Abstract The digitalisation of healthcare is transforming not only clinical practice but also the legal architecture through which health rights are protected, coordinated, and operationalised. Using Italy as a doctrinal case study within the European Union (EU) framework shaped by the General Data Protection Regulation, the European Health Data Space, and artificial intelligence (AI) regulation, this article argues that digital healthcare is moving beyond consent-centred protection toward governance-based safeguards. The Italian trajectory is especially revealing because regionalised healthcare governance intersects with centralised digital coordination through the Fascicolo Sanitario Elettronico, the Ecosystem of Health Data, and EU rules on the secondary use of health data. The article contends that this shift does not displace consent as a legal or constitutional value, but requires stronger substitute and complementary safeguards when consent can no longer operate as an effective practical control mechanism. These include clear legal bases, differentiated access regimes, data minimisation, secure processing environments, meaningful patient information, democratic accountability, human oversight, anti-discrimination duties, and clearer allocations of responsibility among clinicians, institutions, and technology providers. AI-mediated care is treated as a downstream test case for whether governance-based legality remains compatible with autonomy, dignity, and responsibility in clinical care.

Beyond Consent-Centred Protection in Digital Healthcare: Italy, Secondary Use of Health Data, and Governance-Based Safeguards for AI-Mediated Care

Paolo Bailo
Co-primo
;
Giovanna Ricci
Ultimo
2026-01-01

Abstract

Abstract The digitalisation of healthcare is transforming not only clinical practice but also the legal architecture through which health rights are protected, coordinated, and operationalised. Using Italy as a doctrinal case study within the European Union (EU) framework shaped by the General Data Protection Regulation, the European Health Data Space, and artificial intelligence (AI) regulation, this article argues that digital healthcare is moving beyond consent-centred protection toward governance-based safeguards. The Italian trajectory is especially revealing because regionalised healthcare governance intersects with centralised digital coordination through the Fascicolo Sanitario Elettronico, the Ecosystem of Health Data, and EU rules on the secondary use of health data. The article contends that this shift does not displace consent as a legal or constitutional value, but requires stronger substitute and complementary safeguards when consent can no longer operate as an effective practical control mechanism. These include clear legal bases, differentiated access regimes, data minimisation, secure processing environments, meaningful patient information, democratic accountability, human oversight, anti-discrimination duties, and clearer allocations of responsibility among clinicians, institutions, and technology providers. AI-mediated care is treated as a downstream test case for whether governance-based legality remains compatible with autonomy, dignity, and responsibility in clinical care.
2026
digital health; health data governance; patient autonomy; secondary use of health data; electronic health record; European Health Data Space; artificial intelligence in healthcare; informed consent; human oversight; medical liability
262
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11581/504125
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact