Brief IA

Doctolib Shares Your Medical Data with an AI: How to Respond

⚖️ Regulation & Ethics·Tom Levy·

Doctolib Shares Your Medical Data with an AI: How to Respond

Doctolib Shares Your Medical Data with an AI: How to Respond
Key Takeaways
1Doctolib plans to share the medical data of 60 million users with an AI for research purposes.
2The information will be anonymized and analyzed by researchers from Inria, Inserm, and Université Paris Cité.
3The LDH expresses concerns regarding the security and anonymization of data stored at Amazon.
💡Why it mattersThe initiative raises questions about data privacy and the transparency of Doctolib's practices.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Doctolib and AI: An Ambitious but Controversial Project

Doctolib, the renowned medical appointment booking platform, is planning to take a new step by integrating artificial intelligence into the analysis of its users' medical data. Starting in August, the company intends to make the health information of its 60 million users available to AI. This data, which includes appointments, prescriptions, lab results, and medication orders, will be analyzed by researchers from Inria, Inserm, the University of Paris Cité, and Doctolib itself. The stated goal is to advance medical research and improve the prevention of health risks as well as emergency management.

Unclear Communication

Doctolib users were informed about this initiative through an email sent in early July, a time when many are on vacation and do not regularly check their inboxes. The message, titled "Doctolib is Committed to Research to Improve Health," may have gone unnoticed by some. It specifies that starting in August 2026, Doctolib will collaborate with renowned French scientific institutions for a project aimed at improving patient care pathways through AI. The goal is to simplify the often complex and tedious medical journey of patients by identifying certain health risks earlier and optimizing care management.

Concerns from Associations

Despite promises of data anonymization, the project raises concerns, particularly regarding the storage and use of this information. Doctolib assures that the data will be kept for a maximum of five years, encrypted, and secured. However, the Ligue des Droits de l'Homme (LDH) has expressed reservations in a statement, highlighting that Doctolib uses the services of Amazon, an American company subject to its country's laws, including the Cloud Act. This legislation allows U.S. authorities to compel digital service providers to hand over data, fueling fears of collaboration with American companies in an environment of increased surveillance.

Data Security in Question

The LDH is also worried about data security at a time when cyberattacks are on the rise. It recalls that 33 million French people were affected by the hacking of the mutual insurance companies Viamedis and Almerys. The effectiveness of anonymization is also questioned, as health data is particularly sensitive, touching on individuals' privacy. It contains information about diagnoses, medical treatments, and health histories, presenting risks of stigmatization, discrimination, and abusive profiling.

Protecting Medical Data

To participate in this research program, Doctolib has opted for a default "opt-in" method, meaning that all users are automatically included unless they explicitly express their refusal. This option is mentioned at the end of the email sent to users. For those who wish to oppose the use of their data, Doctolib offers an online form that does not require a login. Users simply need to provide their first name, last name, and date of birth. They can also request the deletion of their data from the program by sending an email to contact.dataprivacy@doctolib.com.

The implementation of this program in the middle of summer, without an explicit request for consent and with communication deemed vague, raises doubts about the trustworthiness of Doctolib in managing such sensitive data.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.