<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article">
  <front>
    <journal-meta>
      <journal-id journal-id-type="nlm-ta">REA Press</journal-id>
      <journal-id journal-id-type="publisher-id">null</journal-id>
      <journal-title>REA Press</journal-title><issn pub-type="ppub">3042-1306</issn><issn pub-type="epub">3042-1306</issn><publisher>
      	<publisher-name>REA Press</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">https://doi.org/10.22105/thi.v3i1.46</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group><subject>Medical tourism, Data privacy, Cross-border health information exchange, Legal and regulatory challenges, Emerging technologies</subject></subj-group>
      </article-categories>
      <title-group>
        <article-title>Privacy and data security in medical tourism: A systematic review of health information exchange risks, legal and regulatory challenges, and technology-based solutions</article-title><subtitle>Privacy and data security in medical tourism: A systematic review of health information exchange risks, legal and regulatory challenges, and technology-based solutions</subtitle></title-group>
      <contrib-group><contrib contrib-type="author">
	<name name-style="western">
	<surname> Shabnani Nejad</surname>
		<given-names>Esmail</given-names>
	</name>
	<aff>Department of Management, University of Tehran, Tehran, Iran.</aff>
	</contrib><contrib contrib-type="author">
	<name name-style="western">
	<surname>Laleh</surname>
		<given-names>Nastaran </given-names>
	</name>
	<aff>Department of Tourism, University of Mazyar, Royan, Iran.</aff>
	</contrib></contrib-group>		
      <pub-date pub-type="ppub">
        <month>03</month>
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>14</day>
        <month>03</month>
        <year>2026</year>
      </pub-date>
      <volume>3</volume>
      <issue>1</issue>
      <permissions>
        <copyright-statement>© 2026 REA Press</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access" xlink:href="http://creativecommons.org/licenses/by/2.5/"><p>This is an open-access article distributed under the terms of the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</p></license>
      </permissions>
      <related-article related-article-type="companion" vol="2" page="e235" id="RA1" ext-link-type="pmc">
			<article-title>Privacy and data security in medical tourism: A systematic review of health information exchange risks, legal and regulatory challenges, and technology-based solutions</article-title>
      </related-article>
	  <abstract abstract-type="toc">
		<p>
			Medical tourism, a rapidly expanding industry with an annual market value exceeding $400 billion, has developed on an inadequate foundation of health data protection infrastructure. The cross-border exchange of clinical information exposes patient privacy to multiple security and regulatory risks that remain inadequately addressed. This systematic review aimed to identify and analyze security and privacy risks, legal and regulatory challenges, and technology-based solutions for protecting health data in medical tourism contexts. A systematic review following Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) 2020 guidelines was conducted through systematic searches across five major databases, Scopus, Web of Science, PubMed, ScienceDirect, and Google Scholar, for peer-reviewed articles published between 2015 and 2025. Inclusion criteria encompassed peer-reviewed English-language studies addressing medical tourism, health data security, and protective technologies. Of 1,247 articles initially identified, 52 studies were selected for analysis. Two independent reviewers conducted quality assessments using thematic analysis to extract relevant data. The findings revealed that the most prevalent security risks included data breaches (80.8% of studies), unauthorized access (73.1%), and cyberattacks (78.8%), with average breach costs ranging from $408,000 to $600,000 per incident. Major legal and regulatory challenges identified included heterogeneous data protection laws across jurisdictions (92.3% of studies), undefined jurisdictional authority (80.8%), restricted cross-border data transfer (84.6%), and inadequate informed consent procedures (75.0%). Identified technology-based solutions encompassed advanced encryption (67.3%), Artificial Intelligence (AI) (42.3%), secure cloud computing (48.1%), blockchain (34.6%), digital identity management (36.5%), and Zero Trust architecture (26.9%). However, no single technology provides a complete solution; effective implementation requires an integrated combination of technological, organizational, and legal measures. This review demonstrates that protecting privacy and security of health data in medical tourism represents a multidimensional challenge requiring a comprehensive and balanced approach. Narrowing international legal gaps, enhancing patient consent procedures, and establishing coordinated agreements are essential for building trust and ensuring industry sustainability.  
		</p>
		</abstract>
    </article-meta>
  </front>
  <body></body>
  <back>
    <ack>
      <p>null</p>
    </ack>
  </back>
</article>