Shared Medical Records with AI Developers Without Consent? Petition Against Privacy Law Loophole Tops 30,000 Signatures

From our other sites

The story

Under a special provision of Japan’s revised Personal Information Protection Act, sensitive data such as medical history can now be shared without the individual’s consent, provided the purpose is AI development or statistical research. In response, an online petition calling for operational safeguards has gathered more than 30,000 signatures.

On 5channel, opinions split over whether data is really being handed over complete with names and addresses, and just how thoroughly it’s actually anonymized. Posts citing Diet testimony — in which Chief Cabinet Secretary Kihara and Minister Matsumoto reportedly said that stripping out personally identifiable information is “difficult in practice” — fueled growing unease about what this law change really means on the ground.

“My information, shared without my knowledge…” The woman behind the petition calling for “operational safeguards” on the revised Personal Information Protection Act’s special provision: Tokyo Shimbun Digital

August 18, 2026, 06:00 — Article for paid subscribers only

An online petition calling for operational safeguards on the revised Personal Information Protection Act’s special provision — which allows sensitive information such as medical history to be shared without the individual’s consent for the purposes of AI development or statistical research — has gathered more than 30,000 signatures.

Source: tokyo-np.co.jp / Original article here

What people said

8AnonymousAug 18, 2026 09:04
Apps like LINE have been leaking all kinds of our data for ages, why act shocked now?
If something's free, there's a reason.
35AnonymousAug 18, 2026 09:15
Re: #8
Unlike your average, not-too-careful LINE user, the people speaking up this time — folks who go to the hospital a lot — might just be the type who sweats the details.
15AnonymousAug 18, 2026 09:09
It's not like anyone can actually be identified from it though, right?
Is that ambiguity itself the thing people are pushing back against?
45AnonymousAug 18, 2026 09:18
Re: #15
No, it's handed over complete with address and name attached.
Akira Nagatsuma raised this in the Diet, and Kihara admitted that removing that info isn't technically feasible.
18AnonymousAug 18, 2026 09:10
No, it's fine since personally identifiable info gets stripped out first.
Big-data analysis might surface side effects that clinical trials never caught — like "people who take this drug tend to get this reaction."
23AnonymousAug 18, 2026 09:12
Re: #18
I saw in the news that names get handed over in the data as-is, unredacted.
36AnonymousAug 18, 2026 09:15
Re: #18
You really think that rule actually gets followed?
Way too naive.
48AnonymousAug 18, 2026 09:19
Re: #18
Even if it's handed over in a state that's just barely non-identifiable, it can still be pieced together like a jigsaw puzzle with data from past leaks to reconstruct the full picture.
And it's the people with the least "value" who are easiest to exploit for crime.
26AnonymousAug 18, 2026 09:13
More than that —
isn't it terrifying that raw personal data of every kind ends up piled up at specific companies?
Nobody's watching what they actually do with it internally lol
33AnonymousAug 18, 2026 09:15
Re: #26
Seriously, this.
There are already plenty of sketchy companies as it is.
39AnonymousAug 18, 2026 09:16
Re: #26
Isn't it fine as long as it's not illegal?
34AnonymousAug 18, 2026 09:15
Re: #23
Is that actually true?
Standard practice is to "sanitize" (strip out personally identifiable info) before turning data into big data.
54AnonymousAug 18, 2026 09:20
Re: #34
Also, the information handed over isn't the final "statistical data" itself — at the stage where raw data moves from the source to the recipient, it may still contain names and addresses. Processing it into a non-identifiable form only happens at the final output stage.

And yet vetting of the recipient organizations is lax, basically running on the honor system.
80AnonymousAug 18, 2026 09:25
Re: #34
In Diet questioning, Chief Cabinet Secretary Kihara said it's not feasible to strip out personally identifiable info like address and name.
90AnonymousAug 18, 2026 09:27
What actual harm comes from handing over someone's hospital visit history?
95AnonymousAug 18, 2026 09:28
Re: #90
Well, if you're a woman, having a gynecological condition exposed would be pretty embarrassing.
105AnonymousAug 18, 2026 09:30
Re: #90
Insurance could shift away from uniform premiums based on the law of large numbers
toward extreme risk-segmentation at the individual level.

AI could also end up taking over the role background-check agencies play in employment and marriage discrimination.
104AnonymousAug 18, 2026 09:30
Re: #92
No, I don't think that's really the main purpose — there's no real use value in the names themselves.
The point of big data is analyzing relationships/correlations,
so if names are used at all it's probably just to avoid duplicate entries. They should just swap it for some other identifier so individuals can't be identified.
112AnonymousAug 18, 2026 09:31
Re: #104
Real names aren't necessary for big data.
So the fact that they stubbornly refuse to strip real names out means that's exactly where the real purpose lies.
126AnonymousAug 18, 2026 09:34
Re: #112
What exactly do you mean by "that"? What kind of personal-data use are you imagining?
Big data's main purpose is trend analysis —
like "taking this drug causes this side effect,"
or whether there's regional variation in disease based on address.
Names are probably just there to avoid double-counting duplicate entries, so a number or code would work just as well.
130AnonymousAug 18, 2026 09:35
Re: #126
The standing principle up to now has been "remove real names."
This time it's a special exception making "real names OK."

Do you not get that basic premise?
146AnonymousAug 18, 2026 09:37
Re: #126
According to Minister Matsumoto,
removing names isn't feasible because it would place too much burden on the hospitals holding the data.
148AnonymousAug 18, 2026 09:37
Do people even realize this is supposed to be anonymized data?
Wait, it is anonymous… right? Hard to believe, but still.
172AnonymousAug 18, 2026 09:41
Re: #148
It's all "without the individual's consent," so it's probably handed over completely raw, everything included.
187AnonymousAug 18, 2026 09:43
Re: #148
This law change literally says "you don't have to anonymize it."
196AnonymousAug 18, 2026 09:45
Re: #148
Re: #1
It's right there in the article — it says the data is handed over with real names attached.

Background and Key Points

Sensitive personal information under Japan’s Personal Information Protection Act (個人情報保護法) has always required consent before sharing with third parties, with medical history classed as “special care-required” data given extra weight since Japan lacks the sector-specific health-privacy statute that, say, HIPAA provides in the US. The 2026 revision carves out an exception: hospitals and insurers can pass such records to AI developers or statistical researchers without asking the patient, on the premise the data will be anonymized first. The petition responds to testimony in the Diet — Japan’s national legislature — where Chief Cabinet Secretary Kihara and a minister named Matsumoto both said, under questioning from opposition lawmaker Akira Nagatsuma, that stripping identifying information before handoff is “difficult in practice.”

The thread’s actual fault line isn’t whether the law permits sharing without consent — that’s undisputed — but whether “anonymized” describes the data at the point it changes hands. Some posters insisted stripping happens before any transfer; others, citing the same Diet exchange, argued raw data with names and addresses moves first and de-identification, if it happens, comes only at the final statistical-output stage, with little vetting of who receives it in between.

What the thread never engages with is why names get retained at all: several posters guessed it’s to prevent duplicate patient records across data sources, which is a real technical constraint in de-identification pipelines, not evidence of an ulterior motive. Readers should also know Japan’s health system is near-universal single-payer insurance, so this data pool implicates virtually the entire population, not an opt-in subset — raising the stakes of any anonymization gap well beyond what a Western reader used to fragmented, employer-based insurance records might assume.

*This article is compiled as an excerpt and summary of the 5channel (Breaking News Plus) thread ““Don’t hand over our medical histories to AI developers without asking” — the woman behind the petition calling for “operational safeguards” on the revised Personal Information Protection Act’s special provision.”

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *