical Health (HITECH) Act. The Department of Health has established improvement programs for healthcare quality, safety, including health IT and PHRs.\u003csup\u003e32\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eThe Red Cross (ICRC) uses the Red Cross Health Information System (RCHIS) as the platform for emergency response, tailored for humanitarian situations. Here, medical personnel can manage patient information in the field. ICRC has also developed several apps for first aid and emergencies etc. Its main app RedSafe is a digital humanitarian platform that provides safe and secure services for people affected by conflict, migration and other crises. RedSafe also helps the ICRC to reach out to more people, in compliance with their own ICRC data protection standards.\u003csup\u003e33\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eThe European Union (EU) published a synopsis of the members\u0026rsquo; PHR laws and their compatibility with open internal border policies.\u003csup\u003e34\u003c/sup\u003e Under EU Law \u0026lsquo;Article 14 of Directive 2011/24/EU on the application of patients\u0026rsquo; rights in cross-border healthcare,\u0026rsquo; the eHealth Network aims at facilitating the interactivity between European PHRs. It aims to present pan-European guidelines for future cross-border transferability of PHRs. These need to conform with the existing EU data protection rules, including the General Data Protection Regulation (GDPR). A European Commission action plan aims to remove obstacles for integration and \u0026lsquo;a fully mature and interoperable eHealth system in Europe\u0026rsquo;. Although 24 of 30 surveyed states were not equipped for the EU vision of continental PHR interaction.\u003csup\u003e1,2,4,35\u003c/sup\u003e If realised, then a data substrate of such size may spark the development of AI integrated into PHRs.\u003csup\u003e1,4\u003c/sup\u003e Natural language processing and decision support systems woven in.\u003csup\u003e36\u003c/sup\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e9: An Overview of Global Regulations\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe legislative, clinical and practical ramifications of co-ownership between the three involved parties (patients, clinicians and clinics), involves the resolution of some legal entanglements in the patient-doctor-clinic relationship across the world.\u003c/p\u003e\n\u003cp\u003eFor an overview of the global latticework of regulations see Table 1. The mentioned Global Data GDPR covers all 27 EU member states. Several other countries have been inspired. For instance, Nigeria with the Nigerian Data Protection Regulation (NDPR), which narrowly mirrors the GDPR. Across the world 66% of countries have data protection and privacy laws. Another 10% are drafting new legislation, 19% have no legislation, and for 5% of countries there is no data.\u003csup\u003e37\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e90% of interviewees deemed their state or organisation could integrate with international regulations and reach a global consensus.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTable 1:\u003c/strong\u003e Global Regulations Governing Data Privacy: A Comprehensive Overview\u003c/p\u003e\n\u003cp\u003eAn overview of the global latticework of regulations governing data privacy. Information collected from governmental sources in each country, and from a European Union overview of national member states\u0026rsquo; legislation on PHRs.\u003csup\u003e38\u003c/sup\u003e (S1, S2) Source Data files are available in the article repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTable 2:\u0026nbsp;\u003c/strong\u003eTop Global Producers and Vendors of Personal Health Records (PHRs): A Comparative Analysis\u003c/p\u003e\n\u003cp\u003eGlobal producers and vendors of PHRs. There are only four overlapping companies of the two top ten lists. Figures relate to the 1\u003csup\u003est\u003c/sup\u003e ranking. The 2\u003csup\u003end\u003c/sup\u003e ranking is less exact. The USA dominance is equal in both lists.\u003csup\u003e39,40\u003c/sup\u003e (S1, S2) Source Data files are available in the article repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e10: The Global PHR Market\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eIt is partly less clear which companies dominate this market. Table 2 attempts to overview the largest global PHR producers. Note the pronounced US dominance. Though, the regulation of PHRs is almost always coming from the country of implementation. An exception is when the PHR is part of a foreign aid program. Then the donor nation may influence the regulation. This can lead to legal imbalance or further dependency. There are also open-source solutions such as openEHR and Fast Healthcare Interoperability Resources (FHIR), which provide open standard specifications in health informatics. Notably, 64% of interviewees deemed the PHR market to be an oligopoly, another 12% agreed with some reservations and 20% were neutral.\u003c/p\u003e\n\u003cp\u003eThe producer overview is not complete though. There are also initiatives for nationwide platforms. For example, with the NHS in the UK, in the Nordics and in technically progressive Asian states, e.g., Japan, Singapore, and South Korea. These have demonstrated how clouds can be used to serve nationwide databases of PHRs, to backup both medical research and telemedicine. There are several such national cloud solutions for public health innovations relevant to a GPOC.\u003csup\u003e37\u0026nbsp;\u003c/sup\u003eThese existing national cloud-based solutions and data bases might provide a feasible foundation for a GPOC.\u003csup\u003e4\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eGlobe Newswire estimates in their 2022 report that the total world PHR market will expand from the 2021 value of $32 billion to $34 billion in one year. The growth rate is then anticipated to be 8% per annum. It is further projected the global market will reach $44 billion in 2026 with an average annual growth rate (AAGR) of 7%. In contrast, a Grand View Research report, the total market size is estimated to $27 billion in 2021 and it anticipates a lower AAGR of 4% between 2022 and 2030.