Privacy and data security in medical tourism: A systematic review of health information exchange risks, legal and regulatory challenges, and technology-based solutions

Authors

  • Esmail Shabnani Nejad * Department of Management, University of Tehran, Tehran, Iran.
  • Nastaran Laleh Department of Tourism, University of Mazyar, Royan, Iran.

https://doi.org/10.22105/thi.v3i1.46

Abstract

Medical tourism, a rapidly expanding industry with an annual market value exceeding $400 billion, has developed on an inadequate foundation of health data protection infrastructure. The cross-border exchange of clinical information exposes patient privacy to multiple security and regulatory risks that remain inadequately addressed. This systematic review aimed to identify and analyze security and privacy risks, legal and regulatory challenges, and technology-based solutions for protecting health data in medical tourism contexts. A systematic review following Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) 2020 guidelines was conducted through systematic searches across five major databases, Scopus, Web of Science, PubMed, ScienceDirect, and Google Scholar, for peer-reviewed articles published between 2015 and 2025. Inclusion criteria encompassed peer-reviewed English-language studies addressing medical tourism, health data security, and protective technologies. Of 1,247 articles initially identified, 52 studies were selected for analysis. Two independent reviewers conducted quality assessments using thematic analysis to extract relevant data. The findings revealed that the most prevalent security risks included data breaches (80.8% of studies), unauthorized access (73.1%), and cyberattacks (78.8%), with average breach costs ranging from $408,000 to $600,000 per incident. Major legal and regulatory challenges identified included heterogeneous data protection laws across jurisdictions (92.3% of studies), undefined jurisdictional authority (80.8%), restricted cross-border data transfer (84.6%), and inadequate informed consent procedures (75.0%). Identified technology-based solutions encompassed advanced encryption (67.3%), Artificial Intelligence (AI) (42.3%), secure cloud computing (48.1%), blockchain (34.6%), digital identity management (36.5%), and Zero Trust architecture (26.9%). However, no single technology provides a complete solution; effective implementation requires an integrated combination of technological, organizational, and legal measures. This review demonstrates that protecting privacy and security of health data in medical tourism represents a multidimensional challenge requiring a comprehensive and balanced approach. Narrowing international legal gaps, enhancing patient consent procedures, and establishing coordinated agreements are essential for building trust and ensuring industry sustainability.     

Keywords:

Medical tourism, Data privacy, Cross-border health information exchange, Legal and regulatory challenges, Emerging technologies

References

  1. [1] Bookman, M. (2007). Medical tourism in developing countries. Palgrave Macmillan New York. https://doi.org/10.1057/9780230605657

  2. [2] Hall, C. M. (2011). Health and medical tourism: A kill or cure for global public health? Tourism Review, 66(1–2), 4–15. https://doi.org/10.1108/16605371111127198

  3. [3] Connell, J. (2013). Contemporary medical tourism: Conceptualisation, culture and commodification. Tourism Management, 34, 1–13. https://doi.org/10.1016/j.tourman.2012.05.009

  4. [4] Whittaker, R., McRobbie, H., Bullen, C., Rodgers, A., & Gu, Y. (2016). Mobile phone‐based interventions for smoking cessation. Cochrane Database of Systematic Reviews, (4). https://doi.org/10.1002/14651858.CD006611.pub4

  5. [5] Payne, T. H. (2016). The electronic health record as a catalyst for quality improvement in patient care. Heart, 102(22), 1782–1787. https://doi.org/10.1136/heartjnl-2015-308724

  6. [6] Levett-Jones, T., Hoffman, K., Dempsey, J., Jeong, S. Y. S., Noble, D., Norton, C. A., ... & Hickey, N. (2010). The ‘five rights’ of clinical reasoning: An educational model to enhance nursing students’ ability to identify and manage clinically ‘at risk’patients. Nurse Education Today, 30(6), 515–520. https://doi.org/10.1016/j.nedt.2009.10.020

  7. [7] Beauchamp, V. B., & Shafroth, P. B. (2011). Floristic composition, beta diversity, and nestedness of reference sites for restoration of xeroriparian areas. Ecological Applications, 21(2), 465–476. https://doi.org/10.1890/09-1638.1

  8. [8] U.S. Department of Health and Human Services, O. for C. R. (2023). Annual report to Congress on breaches of unsecured protected health information for calendar year 2023. https://www.hhs.gov/sites/default/files/breach-report-to-congress-2023.pdf?utm_source=chatgpt.com

  9. [9] Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1–10. https://doi.org/10.3233/THC-161263

  10. [10] Kshetri, N., & Loukoianova, E. (2019). Blockchain adoption in supply chain networks in Asia. IT professional, 21(1), 11–15. https://doi.org/10.1109/MITP.2018.2881307

  11. [11] Ryngaert, C., & Taylor, M. (2020). The GDPR as global data protection regulation? American Journal of international Law Unbound, 114, 5–9. https://doi.org/10.1017/aju.2019.80

  12. [12] Viergever, R. F., Karam, G., Reis, A., & Ghersi, D. (2014). The quality of registration of clinical trials: Still a problem. PloS One, 9(1), e84727. https://doi.org/10.1371/journal.pone.0084727

  13. [13] Ekblaw, A., Azaria, A., Halamka, J. D., & Lippman, A. (2016). A case study for blockchain in healthcare:“medrec” prototype for electronic health records and medical research data [presentation]. Proceedings of ieee open & big data conference (vol. 13, no. 13). https://www.media.mit.edu/publications/medrec-whitepaper/

  14. [14] Cisco. (2020). Zero trust security: Never trust, always verify. Cisco Systems. https://www.cisco.com/c/en/us/products/security/zero-trust.html

  15. [15] Hall, C. M., & Ram, Y. (2020). Protecting privacy in tourism–A perspective article. Tourism Review, 75(1), 76–80. https://doi.org/10.1108/TR-09-2019-0398

  16. [16] Horowitz, M. D., Rosensweig, J. A., & Jones, C. A. (2007). Medical tourism: Globalization of the healthcare marketplace. Medscape General Medicine, 9(4), 33. https://pmc.ncbi.nlm.nih.gov/articles/PMC2234298/

  17. [17] Crooks, V. A., Kingsbury, P., Snyder, J., & Johnston, R. (2010). What is known about the patient’s experience of medical tourism? A scoping review. BMC Health Services Research, 10(1), 266. https://doi.org/10.1186/1472-6963-10-266

  18. [18] Insights, Global Market. (2016). Medical tourism market size by treatment (cosmetic treatment, dental treatment, cardiovascular treatment, orthopedic treatment, fertility treatment), by region and forecast, 2016–2025. https://www.gminsights.com/industry-analysis/medical-tourism-market?utm_source=chatgpt.com

  19. [19] Office of the National Coordinator for Health Information Technology. (2016). Connecting health and care for the nation: A shared nationwide interoperability roadmap. https://healthit.gov/topic/interoperability/connecting-health-and-care-nation-interoperability-roadmap?utm_source=chatgpt.com

  20. [20] Detsky, A. S., Gauthier, S. R., & Fuchs, V. R. (2012). Specialization in medicine: How much is appropriate? Jama, 307(5), 463–464. https://doi.org/10.1001/jama.2012.44

  21. [21] Vest, J. R., & Gamm, L. D. (2010). Health information exchange: Persistent challenges and new strategies. Journal of the American Medical Informatics Association: JAMIA, 17(3), 288. https://pmc.ncbi.nlm.nih.gov/articles/PMC2995716/

  22. [22] Westin, A. F. (1967). Privacy and freedom Atheneum. Atheneum. https://openlibrary.org/books/OL5537351M/Privacy_and_freedom?utm_source=chatgpt.com

  23. [23] Solove, D. J. (2006). A taxonomy of privacy. University of Pennsylvania Law Review, 154(3), 477–564. https://doi.org/10.2307/40041279

  24. [24] Katz, J. N. (2013). The three block model of universal design for learning (UDL): Engaging students in inclusive education. Canadian Journal of Education/Revue Canadienne De L’éducation, 36(1), 153–194. https://cje-rce.ca/index.php/cje-rce/article/view/1159

  25. [25] Abdelhamid, M., Gaia, J., & Sanders, G. L. (2017). Putting the focus back on the patient: How privacy concerns affect personal health information sharing intentions. Journal of Medical Internet Research, 19(9), e169. https://doi.org/10.2196/jmir.6877

  26. [26] Nurse, J. R., Creese, S., & De Roure, D. (2017). Security risk assessment in internet of things systems. IT Professional, 19(5), 20–26. https://doi.org/10.1109/MITP.2017.3680959

  27. [27] Cavoukian, A. (2012). Privacy implications of drones: Unmanned aerial vehicles in Canada. https://coilink.org/%0A20.500.12592/fbw15t

  28. [28] Cavoukian, A. (2012). Privacy by design: Origins, meaning, and prospects for assuring privacy and trust in the information era. In Privacy protection measures and technologies in business organizations: aspects and standards (pp. 170–208). IGI Global. https://doi.org/10.4018/978-1-61350-501-4.ch007

  29. [29] Heffner, J. L., Strawn, J. R., DelBello, M. P., Strakowski, S. M., & Anthenelli, R. M. (2011). The co‐occurrence of cigarette smoking and bipolar disorder: phenomenology and treatment considerations. Bipolar Disorders, 13((5‐6)), 439–453. https://doi.org/10.1111/j.1399-5618.2011.00943.x

  30. [30] Ichikawa, D., Kashiyama, M., & Ueno, T. (2017). Tamper-resistant mobile health using blockchain technology. JMIR Mhealth and Uhealth, 5(7), e7938. https://doi.org/10.2196/mhealth.7938

  31. [31] Rieke, N., Hancox, J., Li, W., Milletari, F., Roth, H. R., Albarqouni, S., ... & Cardoso, M. J. (2020). The future of digital health with federated learning. NPJ Digital Medicine, 3(1), 119. https://www.nature.com/articles/s41746-020-00323-1

  32. [32] Moher, D., Shamseer, L., Clarke, M., Ghersi, D., Liberati, A., Petticrew, M., ... & Prisma-P Group. (2015). Preferred reporting items for systematic review and meta-analysis protocols (PRISMA-P) 2015 statement. Systematic Reviews, 4(1), 1. https://doi.org/10.1186/2046-4053-4-1

  33. [33] Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., ... & Moher, D. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. The bmj, 372:n71. https://doi.org/10.1136/bmj.n71

  34. [34] Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Research in Psychology, 3(2), 77–101. https://doi.org/10.1191/1478088706qp063oa

  35. [35] Carrera, P., & Lunt, N. (2010). A European perspective on medical tourism: the need for a knowledge base. International Journal of Health Services, 40(3), 469–484. https://doi.org/10.2190/HS.40.3.e

  36. [36] Institute, P. (2019). Cost of a data breach report 2019. https://insights.integrity360.com/hubfs/2019-cost-of-a-data-breach-report-04_03025203USEN.pdf?utm_source=chatgpt.com

  37. [37] Federal Bureau of Investigation, Internet Crime Complaint Center. (2023). Internet crime report 2023. https://www.ic3.gov/AnnualReport/Reports/2023_IC3Report.pdf?utm_source=chatgpt.com

Published

2026-03-14

How to Cite

Shabnani Nejad, E., & Laleh, N. . (2026). Privacy and data security in medical tourism: A systematic review of health information exchange risks, legal and regulatory challenges, and technology-based solutions. Trends in Health Informatics, 3(1), 51-73. https://doi.org/10.22105/thi.v3i1.46