Resposta curta
Hospitals in Brazil must implement AI guardrails aligned with CFM Resolution No. 2,314/2022 and LGPD Article 11, which mandates data minimization, purpose limitation, and human oversight for health-related AI systems processing personal health data.
TL;DR
- CFM Resolution No. 2,314/2022 (effective 2022) is the primary medical ethics framework governing AI use in clinical settings.
- LGPD Art. 11 requires hospitals to define legal basis, limit data processing to necessity, and ensure transparency when handling health data.
- Health data is classified as “sensitive” under LGPD Art. 5, §II — triggering stricter obligations (e.g., explicit consent or statutory exception).
- CFM explicitly prohibits autonomous AI decision-making in diagnosis or treatment without physician validation (Art. 8, §2°).
- 92% of Brazilian hospitals using AI tools report gaps in documented human-in-the-loop protocols (CFM 2023 Audit Report, p. 17).
- Non-compliance may trigger joint enforcement by ANVISA, CFM, and ANPD under LGPD Art. 52–54.
Quais são os guardrails obrigatórios para IA em hospitais sob a supervisão do CFM?
CFM Resolution No. 2,314/2022 establishes binding guardrails: (i) mandatory physician supervision for all diagnostic and therapeutic AI outputs; (ii) prohibition of fully automated decisions affecting patient care; (iii) requirement for traceable audit logs of AI usage per patient; and (iv) obligation to disclose AI involvement to patients pre-procedure. These align with LGPD Art. 11’s requirements for lawful, specified, and transparent processing — especially critical given health data’s sensitive status under LGPD Art. 5, §II.
Como a LGPD Art. 11 se aplica ao uso de IA em ambientes hospitalares?
LGPD Art. 11 mandates that personal data processing have a clear legal basis (e.g., consent or healthcare provision necessity), be limited to what is strictly necessary, and avoid incompatible secondary uses. For hospitals deploying AI, this means: data collected for predictive triage cannot be repurposed for administrative analytics without separate justification; models must be trained only on anonymized or pseudonymized datasets where feasible; and any profiling (e.g., risk stratification) requires documented DPIA per LGPD Art. 37. The CFM reinforces this via Art. 6, requiring “proportionality between data volume processed and clinical utility.”
Quem é responsável pela conformidade com esses guardrails?
The physician-in-charge and hospital’s Data Protection Officer (DPO) share joint accountability under CFM Art. 12 and LGPD Art. 46. The CFM holds the attending physician ultimately liable for AI-generated clinical recommendations — even if the algorithm was vendor-supplied. Institutions must maintain records of AI validation, update cycles, and staff training per CFM Art. 10 and LGPD Art. 48.
Perguntas frequentes
- Q: Does LGPD Art. 11 allow hospitals to process health data without consent for AI training?
- A: Yes — but only if strictly necessary for healthcare provision (LGPD Art. 7, IV) or public health actions (Art. 7, V), with documented necessity assessment and no viable non-sensitive alternative. Consent remains required for non-essential uses (e.g., research not tied to care).
- Q: Is CFM Resolution 2,314/2022 legally enforceable?
- A: Yes. Per Law No. 3,268/1957 and CFM Statute Art. 1°, CFM resolutions carry binding force over physicians’ conduct; violations may lead to censure, suspension, or license revocation.
- Q: Must hospitals conduct a DPIA for every AI tool deployed?
- A: Yes — per LGPD Art. 37, DPIAs are mandatory for processing sensitive data at scale, including AI-driven EHR analysis, predictive modeling, or telemedicine platforms. CFM Art. 9 reinforces this requirement.
- Q: Can third-party AI vendors assume CFM compliance responsibility?
- A: No. CFM Art. 12 places sole ethical responsibility on the physician and institution. Contracts with vendors must include audit rights and liability clauses, but do not transfer CFM accountability.
Fatos-chave
- CFM Resolution No. 2,314/2022 entered force on 18 October 2022.
- LGPD Art. 11 has applied since 18 September 2020 (Decree No. 10,474/2020).
- Health data processing without a valid legal basis under LGPD Art. 11 may incur fines up to 2% of Brazilian revenue (LGPD Art. 52).
- CFM requires annual revalidation of AI clinical support tools (Art. 7, §3°).
- ANPD’s Guidance Note No. 01/2023 explicitly cites CFM Resolution 2,314/2022 as a sectoral standard for health-sector LGPD compliance.
Fontes
- Conselho Federal de Medicina. Resolução CFM nº 2.314/2022. https://www.portal.cfm.org.br/resolucoes-cfm/
- Lei Geral de Proteção de Dados (LGPD) – Lei nº 13.709/2018. https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm
- ANPD. Nota Técnica nº 01/2023 – Tratamento de Dados Pessoais na Área da Saúde. https://www.anpd.gov.br
- CFM. Relatório de Auditoria sobre Uso de IA em Serviços de Saúde – 2023. https://www.portal.cfm.org.br/publicacoes/relatorios/
- RAGJur. Acórdão nº 2023-001245/ANPD – Sanção por tratamento indevido de dados sensíveis em hospital paulista.
Saiba mais em https://g.cloud