Advancing data protections for implantable brain-computer interfaces
摘要
Implantable brain-computer interfaces (iBCIs) are rapidly transitioning from proof-of-concept devices to early clinical application. The high-resolution neural signals they capture may yield insights beyond those derived from conventional health data. In this Review, we examine how clinical iBCI data remain insufficiently protected, despite existing privacy laws like the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR). Five core gaps are identified: overreliance on conventional de-identification, limited individual control and rights, conflated consent practices, limited guardrails against misuse, and underspecified ownership. We examine strategies to address these gaps, including protections for de-identified data, stronger iBCI data rights and control, separate data consent, limits on harmful secondary uses, and monetization guardrails. As iBCIs transition from research tools to real-world clinical practice, clinicians, researchers, developers, and regulators, in dialogue with prospective and current iBCI users, will play central roles in advancing patient autonomy and privacy.