Another September, Another Spending Review.

This is almost becoming a tradition for the national healthcare service in Italy. Comes September… and a new spending review hits the pharmaceutical and medical device industry.

On August 4, 2015 a law decree has been approved by lawmakers, which introduces a number of new mechanisms for monitoring and reining in public spending in the healthcare sector. In particular, the new legislation has introduced several measures:

  • Negotiations with current suppliers of the national healthcare service in order to achieve a 5% reduction in current spending for general supplies;
  • Negotiations with current suppliers of medical devices in order to comply with the spending thresholds agreed upon between the central government and regional authorities;
  • Centralized negotiations with pharmaceutical companies in order to decrease the reimbursement price of products currently reimbursed by the national healthcare service.

While measures aimed at cutting spending in connection with general supplies and medical devices have been entrusted in principle to local authorities and healthcare providers, the national pharmaceutical agency (“AIFA”) plays a central role in the envisaged mechanism to achieve savings for pharmaceutical products. In accordance with the provisions of the new decree, AIFA has indeed conducted negotiations throughout the month of September 2015, with the aim of decreasing overall spending. The new legislation provides the grouping of products in several “clusters” that include therapeutically similar products, regardless of their active principles. The lowest price in each cluster is then used as the reference price for direct negotiations between AIFA and manufacturers.

The new measures also provide that, in case of failure to reach an agreement, reimbursement by the national healthcare service may be withdrawn. However, it is also expressly provided that generic products are not admitted to reimbursement until any patents and supplementary protection certificates of branded products are definitely expired, thus providing the industry with assurances in connection with their protected drugs.

The reiterated attempts by public authorities to renegotiate prices with suppliers appear to clash not only with basic contractual principles (“pacta sunt servanda”), but also with fundamental rules of public procurement legislation. As the government (in fact, almost yearly) demands discounts on existing contracts, reliance on such contracts is affected, along with transparency and open competition in public procurement procedures. The truth is that the need to cut public expenditures is increasingly overriding basic tenets of contracts and public procurement law.

Med Tech and Pharma industry associations have voiced their concerns, while suggesting that efficiency and savings may be obtained by the national healthcare service through internal reorganization processes rather than by demanding additional discounts to suppliers. In fact, if we step aside from the conflicting commercial interests of suppliers (who want to maximize their revenues) and purchasers (who need to minimize their costs), we cannot but note that, again, the government appears to use cost cutting tools that focus on quantity rather than quality. On the contrary, we would expect that more emphasis should be given to Health Technology Assessment and innovation. We surely need to spend less money, but also to spend it more wisely.

Drones and Privacy: Risks and Recommendations.

Drones Are Increasingly Used in the Civil Field. The civil use of drones is increasing, as also witnessed by the DRONITALY event that will be hosted near the Milan Expo in late September. And attorneys who are contributors to this blog find it certainly exciting when new technologies become widespread and thus present legal challenges!

When a new technology starts to become mainstream, the lack of adequate legal provisions is often deplored. In truth, the interpreter needs to take a deep breath and (i) identify the applicable laws, as well as (ii) understand the unique risks entailed by such novel technology, while comparing them with previous technologies. In the case of unmanned vehicle systems, commonly referred to as drones, it does not look like the applicable rules are lacking, but they are simply difficult to apply.

EU Data Protection Authorities Scratch Their Heads Together. The data protection authorities of the European Union, who work together within the “Article 29 Data Protection Working Party”, have recently tackled the issue of drones. The June 16, 2015 opinion by the “Article 29 Data Protection Working Party” (“Opinion”) is especially interesting because of its solid logic approach, which starts with a careful analysis of potential data protection risks linked to the increased use of drones, goes on to finding specific issues that are unique to drones, and ends with a number of recommendations to operators, manufacturers, regulators and law enforcement officials.

