Pith. sign in

REVIEW 3 major objections 4 minor 103 references

Protecting patient privacy in clinical foundation models: Technical and legal perspectives

T0 review · 3 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read Privacy risk in clinical foundation models is continuous rather than categorical, and laws built for static data handling — HIPAA in the US and the GDPR in the EU — give limited guidance for leakage that happens through the model itself.

desk verdict Useful legal synthesis and concrete scenarios, but the two-axis framework overclaims orthogonality and the continuity conclusion isn't supported. read the letter →

arxiv 2608.07705 v1 pith:G6A57MVT submitted 2026-08-07 cs.AI cs.LG

classification cs.AIcs.LG
keywords privacyriskclinicalfoundationmodelsmodel-mediatedleakagere-identificationmemorizationHIPAAGDPREUAIAct
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper argues that the dominant privacy threat from clinical foundation models is no longer the handling of patient records but what the trained model itself reveals: models can reproduce memorized images, notes, or diagnostic details that enable patient re-identification even when the training data was de-identified. It claims that existing US and EU frameworks — HIPAA, the GDPR, and the EU AI Act — were built to govern static data handling and therefore give little practical guidance for this indirect, model-mediated leakage. The paper proposes a two-axis framework for assessing such risk: how much prior information a user needs to trigger a leak, and how sensitive the leaked information is. If the paper is right, privacy assessment should be continuous and context-aware, tied to realistic deployment scenarios rather than to the binary question of whether data was anonymized.

What carries the argument

The load-bearing object is the paper's two-dimensional privacy-risk framework (Figure 1b). Axis I — prior information — runs from no prior or publicly accessible information up to linkable personal information such as a medication list or a single diagnostic test; Axis II — leaked information — runs from linkable personal information up to identifiable personal information such as a near-verbatim clinical note. The framework's job is to locate every leakage scenario at a coordinate, so that risk is read jointly: leakage that requires little prior knowledge and reveals identifiable information sits at the top of the risk space, and mitigation is calibrated to that position. The six illustrative scenarios are the concrete carriers of the argument: they connect the axes to real deployment channels (institutional fine-tuning versus APIs, web interfaces, and open weights) and to the legal analysis, since each scenario is checked against GDPR roles and obligations and against AI Act high-risk classification.

What would settle it

A concrete check would be a systematic audit of deployed clinical foundation models in which leakage incidents are scored on both axes and against actual re-identification outcomes: if two incidents at the same two-axis coordinates produce materially different real-world harms, or if any documented leakage event cannot be placed on either axis, the claim that the axes are orthogonal and jointly sufficient would be refuted. A lighter test would ask whether any scenario the framework ranks as low risk has already produced a documented patient re-identification.

Watch

Extended reading notes

Core claim

The paper's central claim is that privacy risk in clinical foundation models is continuous rather than categorical, and that the right unit of analysis is the joint position of a leakage event on two orthogonal axes: the prior information required to elicit the leak, and the type and sensitivity of the information leaked. The highest-risk events are those that need little or no prior information and yet yield linkable or identifiable personal information — for example, a generic prompt that produces a near-replica of a training brain MRI, or an autocomplete that copies another patient's phone number and name into a chart. Through six scenarios spanning local hospital deployment and public release (reconstruction, memorization, leaked autocompletion, autocompletion, membership leakage, and secondary use), the paper shows that identical model behavior can carry very different risk depending on who can query the model and what auxiliary data they can combine with its outputs. Mapping the scenarios onto HIPAA, the GDPR, and the EU AI Act, it finds the legal frameworks underspecified: obligations attach to disclosure of personal data, yet models frequently leak probabilistic, fragmentary, or membership-level signals that fall short of explicit record release. The conclusion is that identifiability alone is too blunt a legal trigger, and that regulation should evolve toward context-aware assessment that weighs prior information and leaked information together.

Load-bearing premise

The framework's load-bearing premise is that the two axes — prior information needed to trigger a leak and sensitivity of what is leaked — are independent of each other and together cover every meaningful way a clinical foundation model can compromise patient privacy; if a real leakage route falls outside this space, or if the two dimensions interact in ways the framework does not model, its risk rankings lose their grounding.

Editorial extensions

If this is right

  • Risk assessment for clinical foundation models should shift from certifying that training data was de-identified toward deployment-specific evaluation of what the model can be made to reveal and who can plausibly elicit it.
  • A model trained on de-identified data can still expose patients: near-replica MRI generation, verbatim note reproduction, and membership inference in cohort-specific models each constitute disclosure that data-handling controls alone do not prevent.
  • The same model behavior can be a minor nuisance in one deployment and a serious breach in another, so governance terms such as licenses, API controls, and interface design should be treated as part of the privacy control surface.
  • Because data embedded in model weights is difficult to remove, secondary-use scenarios create an unresolved tension with erasure rights such as GDPR Article 17, and the paper's analysis implies that upstream consent and purpose limitation deserve more weight than post-hoc unlearning.
  • Differential privacy primarily limits what a model can reveal regardless of prior knowledge, while larger and more diverse training cohorts dilute the exposure of any individual record — so mitigation choices should be matched to where on the two axes a scenario falls.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the continuous-risk claim is right, the all-or-nothing legal category of 'personal data' becomes a poor regulatory trigger; a testable extension is whether regulators can define graduated duties that scale with the two-axis risk coordinate rather than with identifiability alone.
  • The framework implies a concrete, comparable benchmark: report each deployed model's 'leakage threshold profile' — the minimum prior information that elicits linkable or identifiable output in each scenario class — so that risk can be compared across models and releases.
  • The orthogonality assumption is itself testable: a corpus of leakage attempts that vary prior information and output sensitivity independently could reveal whether the risk surface is genuinely two-dimensional or whether the axes interact, for example if highly sensitive leaks systematically require more prior information than the framework assumes.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. This preprint argues that existing privacy frameworks (HIPAA, GDPR, and the EU AI Act) are underspecified for model-mediated privacy leakage from clinical foundation models. The authors propose a two-axis framework: Axis I is the prior information required for leakage (no/public information vs. linkable personal information), and Axis II is the type of leaked information (linkable vs. identifiable personal information). Six leakage scenarios are presented across local deployment and public release, mapped to GDPR/AIA roles and analyzed under U.S. and EU law. The paper concludes that privacy risk in foundation models is continuous and context-aware rather than categorical, and recommends complementary technical and legal mitigations, including DP, auditing, machine unlearning, and regulatory reform.

Significance. The legal analysis is careful, well-cited, and appropriately caveated, particularly on HIPAA's 'actual knowledge' provision and the untested status of privacy torts for generative-AI leakage. The six scenarios are concrete and cover distinct deployment pathways, and the paper is transparent about the absence of custom code or empirical data. If the two-axis framework could be made operational, it would bridge technical leakage auditing and legal privacy categories in a useful way. However, the framework is asserted rather than derived, and its central claims of orthogonality and continuity are internally inconsistent as stated. These issues are load-bearing because the framework is the manuscript's main contribution, so the paper requires substantial revision before the framework can support its conclusions.

