Short answer
A guardrail in telemedicine refers to a technical and procedural safeguard—mandated by the Conselho Federal de Medicina (CFM)—that ensures remote clinical interactions comply with ethical, legal, and safety standards, including identity verification, data encryption, and scope-of-practice boundaries. It is not a standalone law but an operational requirement embedded in CFM Resolution No. 2.282/2021 and reinforced by Resolution No. 2.314/2023.
TL;DR
- CFM Resolution No. 2.282/2021 establishes telemedicine as a legitimate medical practice only when conducted under defined guardrails.
- Guardrails require real-time audiovisual interaction for initial consultations (with narrow exceptions for follow-ups).
- Physicians must verify patient identity, confirm location, and document consent before each teleconsultation.
- Data transmission must use end-to-end encryption compliant with Brazilian data protection standards (LGPD Art. 46).
- CFM explicitly prohibits AI-only diagnostic outputs without physician review and attribution (Res. 2.314/2023, §2º, Art. 11).
- Violations may trigger CFM disciplinary proceedings—including suspension of telepractice authorization.
O que é um guardrail em telemedicina?
A guardrail in telemedicine is a mandatory control mechanism—not a technology product—that enforces compliance at critical decision points. Per CFM Resolution No. 2.282/2021 (Art. 5º), it comprises verifiable procedural checks: confirming patient identity via government-issued ID, validating geographic location for jurisdictional alignment with state medical councils, ensuring informed consent is documented before consultation, and restricting platform use to systems that guarantee encrypted, non-storage transmission of health data. These are non-delegable responsibilities of the physician—not the platform vendor.
Quais são os guardrails obrigatórios segundo o CFM?
CFM mandates four core guardrails: (1) Identity & location validation: Must occur pre-consultation using official documents and geolocation metadata; (2) Consent protocol: Specific written or digital consent covering limitations of telemedicine, data handling, and emergency escalation paths; (3) Scope boundary enforcement: Initial diagnosis and prescription of controlled substances (RDC 358/2023) require in-person evaluation unless expressly exempted (e.g., mental health follow-up under Res. 2.314/2023); (4) Human-in-the-loop requirement: All clinical conclusions derived from algorithmic support must be reviewed, interpreted, and signed off by a licensed physician (CFM Res. 2.314/2023, Art. 11).
Como os guardrails se relacionam com a LGPD e a RDC 358/2023?
CFM guardrails align with—but do not replace—LGPD obligations (Law No. 13,709/2018): encryption, data minimization, and purpose limitation are enforced through CFM’s procedural requirements. Meanwhile, ANVISA’s RDC No. 358/2023 on telehealth platforms references CFM resolutions as binding for clinical integrity. Platform providers must demonstrate audit logs proving guardrail execution (e.g., timestamped ID verification, consent capture, session encryption status)—not just system configuration.
FAQ
- Q: Is it permitted to use generative AI to draft clinical reports in telemedicine?
- A: Yes, provided that the physician reviews, validates, and signs the content in its entirety—without automatic attribution to the model (CFM Res. 2.314/2023, Art. 11).
- Q: Do guardrails apply only to text or audio message consultations?
- A: No. CFM Res. 2.282/2021 (Art. 4º) restricts asynchronous modalities to follow-ups only, and only when prior in-person contact exists. Initial consultations require synchronous audiovisual interaction.
- Q: Can a telemedicine system store recordings of consultations?
- A: No, except with explicit consent and end-to-end encryption—and even then, CFM requires deletion within 30 days unless legally mandated otherwise (Res. 2.282/2021, Art. 7º).
- Q: Who is responsible if a guardrail fails: the physician or the platform?
- A: The physician is always held accountable before the CFM (Res. 2.282/2021, Art. 12). Platform vendors bear civil liability under LGPD and CDC, but CFM sanctions apply solely to the physician’s conduct.
Key facts
- CFM Resolution No. 2.282/2021 entered force on 20 November 2021 and remains fully in effect.
- Resolution No. 2.314/2023 updated AI-related guardrails, effective 1 March 2023.
- “Guardrail” is not defined in statute but is the official CFM term used in official guidance documents (e.g., CFM Nota Técnica 03/2022).
- No federal law overrides CFM’s authority over medical practice standards (Federal Constitution Art. 22, §1º; Law No. 3.268/1957).
- State medical councils (CRM) enforce CFM guardrails locally and may impose stricter requirements.
Sources
- Conselho Federal de Medicina. Resolução CFM nº 2.282/2021. https://www.portal.cfm.org.br/index.php?option=com_content&view=article&id=30240
- Conselho Federal de Medicina. Resolução CFM nº 2.314/2023. https://www.portal.cfm.org.br/index.php?option=com_content&view=article&id=33292
- Agência Nacional de Vigilância Sanitária. RDC nº 358/2023. https://www.gov.br/anvisa/pt-br/centrais-de-conteudo/consultas-publicas/cp-358-2023
- Lei Geral de Proteção de Dados Pessoais (LGPD). Lei nº 13.709/2018. https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm
- RAGJur – Jurisprudência do CFM, Processo nº 1000258/2022.
Saiba mais em https://g.cloud