Unique Challenges to Personal Data. Drones are aerial vehicles that can be used for a host of activities (including – as pointed out by the Opinion – dull, dirty or dangerous operations, also known as “3D”). The Opinion is careful in pointing out that the use of drones per se is not problematic: it is the possibility to equip drones with recorders of audio and video data that poses challenges to privacy. Additionally, drones overcome obstacles such as walls or fences, and small drones may even enter buildings. Subjects whose data are recorded are often unaware of the processing of their data and, if they are or suspect that they might be, this may trigger a “chilling effect” on their conduct. In short, the principles of purpose limitation, data minimization and proportionality are at risk. Therefore, the Opinion strongly encourages a data protection impact assessment to check how, given the circumstances, the processing of data by a drone may impact the privacy of interested subjects. The assessment must start early on, and the rule of data protection by design must be respected by manufacturers and users. Such assessment must take into account:

  • The Applicability (or Inapplicability) of Exceptions. When personal data is processed by sensors installed on the drone, there is no doubt that data protection legislation applies. The exception for personal data processed in the course of a personal or household activity is never compatible with the sharing of such data on the internet. Law enforcement may also be found as a legal basis for processing, but it must be lawful, necessary and proportionate: indiscriminate surveillance is not acceptable.
  • Informed Consent. Freely given, specific and informed consent is difficult to achieve when it comes to drones. The Opinion suggests to try anything that may work (they, more elegantly, talk about a “multi-channel approach”): from signposts to symbols, signals, lights, registration marks or the publication on the internet of information on drone activities, so that a specific drone can not only be detected by interested subjects, but also linked to a certain data controller. Other grounds for lawful data processing may be found depending on the circumstances, such as performance of a contract to which the data subject is a party (e.g., security services offered through drones only recording the data subject’s property), processing to protect the vital interests of the data subject (e.g., rescue of victims of accidents) or for the purposes of a legitimate interest (e.g., wildlife research).
  • Security Measures. Personal data gathered must be safely stored and communicated (encryption is encouraged).
  • Anonymization or Deletion of Data. Data must not be kept for a period that goes beyond what is necessary to fulfill the purpose of the processing. Data must be accessed only on a limited basis and anonymized or deleted as soon as possible.

Many of the legal issues connected with drones are similar to those arising in case of video surveillance, already tackled by the Italian Data Protection Authority in 2010, with the notable exception that providing information to data subjects may prove to be much more challenging in case of aerial vehicles that fly at a distance.

Less Open Tenders in e-Health Government Contracts?

In Italy, general principles on government contracts mandate that the provision of services to public administrations must be preceded by the issuing of a public tender allowing various companies to transparently compete for the job. This blog has recently discussed a couple of court decisions that in fact confirmed and further strengthened such principle.

However, a recent decision by the Consiglio di Stato, the higher court which is competent for administrative matters, seems to go in the opposite direction in a case regarding services linked to digital health.

The facts of the case relate to the Lecce health center, located in Puglia, Italy, which assigned to a certain firm the tasks of providing maintenance IT services in the fields of RIS (Radiology Information System) and PACS (Picture Archiving and Communication System). The same firm had previously provided IT maintenance in the RIS-PACS field, was the exclusive authorized reseller of the concerned systems and was in charge of the integration of other IT systems already in place the health center. Given such qualifications, the health center refrained from issuing a public tender and instead used the tool of the “negotiated process” with such IT firm only, which is allowed when, due to technical reasons, the supply contract can be assigned only to a single firm. The petitioner of the case, on the contrary, argued that any other qualified IT company was able to integrate and maintain the IT systems.

What is interesting to note is that the Court gives weight to the “special complexity” of the services constituted by the shift to a digital imaging system: under such view, e-Health is viewed as a field fraught with risks (on data, and ultimately on patients), thus allowing to recur to the exception constituted by the “negotiated process” rather than to rely on the rule of open tenders.

Electronic Medical Record: Italian Data Protection Authority Issues New Guidelines

On June 4, 2015, the Italian Data Protection Authority issued new guidelines governing the collection and processing of personal and sensitive data through the Electronic Medical Record.

  • What is an Electronic Medical Record?

A record, kept by a hospital or a healthcare center, containing patients’ clinical history at that specific hospital or healthcare center.

  • Patients’ rights

The guidelines set forth several rights to which patients treated at any hospital or healthcare center are entitled:

  1. Patients are entitled to decide whether the hospital or the healthcare center may store their data through an Electronic Medical Record. If a patient denies his/her consent, physicians will be able to rely only on information gathered during examination and treatment, as well as on information previously conveyed by the patient, if any. Denial of consent will not affect the possibility of being treated at the hospital/healthcare center.
  2. Specific consent is needed for the collection of certain categories of sensitive date, such as HIV infections, abortions, data relating to sexual assault. With respect to such data, patients will have the right to limit access to specific individuals/professionals.
  3. In addition to all rights granted by the Data Protection Code (such as the right to receive confirmation on the existence of personal/sensitive data, to know the origin of the data, the purpose and means of processing, as well as the logic applied to the processing) patients will also be entitled to receive information on each access to their Electronic Medical Record.
  • Hospitals and healthcare centers’ obligations

Hospitals and healthcare centers are required to provide patients with a thorough privacy notice concerning the processing of data through the Electronic Medical Record. Upon patients’ request, hospitals and healthcare centers shall also provide information concerning stored data and access logs to the Electronic Medical Record (including the professional accessing the data, date and time of access) within 15 days of the request. Patients will also be entitled to redact data or healthcare documentation that they do not wish to be included in their Electronic Medical Record.

The Data Protection Authority’s guidelines also address important technical aspects and provide that patients’ healthcare information contained in the Electronic Medical Record shall be segregated from other administrative data. Sensitive data will need to be encrypted. Furthermore, access to the record will be granted only to medical staff involved in the patient’s treatment and any access and processing will be recorded on log files to be kept by the hospital or healthcare center for at least 24 months.

Lastly, the guidelines set forth strict data breach requirements for hospitals and healthcare center, by providing that any data breach or unauthorized access shall be reported to the Data Protection Authority within 48 hours of knowledge of the breach. Failure to report will lead to the application of penalties.

See the Data Protection Authority’s presentation of the new guidelines

A New e-Health National Plan

A new Agreement on Digital Health (“Patto sanità digitale”) prepared by the Ministry of Health has been submitted to the State and Region Conference in June 2015. The proposed agreement between regions and national government aims at setting forth a precise timetable for the implementation of e-health in Italy and envisages a steering committee in charge of monitoring the status of implementation of the plan.

Among the priorities of the new proposal, the Ministry of Health has indicated the adoption of effective solutions for patient workflow management and patient relationship management, to be achieved through the widespread use of electronic clinical records, telemedicine services and mobile health. According to the plan presented by the government, e-health solutions are key to a deeper overhaul of the national healthcare service in order to increase care outside of hospitals and find more efficient ways of bringing healthcare to patients.

Telemedicine solutions, including remote monitoring and diagnosis, would allow the national health service to bring services to patients in a more efficient way. While a specific piece of legislation addressed to telemedicine services has not yet been enacted, on February 20, 2014 the Italian Ministry of Health issued a set of official national guidelines on telemedicine, which set forth a useful regulatory and technical framework for healthcare authorities and private operators active in the provision of telemedicine services.

Unlike previous guidelines, however, the latest digital health plan also aims at restructuring the use of financial resources devoted to the development of telemedicine solutions, in order to convey funds only to more effective projects capable of fostering the widespread adoption of e-health instruments by other healthcare providers. The government also plans to increase the involvement of private actors in these development projects, through project financing and performance based service contracts.

While it is expected that patients will ultimately benefit from a more efficient model for the supply of healthcare, the government also hopes to rein in spending through a more efficient use of resources and a closer monitoring of test prescriptions and drug consumption, which the new e-health solutions will enable.

What’s New in E-Health? Interesting Developments to Consider.

E-Health is a term often used to describe a relationship established between electronic tools and the art of medicine. The European e-Health Action Plan 2012-2020, for example, describes e-Health as a “mean using digital tools and services for health”, which involves an interaction between patients and health-services providers. Within e-Health, the role of telemedicine is considerably growing.

Regulations and guidelines in the field of e-Health are growing in the Italian jurisdiction, too. In particular:

  1. A new Agreement on Digital Health (“Patto per la Sanità Digitale”) prepared by the Ministry of Health has been proposed to the State and Region Conference in June 2015
  2. New guidelines on electronic health records have been issued by the Data Protection Authority on June 4, 2015; and
  3. An interesting administrative court decision issued on July 10, 2015 set forth innovative principles in the field of digital health supplies to the public administration.

Our next blog posts will explore the above developments, which are set to change certain regulatory aspects of e-Health.

Stay tuned, and happy summer!

Courts Limit Administration’s Discretion in Public Contracts

Recent rulings by two administrative courts in Italy have restricted the discretion of public entities in the award of public contracts without open procurement procedures, in particular in the healthcare sector. The two decisions reaffirm the Courts’ policy of restricting recourse to in-house contracts and extensions of expired contracts.

The first decision, issued on May 7, 2015 by the Supreme Administrative Court in Rome, invalidated the award of a service contract to a company established and owned by the regional government of Puglia for the provision of in-house services to healthcare facilities in the region. The contract was awarded without a public procurement procedure, on the basis of the fact that it was an in-house service contract. The Court, deciding upon an appeal brought by a competitor who was not granted the possibility to submit its offer, held that a procurement procedure open to competitors must always occur, even if a governmental entity has established a specific vehicle for the purpose of providing in-house services. The Court left a limited room for in-house services, i.e., services provided by an entity fully controlled and managed by the same administration awarding the contract, as if it was one of its internal departments.

On a different occasion, the regional administrative Court of Turin had the chance to reiterate that the extension of expired public contracts is prohibited by public procurement legislation, as it prevents competitors from participating in new public procurement procedures. In addition to stating again this general principle, the Court in its decision of April 3, 2015 no. 573 also held that governmental entities should proceed with calls for tenders whenever the goods or services they intend to procure are not covered by a national or regional framework agreement. In an effort to curb public spending, the Italian government has implemented in several sectors a centralized negotiation process, whereby a central governmental agency (“Consip”) enters into framework agreements for the supply of goods and services to local administrations. Local administrations are generally bound to adhere to such framework agreements and, if they do so, no call for tender needs to be issued. Public hospitals, on the other hand, must adhere to healthcare-specific regional framework agreements and to Consip agreements; only if no such agreements exist they may proceed with the issuance of a call for tenders.

In the case the before the Court, a local healthcare office postponed the validity of an expired supply contract, after assessing that the framework agreement entered into by Consip would have only partially covered the needs of the local administration and – most importantly – would have entailed a higher cost than the expired agreement. Regardless of the potential savings that the extension of the existing contract would have granted the public administration, the Court held that no exceptions can be envisaged to the issuance of a public procurement procedure. Clearly, more than by savings, the Court must have been guided by the desire to sanction a widespread practice of extending expired contracts, which in most cases stifles competition and does not guarantee lower prices.

It is expected that this policy, increasingly adopted by many administrative Courts, will be one of the highlights of the new public procurement legislation that is currently being examined by Italian lawmakers. The new public procurement code is, in fact, expected to provide new instruments for a more effective fight against corruption and inefficiencies within the public administration.

On-line Sale of OTC Medicinal Products

Effective as of tomorrow (July 1, 2015), Italian consumers will be able to purchase over-the-counter (“OTC”) drugs on-line.

Legislative decree nr. 17 of 2014 (“Decree”), enacting EU Directive 2011/62, introduced an innovative way of marketing medicinal products for pharmacies and authorized retailers. In order to do so, pharmacies and retailers must meet several conditions, aimed at preventing marketing of counterfeit products.

  1. First of all, pharmacies and retailers must be authorized by either regional entities, provinces or other competent authorities, upon providing the following information:
  • name, VAT and full address of the logistic site;
  • starting date of on-line sale;
  • website address and any other information that may be necessary to identify the seller’s website.

Any change must be communicated within 30 days, subject to forfeiture of the authorization.

  1. Secondly, the seller’s website must contain at least:
  • information relating to the authorizing authority;
  • a link to the Ministry of Health’s website;
  • a specific logo, including a link to the list of the authorized pharmacies and retailers, maintained by the Ministry of Health.

Additionally, the Ministry of Health’s website shall contain a link to a website created by the European Medicines Agency, which will include information on the purpose of the specific logo, as well as on the risks relating to medicinal products that are unlawfully supplied to the public. The Ministry of Health’s website will also contain information relating to the applicable laws and regulations, including any information on differences vis-à-vis other countries as to conditions regulating the supply of medicinal products.

  1. Lastly, distribution shall be carried out in compliance with good distribution practices.

The Italian Agency for Pharmaceutical Products (Agenzia Italiana del Farmaco, “AIFA”) will be in charge of enforcing the new set of rules. AIFA will direct an anti-counterfeiting system in cooperation with the Ministry of Health, the High Institute for Health (Istituto Superiore di Sanità, “ISS”), the Anti-counterfeiting and Health Department of the Police (Nuclei Antisofisticazione e Sanità, “NAS”), and the Customs Authorities. The system will receive reports concerning allegedly counterfeit medicinal products, and AIFA will coordinate seizure of actually counterfeit medicinal products.

Furthermore, the Ministry of Health, upon AIFA’s proposal, will have the power to issue cease and desist orders directed at on-line sellers, as well as orders aiming at blocking the access to websites selling counterfeit medicinal products.

Lastly, on-line sale of prescription drugs will be punished with imprisonment up to one year and a fine between Euro 2,000.00 and Euro 10,000.00, whereas on-line sale of medicinal products by unauthorized individuals or entities will be punished with imprisonment from 6 months to 2 years and a fine between Euro 3,000 and Euro 18,000. On-line sale of counterfeit medicinal products will be instead punished with imprisonment up to 3 years and with a fine between Euro 2,600.00 to Euro 15,600.00.

The measures introduced by the Decree appear balanced. On the one hand they grant an overall wider access to OTC medicinal products along with a presumable price reduction; on the other hand they set forth a solid enforcement system preventing and punishing marketing of counterfeit drugs. As with every innovation in the field of health, only time will tell if benefits and risks are actually balanced.

3D Printing In Healthcare: Regulatory Issues To Consider

The Democratization of 3d Printing: Joys and Sorrows

A fascinating technology is becoming more and more widespread and may completely change the world of manufacturing as we know it: 3D printing. An object passed through a 3D scanner or a file downloaded through the internet may enable almost anybody to produce an unlimited number of 3D copies.

This is a classic example of an innovative technology that is going through the process of “democratization”: with the price of 3D printers now in the range of tens of thousands of Euros, a manufacturing method, which was once available only to a few, may now be found in every architecture firm, in your garage and… in your hospital.

A beautiful National Geographic title points to the revolutionary aspects of 3D printing: “As epoch-making as Gutenberg’s printing press, 3-D printing is changing the shape of the future.” As in many other “revolutions”, it is difficult to imagine its full potential at its onset. Therefore, 3D printing sparks both enthusiasm and anxiety. Many intellectual property owners have much to fear from the possibility of producing countless unauthorized copies of products looking exactly like theirs. While the music and movie industries already suffered when home taping or file sharing became commonplace, 3D printing may impact nearly all industries. Others point to the risks connected with the complete lack of control over the production of guns or other dangerous objects (with others questioning how serious of a threat this might be).

3D printing is already vastly used in the field of medical practice, and many more uses can be imagined in the future (printing organs for transplants is no longer an entirely futuristic scenario). Recent research on 3D programs deployed in Italian hospitals point to the advantages related to 3D models of patients for pre-surgery planning, for training, as well as for obtaining the patient’s informed consent. None of such uses are likely to trigger legal or regulatory issues, if data protection aspects are correctly handled.

Is 3d Printing a Regulated Activity? Is a 3d Printed Item a Regulated Object?

If, instead, a 3D object is created and used closer to patients, it is possible that a regulated item is obtained (most likely a medical device or an advance therapy medicinal product), or that a regulated activity is carried out, with a host of regulatory consequences. In fact:

3d Printing and Liabilities

Who is responsible if a 3D printed medical object is defective? The process of 3D printing involves a number of potentially responsible individuals, who may be liable, in full or in part. A Court would have to determine what went wrong. Depending on the circumstances, the doctor prescribing the 3D object, the surgeon implanting it, the radiologist choosing the images on which the 3D printing process is based, the manufacturers of the 3D printer or of the materials used, the user of a 3D printer… each of them may be responsible for the defect.

However, this is not a new scenario in medical technology, where product liability is always potentially connected with medical malpractice and where finding out the exact responsibility of each subject can be challenging. Italian law sets forth joint liability of all responsible persons and indicates that the person who paid damages has recourse against the other liable persons on the basis of risks, faults and consequences. If such allocation of liability is not possible, then each person is liable in equal parts.

Conclusions

There is often a general sense that an innovative technology is so new that it happens in a legislative vacuum, because how could the legislator have already foreseen rules specific to 3D printing? We have written about a similar approach in the field of medical apps. Instead, new technologies typically land on a pre-existing landscape of applicable regulations, which should be taken into account by innovators and users of innovation. Regulatory authorities may not be ready to start enforcement actions against 3D printing, but may decide to do so in the future.