major comments (3)
  1. [Section 3, Figure 1b; Appendix A] The framework's claim that Axis I and Axis II are 'orthogonal' is contradicted by the paper's own definitions. Axis II classifies leaked information as 'identifiable personal information' if it 'could render an individual identifiable,' and identifiability depends on the recipient's prior and auxiliary information, as the paper itself recognizes in Appendix A's discussion of CJEU Case C-413/23. Consequently, the same leaked artifact shifts between Axis II categories as Axis I changes. In S1, for example, a near-replica brain MRI is 'linkable personal information' for a recipient without cohort knowledge but becomes 'identifiable personal information' if the recipient knows the model was trained on MRIs from a rare tumor clinic; the model output is identical. Section 6 repeats the error when it states that differential privacy reduces 'vertical movement on axis II ... regardless of prior knowledge.' The two axes therefore do not define an independent risk space, and conclusions built on that orthogonality lack a well-defined basis. This is an internal definitional problem, not merely an absence of empirical validation.
  2. [Sections 3 and 7] The central conclusion that 'privacy risk in these systems is continuous rather than categorical' is not operationalized. The framework provides two coarse tiers on Axis I and two on Axis II, so placing scenarios at one of four combinations is categorical, and no metric, ordering, or aggregation rule is defined that would make risk continuous. Section 3's statement that the framework 'is designed to focus on cases where the sensitivity of the leaked data is higher than the required prior information' gestures at a composite ordering but does not define it. The paper therefore cannot support its recommendation that legal standards 'evolve to better reflect gradations' (Section 7). A revision should either define a precise risk measure over the two dimensions and state how to elicit it, or soften the continuity claim to a claim about context-dependence and graded severity.
  3. [Section 3] The framework's claim to characterize privacy risk in a two-dimensional space is further undermined by the paper's own concession that 'other factors, such as model architecture, scale, and training procedures, further affect leakage possibility, shaping the risk that sensitive medical details could be reproduced or inferred.' If these factors materially alter leakage possibility, then prior information and leaked information are not jointly sufficient to determine privacy risk, and the promised two-dimensional assessment is incomplete. The manuscript does not explain how these acknowledged factors are to be folded into Axis I or Axis II, nor why they can be treated as outside the framework.
minor comments (4)
  1. [Table 2] Several copy-paste artifacts undermine the reliability of the scenario corpus: S4's training-data row repeats S3's wording exactly ('Trained on de-identified patient notes and finetuned on identifiable discharge summaries'), S4's privacy-risk analysis embeds a leftover prompt fragment ('draft the likely recent timeline to support handoff') in the running text, and S5 lists 'Clinical language support' as the intended use although the scenario concerns a histopathology embedding model.
  2. [Section 2] The sentence 'In such settings, fine-tuning can use identifiable or de-identifiable.' is incomplete and should be finished or removed.
  3. [Section 5, S6] The GDPR/AIA analysis contains a grammatical error ('The hospital, as controller and must ensure...') and the preceding paragraph has 'renewing conset' instead of 'renewing consent.'
  4. [Appendix A] The reference to CJEU Case C-413/23 should include the case name and year, as the docket number alone is less informative to readers outside EU law.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the paper's framework is a proposed taxonomy and its legal conclusions rest on external statutes and case law, not on its own outputs.

full rationale

The paper does not claim to derive predictions or first-principles results from its framework. The two-axis risk space is stipulated as a conceptual organizing device, and the six scenarios are illustrative applications rather than fitted outputs. The central legal claim that HIPAA and GDPR offer limited guidance for model-mediated leakage is anchored in external sources: the text of HIPAA (45 C.F.R. §§ 160.103, 164.514), GDPR Articles 4 and 9, the EU AI Act, CNIL guidance, and the CJEU's C-413/23 decision reproduced in Appendix A. No equation, fitted parameter, or uniqueness theorem from the authors' prior work forces the conclusion. The only self-citation, Tonekaboni et al. 2025, supports a background statement that leakage auditing is common practice and is accompanied by independent references (Perez et al., Meeus et al., Purpura et al.); it is not load-bearing. The skeptic's orthogonality objection is a legitimate internal-consistency and supportability concern: Axis II's 'linkable personal information' is defined relative to 'other available information,' and Appendix A adopts a recipient-relative account of identifiability, so the axes are not fully independent in application, and the conclusion that risk is 'continuous rather than categorical' is asserted rather than operationalized. However, those are correctness critiques, not reductions of a claimed result to its inputs by construction. Per the hard rules, no circular step can be exhibited, so the appropriate finding is no significant circularity.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The paper has no fitted parameters and no invented entities. The framework depends on three domain assumptions: the realism of model-mediated leakage, the sufficiency of the two-axis representation, and the underspecification of current law. These are reasonable for a review but are not independently established here.