\u003csup\u003e42\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e11: Artificial Intelligence (AI) Integration\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e90% of interviewees regarded GPOC as a potentially positive force for health AI development and dissemination. Though, how AI can be optimally implemented into a GPOC is today a key policy conundrum. One component of this is how AI shall be able use data and interact with GPOC and generate results. Another is how GPOC and its anonymised PHR data becomes a substrate for global machine learning development. A third is under what conditions, for data protection, platform security management and product development. This will most likely depend on the users\u0026rsquo; sharing and permissions.\u003csup\u003e1,2\u003c/sup\u003e Here we are faced with a novel online service paradigm that permits its users to share their health data.\u003csup\u003e43\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eModern PHR software allow patients or caregivers to exchange or share contents. PHRs can now be fortified with AI to forecast patients\u0026apos; critical development enabling earlier therapeutic interventions. Moreover, electronic PHR are starting to be designed so they may interact with other healthcare platforms. However, currently a lot of them do not (Table 2). With older populations and increasing health budgets for the rest of the century this is needed. A GPOC, i.e., an AI empowered cloud-based PHR, designed to minimise medical mistakes may decrease costs by making healthcare more streamlined and qualitative.\u003csup\u003e44\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eSome of the aspects of a GPOC already exist in rare disease or oncological management. The creation of new oncological therapies is a global enterprise. The inclusion of patient experiences into clinical decision-making processes is focused thanks to the international regulatory and health policy communities. Symptoms of both diseases and therapies, and effects on functioning and life quality are essential. International regulatory scientists have identified topics to integrate Patient-reported outcome (PRO) measures into the regulatory and legislative processes. For instance, a GPOC would allow adverse effects reporting on a global scale.\u003csup\u003e45\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eThe risks with cloud computing for PHRs may decrease if cloud providers complied with audits. Thus, regulation obedience for securing cloud data would lead to backups to protect against data loss. This is crucial as healthcare becomes dependent on AI integrated PHRs.\u003csup\u003e46\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e12: Future Challenges\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eChallenging key factors affecting the adaptation to cloud PHR technologies in a Technology-organisation-Environment (TOE) are reliability, security, privacy, management support, hospital readiness, competitive situation, and the regulatory environment.\u003csup\u003e47\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003e94% of interviewees deemed GPOC could play a pivotal role in future global TOE. Challenges include effective global regulatory engagement and development of policies relevant to a GPOC. Though, this may follow as a consequence of market evolution. This may be affected by a GPOC providing a large and anonymised source for global AI development. Hence, a GPOC could be self-sufficient and with co-owning patients receive revenue streams. Possibly a new microeconomy could arise. This may ignite the AI algorithm evolution and the global need for responsible AI health applications.\u003csup\u003e48\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003ePotential risk of adverse implementations might be insurance companies demanding access to personalised information. Authoritarian leadership making decisions based on individual data.\u003c/p\u003e\n\u003cp\u003eIn theory a future market for patient PHR revenue reimbursements could emerge in a microflow of passive income to the co-owners. One part could be reimbursed to the patient and the other corporate component of co-ownership revenue could divert back to the maintenance of GPOC.\u003c/p\u003e\n\u003cp\u003eThe interview series contained \u0026gt;100 interviews resulting in 50 fused annotations (#1-50) for 42 states and 8 international organisations. Twelve questions were asked, corresponding to the review\u0026rsquo;s twelve subheadings 1-12 above. Percentages are based on one unified answer per entity (1/50=2%). Countries were weighted so that number of interviews was balanced. Each result has been quoted under the respective paragraphs above. For detailed questions, responses and general comments see Supplement S5. Source Data files are available in the article repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726\u003c/p\u003e"},{"header":"Discussion","content":"\u003cp\u003eImportantly, the origins of the GPOC concept partly stems from the idea that it is the patient\u0026rsquo;s natural right to co-own information about their own health status. This aligns with the evolving concept of human rights and the emerging notion of freedom of self-information as a fundamental global human right, as discussed earlier.\u003c/p\u003e\n\n\u003cp\u003eMoreover, clinicians and caregivers also have the right to co-own and access documentation produced by themselves. For example, if a patient claims they have been wrongly treated, the clinician or caregiver must be able to access the PHR. Thus, it is one of the reasons why a patient cannot fully own the records.\u003c/p\u003e\n\n\u003cp\u003eFurthermore, the clinic or hospital must also co-own and have access to the PHR, since they have a legally regulated role as a healthcare provider. The latter may be subject to fitness to practise proceedings by a regulatory body. In this scenario, the state-operated regulatory body would have the right to access data indirectly, via the clinic. This is the case in most legislatures globally. \u003c/p\u003e\n\n\u003cp\u003eAs was clearly seen in the WHO Third Global Survey on eHealth, large swathes of the world do not have any electronic PHRs whatsoever.