Would you be willing to let artificial intelligence use your sensitive medical information? That is what Doctolib plans to do from August 2026 - effectively tomorrow.
The platform intends to use the data of all 60 million of its users: appointments, prescriptions, laboratory results and medicines. Every piece of information relating to your health would be supplied to an AI system for analysis by researchers from Inria, Inserm, Université Paris Cité and Doctolib. The stated aim is to advance medical research, while also improving the prevention of risks and emergency situations.
Users were alerted by a somewhat vague email headed “Doctolib commits to research to improve health”. It was sent at the beginning of July, during the holiday period when inboxes can easily go unchecked. It is, admittedly, a rather odd approach:
“From August 2026, we will be working with a research team linked to three leading French scientific institutions (Inria, Inserm and Université Paris Cité) on the research project ‘Improving care pathways through artificial intelligence’. Appointments piling up, several practitioners to coordinate… For too many patients, getting treatment can sometimes feel like an obstacle course. We want to change that by identifying certain health risks earlier and improving patient care.”
Doctolib medical data and AI research
Although Doctolib says that all data will be anonymised, the scheme raises numerous questions. The first concerns where this information will be stored and how it will be used. The platform states that the data will be retained for no more than five years, encrypted and secured. But where will it be held, and under what conditions? These are among the concerns raised by the LDH, which has criticised the plan in a statement. The association points out that Doctolib is a customer of Amazon, a US company subject to its domestic laws:
“The LDH recalls that the previous criticisms and legal challenges concerning Doctolib’s use of servers owned by Amazon Web Services, which remain subject to the Cloud Act (legislation allowing US authorities to compel American digital service providers to hand over data), the suspicions of collaboration with US companies, and the context of authoritarian drift in the United States, remain relevant.”
Associations strongly oppose the scheme
The association is also concerned about the security of the data itself, at a time when many organisations are falling victim to hacks:
“The increasing number of cyber-attacks and data thefts (including the 33 million French people affected by the hacking of the Viamedis and Almerys health insurers) can only heighten these concerns.”
It is more broadly questioning whether anonymisation is truly effective, as well as the consequences that this research could have for patients’ everyday lives:
“The LDH stresses that health data is sensitive data, affecting the deepest privacy of the individual. As it records diagnostic details, medical treatments and health histories, it carries a significant risk of stigmatisation, discrimination and abusive profiling.”
How can you protect your medical data?
For its AI research, Doctolib has chosen an “opt-in” approach. In other words, every user is assumed by default to agree to provide their information, even if they are unaware of it. To be left out of the database, they must expressly ask not to be included. The problem is that this option appears right at the end of the email sent several weeks ago.
To prevent your data from being provided to an AI system, Doctolib has set up a dedicated form available at this address. There is no need to log in to your account: you simply need to enter your first name, surname and date of birth. You may also request that your data be removed from the programme afterwards by emailing [email protected].
The fact that Doctolib is implementing this AI programme in the middle of summer, without seeking users’ explicit permission and while notifying them through a somewhat unclear email, does not exactly inspire confidence about entrusting it with your data.
Following our article, Doctolib responded:
This work falls within public-interest research, precisely the type of research that the CNIL’s MR-004 methodology is designed to regulate and encourage: advancing treatment, prevention and access to healthcare for the benefit of patients and society. This public-interest purpose underpins the framework in which we operate.
This research is far from unprecedented: the Health Data Hub’s public register lists more than 10,000 separate projects registered under the MR-004 methodology, with the first dating from 16 July 2018. This framework is applied every day by hospitals and major public research cohorts in France. There is an issue that we fully acknowledge: tomorrow’s medicine will rely on health AI models, and these models are currently designed overwhelmingly outside Europe, using data that is not our own. By conducting this research in France, with French public and academic partners, under a framework set by the CNIL that is among Europe’s most demanding, we are helping to ensure that our country has its own tools, tailored to its population and healthcare system, rather than becoming dependent on others. It is as much a matter of quality of care as it is of sovereignty.
Comments
No comments yet. Be the first to comment!
Leave a Comment