Who Has Access to Our Medical Data? Medical Confidentiality in the Digital Age

Who Has Access to Our Medical Data? Medical Confidentiality in the Digital Age

The rapid development of digital healthcare has created new opportunities while also raising important questions about medical confidentiality, personal data protection, and patients’ rights.

To discuss these and other pressing issues, we spoke with Ruzanna Movsisyan, Lecturer at the YSMU Healthcare Group and Senior Specialist at the Legal Department, about the legal and ethical challenges of protecting medical confidentiality in Armenia’s digital healthcare system.

  • You recently conducted extensive research on the protection of medical confidentiality in the digital age and the legal and ethical challenges it poses in Armenia. What inspired you to focus on this topic? As a legal expert, what concerns you most about our healthcare system today?

Digital healthcare is one of the greatest achievements of modern medicine, and I am truly inspired by the potential of these systems to enhance the quality of patient care. The goal of my research is not to offer criticism, but to support the system by identifying areas where legal and security-based solutions can make the work of medical professionals even more effective.

  • Today, nearly the entire healthcare system in Armenia has been digitized through the implementation of the ArMed platform. Is our legislation keeping pace with this rapid technological development, or are there still legal gaps?

We are at a natural stage of development. Today, technology is evolving faster than the legal framework, which is typical during periods of digital transformation. This is the historical moment when we can refine our legislation, making it more flexible and better aligned with international best practices.

  • Compared with the strict European standards, such as the General Data Protection Regulation (GDPR), what is the most fundamental element that Europe has already implemented but Armenia has yet to adopt in protecting patients’ data?

The GDPR serves as the gold standard of international practice for us. Our goal is not merely to replicate it, but to adopt its most effective tools, particularly the Privacy by Design approach. This will allow us to build a more integrated and reliable system for the benefit of both patients and physicians.

  • Our digital healthcare system is based on a centralized data model, where all information is stored in one place. What risks does this pose for ordinary citizens if the system is breached or sensitive data are leaked?

A centralized model offers immense opportunities for diagnostics and epidemiological analysis. The challenge lies not in the structure itself, but in strengthening its security layers. Modern digital tools enable us to protect centralized data while maintaining accessibility whenever it is needed.

  • When people hear the phrase “breach of medical confidentiality,” they often imagine serious legal violations. In reality, however, there are also everyday breaches. What are the most common shortcomings you observe in Armenian hospitals today—for example, unattended computer screens or discussions of patient information in public areas?

The workload in medical institutions is significant, and sometimes certain security details may be overlooked due to sheer busyness. This is not negligence; rather, it highlights the need to establish a new workplace culture. We must create conditions where complying with security requirements becomes an easy and automatic part of everyday practice.

  • It is no secret that many physicians share patients’ medical information or X-ray images through common messaging applications such as WhatsApp or Viber when discussing clinical cases or seeking consultations. How safe is this practice, and does it constitute a breach of confidentiality?

Physicians instinctively seek the fastest ways to communicate in order to help their patients. This reflects their dedication to their profession. What we need is to move this communication into the secure environment of electronic healthcare systems by providing healthcare professionals with more convenient and secure tools.

  • How would you assess the level of legal awareness among healthcare professionals, particularly nurses and other mid-level medical staff? Do they fully understand that improper handling of patient data may result not only in ethical concerns but also in criminal liability?

Our healthcare professionals are highly qualified specialists. However, legal aspects often remain in the background because of heavy workloads. By placing greater emphasis on training, we can provide them with additional protection and greater confidence in their daily work. Legal awareness is an essential component of ensuring the safe performance of professional responsibilities.

  • Many people remain skeptical about electronic healthcare systems or are even afraid of them. In your opinion, is this concern justified?

Trust is built through transparency. The questions raised by patients are entirely natural. Our goal is to demonstrate that the digital healthcare system is designed, first and foremost, to protect their rights.

  • Many patients do not even know who has the right to access their medical records. In practice, who can access a patient’s electronic health record and see their medical history?

Transparency is the key to trust. It would be ideal to have a system that enables patients to see how their treatment journey is being improved with the support of their physicians. This is not about surveillance—it is about participatory healthcare.

  • Much has been said about introducing the institution of the Data Protection Officer (DPO). What exactly is the role of a DPO, and how can this position benefit both hospitals and patients?

A Data Protection Officer (DPO) will serve not as an auditor, but as a facilitator. They will work alongside physicians, helping them navigate complex legal issues so that healthcare professionals can focus entirely on patient care. This role will become an essential pillar of the strategic development of healthcare institutions.

  • You have written about the concept of a granular consent model. Could a patient, for example, choose to restrict access to sensitive information related to mental health or gynecology from a general practitioner or other physicians? How can such a model be implemented without compromising patient care?

This represents a new horizon—one that reflects respect for patient autonomy. It will enable us to build physician-patient relationships based on mutual trust and clear agreements, ultimately improving the quality and effectiveness of healthcare.

  • If a patient discovers that a physician who is not involved in their treatment has accessed their electronic medical record without authorization, what legal remedies are currently available in Armenia?

Our objective should be to resolve such issues through systemic improvements rather than litigation. Strengthening existing mechanisms will enable disagreements to be addressed promptly, effectively, and at a professional level.

What is the single most urgent step the Armenian government should take to ensure that digital healthcare is not only effective but also genuinely secure?

The most urgent step is to deepen public and professional dialogue. We must continue constructive cooperation among the government, healthcare professionals, and society so that digital healthcare becomes a source of national pride for Armenia through its safety, security, and high quality.