\u003csup\u003e17\u003c/sup\u003e But the spread of smartphones since then has meant an unprecedented increase in individual access to digital healthcare, which could soon translate into AI-empowered PHRs. \u003c/p\u003e\n\n\u003cp\u003eHere, the additional GPOC review and interviews with country representatives and organisations reveal an articulated will among regulators around the world to give patients\u0026rsquo; co-ownership, access, and the right to share their PHRs.\u003csup\u003e1,2\u003c/sup\u003e The advantages are several, e.g., evidently for a travelling workforce or refugees managing chronic diseases whilst fleeing a conflict (S2).\u003csup\u003e4\u003c/sup\u003e\u003c/p\u003e\n\n\u003cp\u003eThe present legal latticework needs both more universal and granular legislation. Thus, giving a globally valid co-ownership regulation for patients, clinicians and clinics.\u003c/p\u003e\n\n\u003cp\u003eCo-ownership may be regarded as a constituent of the universal human rights, along with the rights to good health, to be informed about one\u0026rsquo;s health, the right physical and psychological integrity, freedom from harm and the right to own property. Hence, everyone is \u0026lsquo;entitled to participate in, contribute to, and enjoy economic, social, cultural, and political development, in which all human rights and fundamental freedoms can be fully realised,\u0026rsquo; as stipulated in the pioneering UN Declaration on the Right to Development, 1986. \u003c/p\u003e\n\n\u003cp\u003eThe geographic variations on the rulings of custodianship for data, ownership, sharing and security, have been bridged in the international banking sector and in many corporate examples. For instance, Spotify with its global reimbursement and revenue model for copyrighted material.\u003csup\u003e49\u003c/sup\u003e Perhaps, it may be inspiring to future self-sufficient GPOC models.\u003c/p\u003e\n\n\u003cp\u003eThere is a long list of international organisations and companies, with headquarters in one place, but with activities reaching far over the globe, with standard legal adaptation to local regulations. A GPOC would of course need terms of use, but such a global PHR platform would need to adapt to local regulations as well. The legislation would in other words need two layers, with caveats when indicated. Future GPOC terms of use may be inspired by the framework used today by open-source platforms.\u003csup\u003e50\u003c/sup\u003e\u003c/p\u003e\n\u003cp\u003eIn a world of free markets, a GPOC may also appear unexpectedly, or as a consequence of technical and economic evolutions. Then regulation would come hastily and ad hoc. This has been highlighted in many interviews, i.e., that market \u0026ldquo;macro trends\u0026rdquo; may be stronger than political initiatives. (S2)\u003c/p\u003e\n\u003cp\u003eIt should also be discussed at international fora, whether a GPOC should ideally be initiated, sponsored and regulated through international organisations, such as the UN and the WHO. These have some influential members with authoritarian rule though. Perhaps it should have the form of an international foundation. Its nature would likely be decentralised with a consensus from blockchain. It needs further debate on how decisions would be made for GPOC in the future. For instance, which quorum would be needed. More specifically: how can the need for future consensus algorithms be met? On what mathematical frameworks would those algorithms be based?\u003c/p\u003e\n\u003cp\u003eThe advancements of AI, cloud computing and blockchain technology have been rapid. These technical land winnings now enable the realisation of a GPOC concept. A globalised economy further sparks this development. A recent UN declaration attempts to charter universal health guarantees. As a result of human rights\u0026rsquo; evolution, a new entity may entail the right to health information co-ownership. In medical ethics new terms appear, such as sharing and global movability of PHRs. Co-ownership may have pivotal importance for patient control of privacy. The patient may become an access gatekeeper. \u003c/p\u003e\n\u003cp\u003eThere is a global latticework of regulations of PHRs, with two thirds of countries having data protection and privacy laws in place. The global PHR producers are dominated by the US, but there are several other nationwide initiatives. The COVID-19 pandemic made the advantages of global PHR collaboration clearer. Several countries and organisations have launched initiatives for PHR regulation, digitalisation, cross-border integration and medical research. This may emanate in a consensus pointing towards benefits with GPOC for global health.\u003c/p\u003e"},{"header":"CONCLUSIONS","content":"\u003cp\u003eIn conclusion, co-ownership must be trisected between patients, clinicians and clinics. The timing for relevant policy guidelines is now ripe. Novel technical solutions, such as fully homomorphic encryption, enable secure sharing and research on PHRs. Importantly, an AI-empowered GPOC of PHRs would bestow the world with an unprecedented substrate for medical science. It would provide a giant source for AI development, and dissemination. It would mean democratisation of healthcare and release the awesome power of deep medicine. Therefore, GPOC may have positive effects on global health.\u003c/p\u003e"},{"header":"Declarations","content":"\u003cp\u003e\u003cstrong\u003e\u003cem\u003eEthics Approval and Consent to Participate\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eEthical approval for the GPOC Series was obtained from the Imperial College London University research ethics committee, IRAS Project ID 310441\u003cem\u003e.\u003c/em\u003e Prior to distribution, all participants provided informed consent in accordance with the guidelines outlined in the Nature Portfolio participant release form. Written ethics and consent declaration found in S3.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eConsent for Publication\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe GPOC featured image was purchased by the first author from Shutterstock under a license that includes a consent for publication from the individuals, whose faces are visible in the image. GPOC Featured Image License Information found in supplement S4.