Beyond the EHR: Navigating Privacy and Dynamic Consent for New Data Sources
A Review of Privacy and Consent Management in Healthcare: A Focus on Emerging Data Sources
This paper provides a comprehensive review of privacy and consent management frameworks in healthcare, specifically focusing on the integration of New Data Sources (NDS) such as wearables, social media, and patient-generated data. It evaluates legal requirements across NZ, AU, EU, and the US, identifying a critical gap between current legislation and the technical capabilities required for flexible, dynamic consent in a "Big Data" healthcare era.
TL;DR
As healthcare shifts toward precision medicine, the data landscape is expanding from static Electronic Health Records (EHR) to New Data Sources (NDS)—including wearables, social media footprints, and genetic data. This paper reviews the legal and technical chasm currently preventing these sources from being safely integrated. The authors argue for a Dynamic Consent model to replace the current "fragile" and opaque systems that dominate the industry.
Background: The NDS Tsunami
We are entering an era of "Precision Driven Health" (PDH). Clinicians no longer want just your blood pressure from a clinic visit; they want a virtual holistic image built from your Apple Watch, your nutritional logs, and potentially even behavioral insights from social media.
However, the "legal ground reality" is that current frameworks like HIPAA (US) or HPIC (NZ) were designed for a world where data stayed inside the hospital walls.
The Core Problem: Static Laws vs. Dynamic Data
The authors identify a primary friction point: Consent Revocability.
- EHR Data: Often governed by "implied consent" for direct care; difficult to withdraw if already part of a diagnostic history.
- NDS Data: Highly private and "fragile." A patient might share Fitbit data for a weight study today but want to revoke it tomorrow if they change insurance providers.
Current systems (RBAC - Role-Based Access Control) are too rigid. They assign access based on job titles (e.g., "Nurse"), not the specific context or the patient's individual preference regarding sensitive NDS.
Methodology: A Legal and Cryptographic Audit
The paper conducts a dual-track analysis:
1. The Legal Gap
The authors compared the New Zealand HPIC, Australian NSW HRIPA, EU Data Protection Directive, and the US HIPAA.

The verdict? None of these legislations specifically address NDS. While they cover "identifiable information," they lack the nuance required for data that flows from a third-party consumer app into a clinical environment.
2. The Technical Evolution
The authors reviewed several technical "Access Control" paradigms:
- Smart Card Systems: Secure but physically fragile (cards get lost or broken).
- Attribute-Based Encryption (ABE): Mathematically elegant as it embeds policies into the data itself. However, it struggles with Attribute Revocation—if a doctor leaves a hospital, revoking their "key" without re-encrypting everything is a massive computational challenge.
- Consent Based Access Control (CBAC): Uses tokens with specific lifetimes, which is more aligned with the "fragile" nature of NDS.
Critical Insights: Why Existing Research Fails
The paper points out that most existing work ignores the human element. Patients are "out of the loop." Most EHR systems do not provide a "dashboard" where a patient can see who accessed their data and why.
The authors highlight the Google DeepMind/Royal Free London case as a warning: when data sharing occurs without explicit, transparent consent for a specific purpose, it leads to legal and public trust failures.
Challenges for the Future
To achieve a truly "Precision Driven" health system, the authors list several hurdles:
- Interoperability: How do we sync geographically dispersed "Big Data" sources with clinical standards?
- Stakeholder Balance: Including insurance companies and government bodies without overburdening the patient with "consent fatigue."
- The "Break the Glass" Scenario: How do we maintain a patient's restrictive NDS consent during a medical emergency where saving a life requires bypassing those rules?
Conclusion: Toward Dynamic Consent
The paper concludes that we need a Dynamic Consent Framework. This isn't just a "Yes/No" checkbox at the registration desk. It is a living process where:
- Patients can withdraw access to NDS at any time.
- Audit logs are transparent and available to the patient.
- Access is context-aware (e.g., "My GP can see my heart rate, but the hospital researcher cannot").
As we move toward a data-driven healthcare society, the "patient in the loop" becomes not just a legal requirement, but a technical necessity for safety and trust.
