Doctolib Shares Your Medical Data with an AI: How to Respond

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Doctolib and AI: An Ambitious but Controversial Project
Doctolib, the renowned medical appointment booking platform, is planning to take a new step by integrating artificial intelligence into the analysis of its users' medical data. Starting in August, the company intends to make the health information of its 60 million users available to AI. This data, which includes appointments, prescriptions, lab results, and medication orders, will be analyzed by researchers from Inria, Inserm, the University of Paris Cité, and Doctolib itself. The stated goal is to advance medical research and improve the prevention of health risks as well as emergency management.
Unclear Communication
Doctolib users were informed about this initiative through an email sent in early July, a time when many are on vacation and do not regularly check their inboxes. The message, titled "Doctolib is Committed to Research to Improve Health," may have gone unnoticed by some. It specifies that starting in August 2026, Doctolib will collaborate with renowned French scientific institutions for a project aimed at improving patient care pathways through AI. The goal is to simplify the often complex and tedious medical journey of patients by identifying certain health risks earlier and optimizing care management.
Concerns from Associations
Despite promises of data anonymization, the project raises concerns, particularly regarding the storage and use of this information. Doctolib assures that the data will be kept for a maximum of five years, encrypted, and secured. However, the Ligue des Droits de l'Homme (LDH) has expressed reservations in a statement, highlighting that Doctolib uses the services of Amazon, an American company subject to its country's laws, including the Cloud Act. This legislation allows U.S. authorities to compel digital service providers to hand over data, fueling fears of collaboration with American companies in an environment of increased surveillance.
Data Security in Question
The LDH is also worried about data security at a time when cyberattacks are on the rise. It recalls that 33 million French people were affected by the hacking of the mutual insurance companies Viamedis and Almerys. The effectiveness of anonymization is also questioned, as health data is particularly sensitive, touching on individuals' privacy. It contains information about diagnoses, medical treatments, and health histories, presenting risks of stigmatization, discrimination, and abusive profiling.
Protecting Medical Data
To participate in this research program, Doctolib has opted for a default "opt-in" method, meaning that all users are automatically included unless they explicitly express their refusal. This option is mentioned at the end of the email sent to users. For those who wish to oppose the use of their data, Doctolib offers an online form that does not require a login. Users simply need to provide their first name, last name, and date of birth. They can also request the deletion of their data from the program by sending an email to contact.dataprivacy@doctolib.com.
The implementation of this program in the middle of summer, without an explicit request for consent and with communication deemed vague, raises doubts about the trustworthiness of Doctolib in managing such sensitive data.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.