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eAvailability of Data and Materials\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe data generated in this study are provided in the Supplementary Information\u003cstrong\u003e\u003cem\u003e. \u003c/em\u003e\u003c/strong\u003eSource data are provided with this paper. Source data and raw data generated in this study, have been deposited in the article repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726. All data are available on the repository without restrictions. All data are free to use.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003e \u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eCompeting Interests\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAll authors declare that they have no conflicts of interest.\u003c/p\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eFunding\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThis GPOC study series were supported by grants to Eric Herlenius (EH) from the Swedish Research Council (2019-01157 and 2023-02613), the Stockholm County Council (FoUI-966 449), the Swedish National Heart and Lung Foundation (2018-0505 and 2021-0579) and Freemasons Children\u0026apos;s House foundations and Karolinska Institutet. Dr Niklas Lidstr\u0026ouml;mer (NL) was partly supported by the Freemasons Children\u0026rsquo;s House Foundation Scholarship. The funders did not participate in the design or conduct of the study.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003e \u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eAuthor Contributions\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eNiklas Lidstr\u0026ouml;mer (NL) conceived the background research, idea and concept. NL conducted the literature review. NL made the interviews. NL created the networks for invitations.NL performed data collection. NL performed data analysis. NL assembled and structured the source data. All authors (NL, Joe Davids (JD), Mohamed ElSharkawy (ME), Hutan Ashrafian (HA) and Eric Herlenius (EH) contributed to the data interpretation. EH provided critical intellectual input throughout the study. NL conducted statistical analyses. NL and EH contributed to the interpretation of results. NL wrote the manuscript with input from all co-authors. NL made all revisions of the manuscript with critical reviews from EH. All authors critically reviewed and approved the final version of the manuscript. NL created all tables, figures and assembled all source data into a repository on Figshare, DOI: 10.6084/m9.figshare.c.7067726.\u003c/p\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eAcknowledgements\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eWe acknowledge the Swedish Foreign Ministry, the Permanent Mission of Sweden to the United Nations in New York, the health ministries of all 193 member states of the United Nations, the two UN observer states (Palestine and the Holy See), the de facto independent non-UN member state (Taiwan), and 18 international organisations - the United Nations (UN), United Nations specialised agency World Health Organisation (WHO), United Nations High Commissioner for Refugees (UNHCR), United Nations Children\u0026apos;s Fund (UNICEF), United Nations Educational, Scientific and Cultural Organization (UNESCO), and United Nations Programme on HIV/AIDS (UNAIDS), the international financial institution World Bank (WB) and the international non-governmental organisations International Committee of the Red Cross (ICRC), the World Economic Forum (WEF), Africa Health Organisation (AHO), Amnesty International, Center for Security and Emerging Technology (CSET), Freedom House, Centers for Disease Control and Prevention (CDC), Doctors Without Borders (M\u0026eacute;decins Sans Fronti\u0026egrave;res, MSF), Global Organisation Against Female Genital Mutilation, IPAS - Partners for Reproductive Justice, and Population Services International (PSI).\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\n\u003cli\u003eLidstr\u0026ouml;mer N et al, Systematic Review and Meta-Analysis for a Global Patient co- Owned Cloud (GPOC), Nature Communications, (2024) 15:2186, DOI: 10.1038/s41467-024-46503-5.\u003c/li\u003e\n\u003cli\u003eLidstr\u0026ouml;mer N et al, Necessity of a Global Patient co-Owned Cloud (GPOC), BMC Digital Health, DOI: 10.21203/rs.3.rs-3004727/v1 (Latest version: https://figshare.com/s/c0e7e94418ec7fbdcb00)\u003c/li\u003e\n\u003cli\u003eDavids J et al Technical Sandbox for a Global Patient co-Owned Cloud (GPOC), BMC Digital Health, DOI: 10.21203/rs.3.rs-3004979/v2 (Latest version: https://figshare.com/s/f6f935bfd440258b50ce)\u003c/li\u003e\n\u003cli\u003eLidstr\u0026ouml;mer N et al, A Summit on a Global Patient co-Owned Cloud (GPOC), BMC Digital Health, (Latest version: https://figshare.com/s/489c908e2f7e097fcf92)\u003c/li\u003e\n\u003cli\u003eUnited Nations. Universal declaration of human rights (UDHR); 1948\u003c/li\u003e\n\u003cli\u003eKandasamy V. and Papitha E., \u0026quot;Flexible access control for outsourcing personal health services in cloud computing using hierarchical attribute set based encryption,\u0026quot; International Conference on Information Communication and Embedded Systems (ICICES), 2013, pp. 569-571, DOI: 10.1109/ICICES.2013.6508268.\u003c/li\u003e\n\u003cli\u003eZhu H, Huang R, Liu X, Li H, editors. SPEMR: A new secure personal electronic medical record scheme with privilege separation; 2014, DOI: 10.1109/ICCW.2014.6881281.\u003c/li\u003e\n\u003cli\u003eUN General Assembly. Right to development, 4 December; 1986.\u003c/li\u003e\n\u003cli\u003eUnited Nations Political Declaration on universal health coverage (UHC), 2019.\u003c/li\u003e\n\u003cli\u003eLehmann, L.S. (2022). Ethical Challenges of Integrating AI into Healthcare. In: Lidstr\u0026ouml;mer, N., Ashrafian, H. (eds) Artificial Intelligence in Medicine. Springer, Cham, DOI: 10.1007/978-3-030-64573-1_337\u003c/li\u003e\n\u003cli\u003eKant I. Grundlegung zur Metaphysik der Sitten (English: Groundwork of the Metaphysics of Morals); 1785.\u003c/li\u003e\n\u003cli\u003eMathioudakis A, Rousalova I, Gagnat AA, Saad N, Hardavella G. How to keep good clinical records. Breathe (Sheff). 2016 Dec;12(4):369-373, DOI: 10.1183/20734735.018016.\u003c/li\u003e\n\u003cli\u003eEss\u0026eacute;n A. Patient access to electronic health records: Differences across ten countries. Health Policy and Technology. 