Skip to content
Preprint

Protecting patient privacy in clinical foundation models: Technical and legal perspectives

Aug 2026 · 0 citations · 76 references
Computer Science

TL;DR

This work proposes a practical framework for assessing privacy risk in clinical foundation models and illustrates realistic leakage scenarios across deployment settings, map them to legal regimes, and outline complementary technical and legal mitigations.

Abstract

Clinical foundation models trained on large-scale patient data are increasingly used for decision support, screening, and public health. As deployment expands, privacy risk increasingly arises from model-mediated leakage, yet its prevalence and severity remain poorly quantified. Models can disclose sensitive training artifacts, enabling patient re-identification in ways not captured by data-handling controls alone. Existing frameworks, including HIPAA and GDPR, offer limited guidance for such indirect threats. We propose a practical framework for assessing privacy risk in clinical foundation models and illustrate realistic leakage scenarios across deployment settings, map them to legal regimes, and outline complementary technical and legal mitigations. Our analysis provides a context-aware risk assessment grounded in realistic usage to preserve the value of medical foundation models while rigorously safeguarding patient privacy.

View source

Similar papers

FAIR and Square: Privacy Compliance Framework for Healthcare Databases

Initial evaluations using various machine-learning algorithms on pre-and post-generalized datasets demonstrate the privacy framework’s effectiveness in mitigating privacy risks while preserving data usability.

Ze-Yang Zhu, Matthias N. Louws, Roland V. Bumbuc et al. · 0 citations
Open access Aug 2026

Privacy-Enhancing Technologies and Privacy-By-Design for Medical AI

This paper examines how privacy-enhancing technologies such as synthetic data, federated learning and ‘Secure Data Environments’ can be integrated into artificial intelligence ( AI ) development processes to uphold key data protection principles in the UK GDPR , like storage limitation, data minimisation, purpose limitation, security, and fairness. The analysis highlights how privacy-enhancing technologies offer benefits beyond anonymisation by embedding privacy-by-design values to support responsible innovation and protect sensitive patient data throughout the design, training, and validation of medical AI systems. The paper uses the 2015 DeepMind and Royal Free case as a practical study to realise the practical and legal benefits of privacy-enhancing technologies in medical AI development, particularly involving public-private collaborations. While grounded in the UK context, the findings have broader relevance to the European Union and other international jurisdictions grappling with tensions between data protection and AI development in the healthcare context.

Yasmine Zoya · 0 citations
Aug 2026

Scalable privacy risk assessment of medical data processed by large language models

This paper empirically evaluates ChatGPT 3.5 and 4.0 using over 23,000 real user-generated medical queries, assessing their susceptibility to privacy breaches through quasi-identifiers such as age, location, phone number and national registration number and proposes a scalable privacy evaluation model that combines k-anonymity, l-diversity, t-closeness, entropy, re-identification risk and delta-disclosure.

Foad Jalali, Mehran Alidoost Nia · 0 citations
Jul 2026

Beyond HIPAA: The FTC’s Expanding Role in Digital Health Privacy Enforcement

Consumer digital health platforms have become an increasingly prominent feature of modern health care, collecting and storing sensitive health information directly from users. Yet most of these applications operate outside the scope of the Health Insurance Portability and Accountability Act (HIPAA), creating a significant regulatory gap in the protection of personal health data. This case note examines how the Federal Trade Commission (FTC) has stepped into that gap by leveraging Section 5 of the FTC Act and the Health Breach Notification Rule (HBNR) to police privacy and data security practices among non-HIPAA-covered digital health platforms. Focusing on three landmark enforcement actions against Flo Health, GoodRx, and BetterHelp, the paper analyzes how the FTC has applied longstanding consumer protection principles to emerging health technologies and expanded its role in governing digital health privacy. It further explores the broader implications of these actions for digital health companies, consumers, and advertisers, highlighting the FTC’s increasingly expansive interpretation of sensitive health information and its emphasis on transparency, accountability, and third-party oversight.

Sandhya Srinivasa · 0 citations
Open access Jul 2026

Privacy-Enhancing Technologies: Unlocking Responsible Cross-Border Data Research

International data transfer rules, designed to protect individuals, often create barriers to collaborative research by imposing constraints misaligned with modern data ecosystems. Frameworks like GDPR and UK GDPR can unintentionally hinder scientific progress by failing to recognise the safeguards provided by emerging technologies. More nuanced legal approaches are needed to preserve privacy while enabling responsible international research. We will examine how privacy-enhancing technologies (PETs) can help address these challenges. Informed by insights from pilot projects under the Alzheimer’s Disease Data Initiative which seek to address critical dementia questions, while expanding dataset access. With dementia cases projected to rise globally from 57 million to 153 million by 2050, this work demonstrates the urgent need for cross-border data sharing in brain health research. Specifically, we will explore how PETs offer pathways through regulatory barriers, and how Trusted Research Environments (TREs), aligned with the Five Safes Framework, provide strong safeguards to prevent identifiable data disclosure. We will demonstrate how remote querying techniques enable international analysis without data transfers, as researchers receive only aggregate results. The presentation will address persistent challenges: under European Data Protection Board guidance, even viewing data across borders constitutes a transfer, meaning TRE access may trigger complex compliance requirements despite technical safeguards. We will explore the rapidly evolving landscape through new UK legislation, the European Health Data Space, and emerging case law. Finally, we will discuss whether PETs can bridge the gap between privacy protection and scientific progress, and what regulatory adaptations are required to recognise the protections they provide.

Edel McNamara, Cassie Smith, Neil Postlethwaite et al. · 0 citations