Initial evaluations using various machine-learning algorithms on pre-and post-generalized datasets demonstrate the privacy framework’s effectiveness in mitigating privacy risks while preserving data usability.
This paper examines how privacy-enhancing technologies such as synthetic data, federated learning and ‘Secure Data Environments’ can be integrated into artificial intelligence (
AI
) development processes to uphold key data protection principles in the UK
GDPR
, like storage limitation, data minimisation, purpose limitation, security, and fairness. The analysis highlights how privacy-enhancing technologies offer benefits beyond anonymisation by embedding privacy-by-design values to support responsible innovation and protect sensitive patient data throughout the design, training, and validation of medical
AI
systems. The paper uses the 2015 DeepMind and Royal Free case as a practical study to realise the practical and legal benefits of privacy-enhancing technologies in medical
AI
development, particularly involving public-private collaborations. While grounded in the UK context, the findings have broader relevance to the European Union and other international jurisdictions grappling with tensions between data protection and
AI
development in the healthcare context.
Yasmine Zoya· European Journal of Health L...· 0 citations
This paper empirically evaluates ChatGPT 3.5 and 4.0 using over 23,000 real user-generated medical queries, assessing their susceptibility to privacy breaches through quasi-identifiers such as age, location, phone number and national registration number and proposes a scalable privacy evaluation model that combines k-anonymity, l-diversity, t-closeness, entropy, re-identification risk and delta-disclosure.
Foad Jalali, Mehran Alidoost Nia· Journal of Supercomputing· 0 citations
Safeguarding patient privacy while enabling meaningful healthcare data use remains critical under GDPR and HIPAA. Existing compliance methods are manual, error-prone, and separate policy audits from data-level assessments. This paper presents PriEval-Protect, a two-phase framework for unified privacy risk evaluation and mitigation. The evaluation phase combines regulatory compliance scoring using a fine-tuned legal LLM with RAG, and technical analysis via encryption type, data architecture, and metrics including similarity, uncertainty, adversary success, and information gain/loss. A composite risk score uses weighted aggregation via Analytic Hierarchy Process. The protection phase recommends countermeasures including federated learning and differential privacy based on assessed risk. Results on hospital documents and datasets demonstrate regulation-aligned, explainable assessments, bridging legal conformance and data-level risk analysis.
Ilef Chebil, Asma El Hadj, Souheib Yousfi et al.· 0 citations
Clinical foundation models trained on large-scale patient data are increasingly used for decision support, screening, and public health. As deployment expands, privacy risk increasingly arises from model-mediated leakage, yet its prevalence and severity remain poorly quantified. Models can disclose sensitive training artifacts, enabling patient re-identification in ways not captured by data-handling controls alone. Existing frameworks, including HIPAA and GDPR, offer limited guidance for such indirect threats. We propose a practical framework for assessing privacy risk in clinical foundation models and illustrate realistic leakage scenarios across deployment settings, map them to legal regimes, and outline complementary technical and legal mitigations. Our analysis provides a context-aware risk assessment grounded in realistic usage to preserve the value of medical foundation models while rigorously safeguarding patient privacy.
Sana Tonekaboni, Lena Stempfle, Sasha Ronaghi et al.· 0 citations