2018; Volume 7, Issue 1, March 2018, Pages 44-56, DOI: 10.1183/20734735.018016.\u003c/li\u003e\n\u003cli\u003eCRICO Strategies. National Comparative Benchmarking System (CBS) Report: Medication-related Malpractice Risks. 2016, Available at https://psnet.ahrq.gov/issue/medication-related-malpractice-risks-2016-crico-strategies-national-cbs-report on 30\u003csup\u003eth\u003c/sup\u003e March 2024.\u003c/li\u003e\n\u003cli\u003eSteven H Miles, The art of medicine Hippocrates and informed consent, The Lancet, Vol 374 October 17, 2009, DOI: 10.1016/s0140-6736(09)61812-2.\u003c/li\u003e\n\u003cli\u003eTopol E. The Patient Will See You Now: The Future of Medicine Is in Your Hands. First edition. ed. 2016: Basic Books: New York, NY; 2016, ISBN: 978046505474\u003c/li\u003e\n\u003cli\u003eAmmar N, Bailey JE, Davis RL, Shaban-Nejad A. Implementation of a Personal Health Library (PHL) to Support Chronic Disease Self-Management. 2021. p. 221-6, DOI: 10.1007/978-3-030-53352-6_20.\u003c/li\u003e\n\u003cli\u003eKocabas O, Soyata T. Towards privacy-preserving medical cloud computing using homomorphic encryption. 2015. p. 213-46, DOI: 10.4018/978-1-4666-8662-5.ch007\u003c/li\u003e\n\u003cli\u003eEuropean Commission, Cloud, Data and Artificial Intelligence (DIGITAL-2023-CLOUD-AI-04), Digital Europe Programme (DIGITAL), opened 11 May 2023, ending 22 November 2023.\u003c/li\u003e\n\u003cli\u003eKhansa L, Forcade J, Nambari G, Parasuraman S, Cox P. Proposing an intelligent cloud-based electronic health record system. International Journal of Business Data Communications and Networking. 2012;8(3):57-71, DOI: 10.4018/jbdcn.2012070104.\u003c/li\u003e\n\u003cli\u003eAu MH, Yuen TH, Liu JK, Susilo W, Huang XY, Xiang Y, et al. A general framework for secure sharing of personal health records in cloud system. Journal of Computer and System Sciences.90:46-62, DOI: 10.1016/j.jcss.2017.03.002.\u003c/li\u003e\n\u003cli\u003eShynu PG, Singh KJ. An enhanced ABE based secure access control scheme for E-health clouds. International Journal of Intelligent Engineering and Systems. 2017;10(5):29-37, DOI: 10.22266/ijies2017.1031.04.\u003c/li\u003e\n\u003cli\u003eAnand A, Singh A K, SDH: Secure Data Hiding in Fused Medical Image for Smart Healthcare, in IEEE Transactions on Computational Social Systems, 2022, August, vol. 9, no. 4, pp. 1265-1273, DOI: 10.1109/TCSS.2021.3125025.\u003c/li\u003e\n\u003cli\u003eAwad M, Kerschberg L, editors. Patient-centric secure-and-privacy-preserving Service-Oriented Architecture for health information integration and exchange, CEUR Workshop Proceedings, vol. 713, 5th International Conference on Semantic Technologies for Intelligence, Defense, and Security, STIDS 2010; Fairfax, VA; United States; 27 - 28 October; 2010.\u003c/li\u003e\n\u003cli\u003ePloner N, Neurath MF, Schoenthaler M, Zielke A, Prokosch H-U. Concept to gain trust for a German personal health record system using public cloud and FHIR. Journal of biomedical informatics. 2019;95:103212, DOI: 10.1016/j.jbi.2019.103212.\u003c/li\u003e\n\u003cli\u003eCao S, Wang J, Du X, Zhang X, Qin X, editors, CEPS: A Cross-Blockchain based Electronic Health Records Privacy-Preserving Scheme, ICC 2020 - 2020 IEEE International Conference on Communications (ICC), 2020, pp. 1-6, DOI: 10.1109/ICC40277.2020.9149326.\u003c/li\u003e\n\u003cli\u003eGeorge M, Chacko AM, A Patient-Centric Interoperable, Quorum-based Healthcare System for Sharing Clinical Data, 2022 International Conference for Advancement in Technology (ICONAT), 2022, pp. 1-6, DOI: 10.1109/ICONAT53423.2022.9725924.\u003c/li\u003e\n\u003cli\u003e(FDA) Federal Drug Agency. Real-World Data: Assessing Electronic Health Records and Medical Claims Data To Support Regulatory Decision-Making for Drug and Biological Products - Draft Guidance for Industry. September 2021; Docket Number: FDA-2020-D-2307.\u003c/li\u003e\n\u003cli\u003eMedicines and Healthcare products Regulatory Agency (MHRA) Inspectorate, Jennifer Martin, Electronic health records, 23 July 2019, MHRA Inspectorate; 2019, accessed on 10\u003csup\u003eth\u003c/sup\u003e February 2024 on (https://mhrainspectorate.blog.gov.uk/2019/07/23/electronic-health-records/)\u003c/li\u003e\n\u003cli\u003e(WHO) World Health Organisation.Third Global Survey on eHealth in 2015; 2015.\u003c/li\u003e\n\u003cli\u003e(WHO) World Health Organisation. Electronic Health Records: Manual for Developing Countries. Pacific WROftW; 2006\u003c/li\u003e\n\u003cli\u003eHITECH Act Enforcement Interim Final Rule; 2009.\u003c/li\u003e\n\u003cli\u003e(ICRC) International Committee of the Red Cross. R. RedSafe App, ICRC; 2022. Available at \u003cu\u003ehttps://www.icrc.org/en/redsafe\u003c/u\u003e\u003cu\u003e Accessed on 30\u003csup\u003eth\u003c/sup\u003e March 2024.\u003c/u\u003e\u003c/li\u003e\n\u003cli\u003eEuropean Union. Overview of the national laws on electronic health records in the EU Member States and their interaction with the provision of cross border services; 2016, accessed on 10\u003csup\u003eth\u003c/sup\u003e February 2024 on (https://health.ec.europa.eu/other-pages/basic-page/overview-national-laws-electronic-health-records-eu-member-states-2016_en)\u003c/li\u003e\n\u003cli\u003eProgramme EU-EH. Overview of the national laws on electronic health records in the EU Member States and their interaction with the provision of cross-border eHealth services - Final report and recommendations. Consumers, Health and Food Executive Agency (Chafea), 2014.\u003c/li\u003e\n\u003cli\u003eHecht J. The future of electronic health records. Nature. 2019;573, S114-S116, DOI: 10.1038/d41586-019-02876-y.\u003c/li\u003e\n\u003cli\u003eRudd, J., Igbrude, C. A global perspective on data powering responsible AI solutions in health applications. AI Ethics (2023) , DOI: 10.1007/s43681-023-00302-8.\u003c/li\u003e\n\u003cli\u003e(EU) European Union. Overview of the national laws on electronic health records in the EU Member States; 2016.\u003c/li\u003e\n\u003cli\u003eHospitalView annual report from DefinitiveHealthcare (definitivehc.com). Updated in June 2022.\u003c/li\u003e\n\u003cli\u003eGlobe Newswire\u0026rsquo;s report \u0026lsquo;Electronic Medical Records Global Market Report 2022\u0026rsquo; (published on Reportlinker.com 23\u003csup\u003erd\u003c/sup\u003e September 2022).