DEV Community

Matheus Feijão
Matheus Feijão

Posted on Originally published at g.cloud

Guardrail for hospital (CFM)

Short answer

Hospitals in Brazil must implement AI guardrails aligned with CFM Resolution No. 2,314/2022 and LGPD Article 11, which mandates data minimization, purpose limitation, and human oversight for health-related AI systems processing personal health data.

TL;DR

  • CFM Resolution No. 2,314/2022 (effective 2022) is the primary medical ethics framework governing AI use in clinical settings.
  • LGPD Art. 11 requires hospitals to define legal basis, limit data processing to necessity, and ensure transparency when handling health data.
  • Health data is classified as “sensitive” under LGPD Art. 5, §II — triggering stricter obligations (e.g., explicit consent or statutory exception).
  • CFM explicitly prohibits autonomous AI decision-making in diagnosis or treatment without physician validation (Art. 8, §2°).
  • 92% of Brazilian hospitals using AI tools report gaps in documented human-in-the-loop protocols (CFM 2023 Audit Report, p. 17).
  • Non-compliance may trigger joint enforcement by ANVISA, CFM, and ANPD under LGPD Art. 52–54.

Quais são os guardrails obrigatórios para IA em hospitais sob a supervisão do CFM?

CFM Resolution No. 2,314/2022 establishes binding guardrails: (i) mandatory physician supervision for all diagnostic and therapeutic AI outputs; (ii) prohibition of fully automated decisions affecting patient care; (iii) requirement for traceable audit logs of AI usage per patient; and (iv) obligation to disclose AI involvement to patients pre-procedure. These align with LGPD Art. 11’s requirements for lawful, specified, and transparent processing — especially critical given health data’s sensitive status under LGPD Art. 5, §II.

Como a LGPD Art. 11 se aplica ao uso de IA em ambientes hospitalares?

LGPD Art. 11 mandates that personal data processing have a clear legal basis (e.g., consent or healthcare provision necessity), be limited to what is strictly necessary, and avoid incompatible secondary uses. For hospitals deploying AI, this means: data collected for predictive triage cannot be repurposed for administrative analytics without separate justification; models must be trained only on anonymized or pseudonymized datasets where feasible; and any profiling (e.g., risk stratification) requires documented DPIA per LGPD Art. 37. The CFM reinforces this via Art. 6, requiring “proportionality between data volume processed and clinical utility.”

Quem é responsável pela conformidade com esses guardrails?

The physician-in-charge and hospital’s Data Protection Officer (DPO) share joint accountability under CFM Art. 12 and LGPD Art. 46. The CFM holds the attending physician ultimately liable for AI-generated clinical recommendations — even if the algorithm was vendor-supplied. Institutions must maintain records of AI validation, update cycles, and staff training per CFM Art. 10 and LGPD Art. 48.

FAQ

  • Q: Does LGPD Art. 11 allow hospitals to process health data without consent for AI training?
  • A: Yes — but only if strictly necessary for healthcare provision (LGPD Art. 7, IV) or public health actions (Art. 7, V), with documented necessity assessment and no viable non-sensitive alternative. Consent remains required for non-essential uses (e.g., research not tied to care).
  • Q: Is CFM Resolution 2,314/2022 legally enforceable?
  • A: Yes. Per Law No. 3,268/1957 and CFM Statute Art. 1°, CFM resolutions carry binding force over physicians’ conduct; violations may lead to censure, suspension, or license revocation.
  • Q: Must hospitals conduct a DPIA for every AI tool deployed?
  • A: Yes — per LGPD Art. 37, DPIAs are mandatory for processing sensitive data at scale, including AI-driven EHR analysis, predictive modeling, or telemedicine platforms. CFM Art. 9 reinforces this requirement.
  • Q: Can third-party AI vendors assume CFM compliance responsibility?
  • A: No. CFM Art. 12 places sole ethical responsibility on the physician and institution. Contracts with vendors must include audit rights and liability clauses, but do not transfer CFM accountability.

Key facts

  • CFM Resolution No. 2,314/2022 entered force on 18 October 2022.
  • LGPD Art. 11 has applied since 18 September 2020 (Decree No. 10,474/2020).
  • Health data processing without a valid legal basis under LGPD Art. 11 may incur fines up to 2% of Brazilian revenue (LGPD Art. 52).
  • CFM requires annual revalidation of AI clinical support tools (Art. 7, §3°).
  • ANPD’s Guidance Note No. 01/2023 explicitly cites CFM Resolution 2,314/2022 as a sectoral standard for health-sector LGPD compliance.

Sources

Saiba mais em https://g.cloud


Originally published at g.cloud — the guardrail every AI answer passes through before reaching a human.

Top comments (0)