Corvus Medical Press
JMIDH

Research Ethics for Health Data & Digital Health Studies

All research published in JMIDH must meet international ethical standards and the laws of the country in which it was conducted.

Ethics approval

•     Research involving human participants or their identifiable data — including retrospective analyses of electronic health records, images, clinical notes, device data and app data — requires approval from a registered institutional ethics committee before the research begins, or a formal exemption issued by that committee. The authors’ own view that approval is unnecessary is not accepted.

•     Research must comply with the Declaration of Helsinki (current revision). Research in India must follow the ICMR National Ethical Guidelines for Biomedical and Health Research Involving Human Participants (2017) and the ICMR Ethical Guidelines for Application of Artificial Intelligence in Biomedical Research and Healthcare (2023). Trials of software as a medical device must also meet the Medical Devices Rules, 2017 where applicable. Research elsewhere must follow national rules.

•     State the committee name, approval number and date in the Methods (blinded for review) and the declarations.

•     Analyses of fully de-identified public datasets with their own approvals (for example MIMIC or national survey data) may not need new approval; authors must name the dataset, confirm they followed its data use agreement, and cite its original ethics approval.

Consent

Prospective studies, usability studies, surveys and trials of digital interventions require informed consent from participants, including electronic consent where approved. Consent must explain what data are collected, how they are stored and shared, and any use for training AI models. For retrospective studies of routinely collected data, the ethics committee may waive consent; the waiver and its reason must be stated. Children and adults lacking capacity need consent from a parent, guardian or legally authorised representative.

Data protection

Studies must comply with data protection law, including India’s Digital Personal Data Protection Act, 2023, and, where applicable, the EU General Data Protection Regulation and the US HIPAA Privacy Rule. The Methods should describe where data were stored and processed, who had access, and how data were de-identified. Transferring identifiable patient data to external cloud services or commercial AI tools requires explicit approval and appropriate agreements.

Fairness, safety and responsible AI

Authors developing or evaluating AI systems should assess and report performance across relevant population subgroups, describe known risks and failure modes, and state whether the tool is intended for research only or for clinical use. Studies that deploy AI tools to influence patient care must have ethics approval, monitoring for harm and a plan to switch off or correct the tool if problems arise. The regulatory status of any tool used in care (for example, CDSCO, FDA or CE approval) should be stated.

Online communities and social media data

Research using data from online forums, social media or patient communities must consider users’ expectations of privacy, avoid quoting posts in ways that allow users to be traced through search engines, and have ethics review appropriate to the data used.

Verification

Editors may request approval letters, consent documents, data use agreements and protocols at any stage. Manuscripts without adequate approval will be rejected, and published articles may be retracted.