\u003c/li\u003e\n\u003cli\u003eRaghavan, A.; Demircioglu, M.A.; Taeihagh, A. Public Health Innovation through Cloud Adoption: A Comparative Analysis of Drivers and Barriers in Japan, South Korea, and Singapore. Int. J. Environ. Res. Public Health 2021, 18, 334, DOI: 10.3390/ijerph18010334.\u003c/li\u003e\n\u003cli\u003eGrand View Research. Electronic Health Records Market Size, Share \u0026amp; Trends Analysis Report By Product (Client-server-based, Web-based), By Type (Acute, Ambulatory, Post-acute), By End-use, By Business Models, By Region, And Segment Forecasts, 2022 - 2030); 2022, Report ID: 978-1-68038-394-2.\u003c/li\u003e\n\u003cli\u003eKumar S, Wajeed MA, Kunabeva R, Dwivedi N, Singhal P, Jamal SS, et al. Novel Method for Safeguarding Personal Health Record in Cloud Connection Using Deep Learning Models. Computational intelligence and neuroscience. 2022. 2022:3564436, DOI: 10.1155/2022/3564436.\u003c/li\u003e\n\u003cli\u003eKhansa L, Forcade J, Nambari G, Parasuraman S, Cox P. Proposing an intelligent cloud-based electronic health record system. International Journal of Business Data Communications and Networking. 2012;8(3):57-71, DOI: 10.4018/jbdcn.2012070104.\u003c/li\u003e\n\u003cli\u003eKluetz PG, O\u0026apos;Connor DJ, Soltys K. Incorporating the patient experience into regulatory decision making in the USA, Europe, and Canada. The Lancet Oncology. 2018;19(5):e267-e74, DOI: 10.1016/S1470-2045(18)30097-4.\u003c/li\u003e\n\u003cli\u003eMxoli NA, Mostert N, Gerber M, Guidelines for secure cloud-based personal health records; IEEE; 2019. http://hdl.handle.net/10204/10967, DOI: 10.1109/ICTAS.2019.8703524.\u003c/li\u003e\n\u003cli\u003eSulaiman H, Magaireh A, Ramli R. Adoption of cloud-based E-health record through the technology, organization and environment perspective. International Journal of Engineering and Technology(UAE). 2018;7(4):609-16, DOI: 10.14419/ijet.v7i4.35.22923.\u003c/li\u003e\n\u003cli\u003eSounderajah, V., Ashrafian, H., Rose, S. et al. A quality assessment tool for artificial intelligence-centered diagnostic test accuracy studies: QUADAS-AI. Nat Med 27, 1663\u0026ndash;1665 (2021), DOI: 10.1038/s41591-021-01517-0.\u003c/li\u003e\n\u003cli\u003eSpotify. Spotify End-User Agreement, https://www.spotify.com/us/legal/end-user-agreement/; 2022.\u003c/li\u003e\n\u003cli\u003eOpen-Source. Open-Source Legal Guide, Available at https://opensource.guide/legal/ on 30\u003csup\u003eth\u003c/sup\u003e March 2024.\u003c/li\u003e\n\u003c/ol\u003e"},{"header":"Tables","content":"\u003cp\u003e\u003cstrong\u003eTable 1:\u003c/strong\u003e \u003cem\u003eGlobal Regulations Governing Data Privacy: A Comprehensive Overview\u003c/em\u003e\u003c/p\u003e\n\u003ctable border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"602\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003eCountries\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003eApplicable Legal Framework\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003eRemarks\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eAustralia\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eTwo legal systems - Federal Law and State or Territorial Laws\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eAustralia has several laws on both territorial and state/federal levels regarding protection of privacy and personal data. On the highest levels there are also general guidelines.\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eInformation Privacy Acts, \u0026nbsp;Information Acts, Privacy, Data Protection Acts, Personal Information Acts, etc. (several similar wordings for each state).\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eOnly relevant to the respective states and territories, but two laws are federal: the APPs (Australian Privacy Principles) and the FPA (Federal Privacy Act). Both were introduced in 1988.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eBrazil\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eBrazilian General Data Protection Law (LGPD)\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eThe Brazilian equivalence to the European Union\u0026rsquo;s GDPR. Both laws have an extraterritorial scope.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eCanada\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003ePersonal Information Protection, Identity Theft Prevention Act, Personal Information Protection Act, the Privacy Act, etc. (several similar wordings for each state).\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eAs with Australia, Canada has state level laws for privacy and data protection.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003ePersonal Information Protection \u0026amp; Electronic Documents Act\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eThis law applies to organisations operating inter-provincially or globally.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eChina\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eChina lacks a state law regulating data privacy. The below laws cover most cases.\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eRecently China introduced several major data protection laws, especially from September 2021.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003ePeople\u0026rsquo;s Republic of China\u003c/p\u003e\n \u003cp\u003eCybersecurity Law\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eThese laws demand both the local storage of any data harvested about people residing in China by both domestic and foreign enterprises and forbids any foreign export of data technology.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003ePersonal Information Protection Law \u0026amp; Data Security Law, and a plethora of guidelines on the protection of personal identity\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eNew Chinese framework, legislated in 2021/2022. Several guidelines or directives, both local and national have recently been published.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eDraft for: \u0026lsquo;National Standard of Information Security Technology\u0026rsquo;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eLaw in draft: to secure, among other, Chinese national security.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eEU\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eGeneral Data Protection Regulation (GDPR) \u0026ndash; its \u0026lsquo;primary goals\u0026rsquo;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eStipulating the privacy of \u0026ldquo;personal data as a fundamental human right\u003cem\u003e.\u0026rdquo;\u003c/em\u003e Legislating on the basic credentials of personal privacy. Standardising the privacy rule application for the EU.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eGeneral Data Protection Regulation (GDPR) \u0026ndash; \u0026lsquo;Protections included\u0026rsquo;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eIncludes the regulation of Personally identifiable information (PII),which encompasses personal names, identity, and facts connected with it such as street address, various numbers, etc. It also covers web related facts, such as email, \u0026nbsp; \u0026nbsp; cookies, ID addresses, and finally also biological or biometric facts relevant to PHRs such as genetics, DNA, fingerprints, and medical record contents.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eSingapore\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003ePersonal Data Protection Act (PDPA)\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eAll of Singapore\u0026rsquo;s applicable laws; here relevant laws are collected in one single act.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eSouth Africa\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eProtection of Personal Information Act (POPIA)\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eThe POPIA is one of the latest data protection laws, the intention of which is to strengthen the privacy rights of individuals in a data-dominated society.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eUSA\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eFederal Trade Commission Act\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eA federal regulation on privacy protection and prohibits, e.g., fake advertising.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eChildren\u0026rsquo;s Online Privacy Protection Act\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eStipulates how data about children can be collected.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eHealth Insurance Portability and Accounting Act (HIPAA)\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eThis is the most relevant law about PHRs in the USA, and covers, e.g., storing and usage of health data.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eGramm Leach Bliley Act\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eCovers personal data used by, e.g., banks.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eFair Credit Reporting Act\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eCovers the usage of information related to credits.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eData Privacy Laws on US state levels\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eThere are several federal guidelines, but 25 US states also have local rules on data and privacy.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"11.461794019933555%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"39.3687707641196%\" valign=\"top\"\u003e\n \u003cp\u003eCalifornia Consumer Privacy Act (CCPA)\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"49.16943521594684%\" valign=\"top\"\u003e\n \u003cp\u003eCCPA applies to personal data: provided directly by users in online forms or collected by tracking tools and related technologies\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTable 2:\u0026nbsp;\u003c/strong\u003e\u003cem\u003eTop Global Producers and Vendors of Personal Health Records (PHRs): A Comparative Analysis\u003c/em\u003e\u003c/p\u003e\n\u003ctable border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"595\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003e#\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003ePHR Producer Ranking 1\u003csup\u003e39\u003c/sup\u003e\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003eOrigin\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003eLegislation\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003eInstallations\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003eGlobal %\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u003cem\u003ePHR Producer Ranking 2\u003csup\u003e40\u003c/sup\u003e\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e1st\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eEpic Systems Corporation\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eWI, USA\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 2,400\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 37%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eEpic Systems Corporation\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e2nd\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eOracle Cerner Corporation\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eTX, USA\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 1,500\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 23%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eOracle Cerner Corporation\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e3rd\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eMediTech\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eMA, USA\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 900\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 14%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eAdvancedMD Inc. \u0026amp;\u003c/p\u003e\n \u003cp\u003eCureMD Healthcare\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e4th\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eEvident, a CPSI Company\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eGA \u0026amp; AL (CPSI), USA\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 500\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 8%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eEClinicalWorks \u0026amp;\u003c/p\u003e\n \u003cp\u003eGE Healthcare\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e5th\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eMedHost\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eTN, USA\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 250\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 4%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eGreenway Health\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e6th\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eAltera Digital Health (Harris)\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eBC, CA \u0026amp; FA, USA (Harris)\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 200\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 3.5%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eMcKesson Corporation \u0026amp;\u003c/p\u003e\n \u003cp\u003eNextGen Healthcare Inc.