Healthcare
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing in healthcare and medical context
Overview
16 sources · Jul 15, 2026Legal Framework
Health data receives heightened protection under Article 9(1) GDPR, which prohibits processing of personal data concerning health unless an Article 9(2) exception applies. Recital 35 defines health data broadly: it encompasses all data revealing past, present, or future physical or mental health status, including information collected during registration for or provision of healthcare services, as well as identifiers assigned for health purposes. This sweeping definition captures everything from clinical records to medical registration numbers.
The primary legal bases for healthcare processing typically arise under Article 9(2)(a) (explicit consent), Article 9(2)(h) (medical diagnosis, treatment, or health service management), and Article 9(2)(i) (public health). A separate Article 6 basis is always required alongside the Article 9 condition. The AI Act Recital 4 further signals that AI deployment in healthcare—spanning diagnostics, resource allocation, and personalized treatment—will face additional scrutiny, particularly where health data trains or operates AI systems.
Key Developments
The V v. European Parliament decision establishes that transferring medical data between institutions constitutes an interference with Article 8 ECHR rights regardless of the recipient's purpose. Critically, even where a legitimate employment-law obligation exists to assess fitness for duty, the transfer must be necessary—the institution must demonstrate that no less intrusive alternative was available. In that case, the Parliament could have verified fitness without receiving the full medical file, rendering the transfer unlawful.
The Rotterdam District Court (ROT 20/3286) awarded immaterial damages for unlawful retention and processing of medical reports, confirming that violations of health-data provisions trigger not only administrative fines but also civil liability. The same court's detailed psychiatric examination framework in the childcare benefits scandal illustrates how medical data processing in litigation contexts requires proportionality: requests for anamnesis, treatment history, and ADL limitations must be scoped to the specific legal question at issue.
Enforcement confirms regulators' focus on healthcare sector compliance. The Irish DPC fined Midlands Regional Hospital Tullamore €300,000 for violations spanning Articles 5(1)(f), 28, 30, 32(1), and 34 GDPR—covering integrity, processor contracts, records of processing, security measures, and breach notification. The Italian Garante's action against Copacabana s.r.l. reinforces that insufficient legal basis remains a foundational enforcement trigger even at lower fine levels.
Practical Guidance
Map each processing purpose to a specific Article 9(2) condition and a corresponding Article 6 basis. Healthcare providers relying on Article 9(2)(h) must confirm processing genuinely relates to health service management, not administrative convenience.
Apply the necessity test from V v. European Parliament to all inter-institutional transfers. Before sharing medical data with any third party—including employers, insurers, or other care providers—document why no less intrusive measure suffices.
Maintain executed Article 28 agreements with all processors and keep Article 30 records current. The Tullamore fine demonstrates that processor governance and processing inventories are independently enforceable in healthcare settings.
Implement Article 32 security measures calibrated to health data sensitivity and establish Article 34 breach notification protocols. The Dutch DPA's Woo-decision on healthcare data leaks signals active monitoring of breach response timelines.
Scope medical examinations and data requests in litigation to the specific legal question. The Rotterdam court's structured questionnaire approach shows that proportionality in data collection is judicially enforceable and excess collection risks damages liability.