A hospital visit can leave medical records, test results, and National Health Insurance claims records. If the same person also joins a biobank, they may provide specimens and health information. These records concern one person, but they were created for different purposes. The fact that they can be linked does not automatically give them the same permissions for use.

Pages 355–361 of the 2026 Biotechnology Industry White Paper discuss the integration of NHI data, biobanks, and medical data. When reading these plans, I begin with a question: what did the person agree to when they first provided the data?

If a developer discovers only near the end of a product that the permitted scope of data use does not include the intended purpose, earlier investment may have to be redone. If participants are told only that their data will “advance medical development,” they have little way to know where their records will actually go.

The National Health Insurance Administration explains that NHI data are collected mainly through claims for medical expenses. Participation in a biobank involves a separate set of notices, consents, and governance arrangements. Putting both under the label “health big data” can omit why a person originally provided the data and which conditions subsequent use must meet. NHIA explanation of data use

Likewise, a hospital’s possession of medical records does not mean that every collaborator may take those records away to train a product. A collaboration should first identify the data source, research purpose, and basis of access, then determine the applicable review and protection requirements. Different cases can rest on different grounds; one collaboration cannot substitute for the judgment required in the next.

If a data provider assumes the data are for one study while a developer assumes they can be extended to every product, the parties may be making different plans even after their collaboration has begun.

What changes after opting out?

The NHIA currently provides an application mechanism to stop use of NHI data beyond the original collection purpose (secondary use). Under its explanation updated in August 2026, once an application takes effect, the relevant data are no longer provided for new use applications. The opt-out is not retroactive; data already authorized before it takes effect may continue to be used. NHIA explanation of stopping secondary use

This “opt-out” concerns a defined scope of data use. It does not mean deleting hospital medical records or leaving the NHI system. If a service interface offers a single switch without explaining the effective date, scope, and treatment of existing use, people may make a choice without knowing what that choice changes.

Biobanks have their own arrangements. Article 8 of Taiwan’s Human Biobank Management Act addresses discontinuation of provision, withdrawal from participation, and changes to the scope of consent. How previously obtained specimens and data are handled must be determined under the Act and its exceptions. The NHI-data opt-out procedure cannot simply be applied to a biobank, nor can one guarantee that every form of withdrawal will retrieve all research results already produced. TFDA legal compilation, printed p. 85, Article 8

At a minimum, an explanation of withdrawal should tell people what use will stop if they change their mind today and what can no longer be retrieved. That is harder to design than a single “I agree” checkbox, and deserves serious attention.

How research proceeds while data remain in place

Page 361 of the White Paper proposes a trusted research environment, or TRE. The approach includes allowing data to be analysed in a controlled environment, with access and security controls that reduce the risk of data being taken out for arbitrary use. It is a governance direction, not evidence that every data platform already has the same capability.

Whether a data file can be downloaded is easy to see. Less visible are login permissions, activity records, and whether analytical results can leave the environment. Turning off downloads alone does not resolve these issues.

Researchers need tools to perform analysis; administrators need to know who did what. How outputs are reviewed, and whom to approach for renewed confirmation if a research purpose changes, should be agreed before access is opened.

De-identification also has to be understood in a specific context. Removing names is one treatment. Whether linkage with other data increases the risk of identification requires a separate assessment. “De-identified” does not remove the need to assess risk in subsequent use.

After the formats connect

FHIR is a standard for exchanging healthcare information. It provides data structures that systems can exchange and understand, giving different software a common way to communicate. Standardization can improve exchange, but a record in FHIR format does not authorize anyone to obtain or use it. HL7 FHIR overview

Page 362 of the White Paper records progress in some hospitals’ adoption of FHIR tools for extracting electronic medical records. Page 364 sets a goal of 100 percent interoperability of medical-center data. Some adoption has occurred; overall interoperability remains a goal.

Even when data can be exchanged smoothly, researchers still need to understand what each field represents, how missing values arose, and whether record-keeping practices at different hospitals affect comparison. Converting the format and obtaining data that can answer a research question are related but distinct tasks.

Some differences can only be explained by the people who made the records. Clinicians know why a test was done at a particular time; information staff know how a field was generated. A researcher who receives a file may no longer have the chance to ask. Cross-hospital collaboration needs room for these conversations.

That is one reason data collaboration takes time. The earlier a team clarifies the proposed use, review requirements, and later use of outputs, the better it can judge how much to invest. Participants need a different explanation: which studies their data supported, whom to contact if something goes wrong, and whether their choice took effect.

A data platform may let researchers find files quickly while leaving people unable to find where to exercise their choices. The collaboration still lacks something. It is difficult to express that part as a record count, but it will affect whether people are willing to provide data again.


Sources: 2026 Biotechnology Industry White Paper, Industrial Development Administration, Ministry of Economic Affairs, August 2026, printed pp. 355–364. Legal requirements and mechanisms follow the competent authorities’ sources linked in the text; the arrangements for projects and conditions of trust are the author’s analysis.

Data, permission and use are separate questions
  1. Where did the data come from?

    Medical records, NHI claims and biobanks serve different original purposes.

  2. What uses are permitted?

    Establish the research purpose, the basis for access and participants’ choices.

  3. How is use managed?

    Define access controls, activity records and management of research outputs.

A guide to the questions raised in this article. Interoperable formats do not extend permission; the effect of withdrawal depends on the applicable system.