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e7th\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eNetsmart Technology\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eKS, USA\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 150\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 2%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eGoodWill \u0026amp;\u003c/p\u003e\n \u003cp\u003eModernising Medicine Inc.\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e8th\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eProprietary software\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eMany different countries\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eLocal\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 100\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 1.8%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eNeusoft \u0026amp;\u003c/p\u003e\n \u003cp\u003ePCCW Solution\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e9th\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eAthenaHealth\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eMA, USA\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 80\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 1.2%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eAthenaHealth\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.218487394957983%\" valign=\"top\"\u003e\n \u003cp\u003e10th\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"22.18487394957983%\" valign=\"top\"\u003e\n \u003cp\u003eAllscripts Healthcare\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"14.285714285714286%\" valign=\"top\"\u003e\n \u003cp\u003eIL, USA\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"12.77310924369748%\" valign=\"top\"\u003e\n \u003cp\u003eUS or local\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"11.092436974789916%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 40\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"9.579831932773109%\" valign=\"top\"\u003e\n \u003cp\u003eCa. 0.6%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"23.865546218487395%\" valign=\"top\"\u003e\n \u003cp\u003eAllscripts Healthcare\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"global patient co-owned cloud, GPOC, personal health records, medical ethics, health policies, medical regulation, cloud-based health, blockchains, artificial intelligence in medicine","lastPublishedDoi":"10.21203/rs.3.rs-4198485/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-4198485/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eCloud-based personal health records have increased during the last thirty years across the globe. The concept of a Global Patient co-Owned Cloud (GPOC) of personal health records is presented in the GPOC series. It encompasses a systematic review and meta-analysis, a global survey among 100% of the UN member states and a technical sandbox.\u003c/p\u003e \u003cp\u003eGPOC introduces patient co-ownership of personal health records. Here, we review the ethics, rights, privacy, co-ownership, policies, security, technique, initiatives, regulation, market, AI integration, and future challenges relevant to GPOC. We also included novel data from a series of over a hundred interviews with representatives of fifty national health ministries from all over the world and international organisations. Over 90% of the interviewees strongly endorsed the idea that co-ownership should be a human right. Similarly, consensus was attained for all the twelve reviewed aspects. Our hybrid approach, combining narrative review with interviews of senior state and organizational health experts, offers original insights and in-depth analysis of key aspects relevant to GPOC. Notably, the enthusiasm for the GPOC concept was unanimous.\u003c/p\u003e \u003cp\u003eMoreover, we provide a comprehensive global overview of aspects of relevant human rights, ethics, privacy, policy, regulations, and integration initiatives by states and organisations. We also analysed the incumbent health record market, AI integration, and future challenges for a GPOC.\u003c/p\u003e \u003cp\u003eFurthermore, we offer a holistic analysis of regulations, the global nature of AI, and its implications for healthcare. These discussions contribute to the ongoing discourse on the ethical and societal implications of emerging technologies in healthcare.\u003c/p\u003e \u003cp\u003eFinally, the present study indicates that GPOC might result in a new human right to co-own one\u0026rsquo;s personal health information. GPOC could drive development and spread of artificial intelligence for healthcare globally. It may solve the lacking personal health record integration on a global scale. Thus, a decentralised GPOC with consensus from blockchain, may benefit global health.\u003c/p\u003e","manuscriptTitle":"Review and Inquiries on Ethics, Policies and Regulations of a Global Patient co-Owned Cloud (GPOC)","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2024-04-05 13:08:55","doi":"10.21203/rs.3.rs-4198485/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"9b7cf6f9-b453-457b-ba07-7bd5ce6da038","owner":[],"postedDate":"April 5th, 2024","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2024-04-09T08:21:35+00:00","versionOfRecord":[],"versionCreatedAt":"2024-04-05 13:08:55","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-4198485","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-4198485","identity":"rs-4198485","version":["v1"]},"buildId":"qtupq5eGEP_6zYnWcrvyt","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2024) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00
unpaywall
last seen: 2026-05-26T02:00:01.498150+00:00
License: CC-BY-4.0