assumptions (3)
  • domain assumption Model-mediated leakage (memorization, reconstruction, membership inference) is a realistic privacy risk in clinical foundation models.
    The paper relies on cited studies (Carlini et al., Dar et al., Packhäuser et al.) to assert these attacks are feasible; no new experiments are run. This underpins the entire motivation in Sections 1 and 5.
  • ad hoc to paper Privacy risk can be captured by two orthogonal axes: prior information and leaked information.
    The framework is proposed in Section 3 but is not empirically or formally validated. The orthogonality of the axes is asserted, not demonstrated, and the paper does not test whether the axes are sufficient.
  • domain assumption Existing legal frameworks (HIPAA, GDPR, AIA) focus on data handling rather than model behavior, creating a gap.
    The paper's central gap claim rests on the legal interpretation presented in Section 4. The authors acknowledge some contested elements, such as the 'actual knowledge' clause in HIPAA and the relative identifiability standard in GDPR.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Protecting patient privacy in clinical foundation models: Technical and legal perspectives." pith.science (2026). https://pith.science/paper/G6A57MVT

@misc{pith2026260807705,
  author       = {Pith},
  title        = {Pith review of: Protecting patient privacy in clinical foundation models: Technical and legal perspectives},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/G6A57MVT}},
  note         = {Machine review of arXiv:2608.07705}
}
read the original abstract

Clinical foundation models trained on large-scale patient data are increasingly used for decision support, screening, and public health. As deployment expands, privacy risk increasingly arises from model-mediated leakage, yet its prevalence and severity remain poorly quantified. Models can disclose sensitive training artifacts, enabling patient re-identification in ways not captured by data-handling controls alone. Existing frameworks, including HIPAA and GDPR, offer limited guidance for such indirect threats. We propose a practical framework for assessing privacy risk in clinical foundation models and illustrate realistic leakage scenarios across deployment settings, map them to legal regimes, and outline complementary technical and legal mitigations. Our analysis provides a context-aware risk assessment grounded in realistic usage to preserve the value of medical foundation models while rigorously safeguarding patient privacy.

Figures

Figures reproduced from arXiv: 2608.07705 by the authors.

Figure 1
Figure 1. Overview of the deployment workflow and privacy risk framework. [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗
Figure 2
Figure 2. Privacy leakage scenarios across deployment pathways. Illustrative examples of the six scenarios described in [PITH_FULL_IMAGE:figures/full_fig_p008_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

103 extracted references · 67 canonical work pages

  1. [1]

    Gupta, Vikash and Erdal, Barbaros Selnur and Ramirez, Carolina and Floca, Ralf and Jackson, Laurence and Genereaux, Brad and Bryson, Sidney and Bridge, Christopher P. and Kleesiek, Jens and Nensa, Felix and Braren, Rickmer and Younis, Khaled and Penzkofer, Tobias and Bucher, Andreas Michael and Qin, Ming Melvin and Bae, Gigon and Lee, Hyeonhoon and Cardos...

  2. [2]

    and Darzi, Ara and Etemadi, Mozziyar and Garcia-Vicente, Florencia and Gilbert, Fiona J

    McKinney, Scott Mayer and Sieniek, Marcin and Godbole, Varun and Godwin, Jonathan and Antropova, Natasha and Ashrafian, Hutan and Back, Trevor and Chesus, Mary and Corrado, Greg S. and Darzi, Ara and Etemadi, Mozziyar and Garcia-Vicente, Florencia and Gilbert, Fiona J. and Halling-Brown, Mark and Hassabis, Demis and Jansen, Sunny and Karthikesalingam, Ala...

  3. [3]

    A clinically applicable approach to continuous prediction of future acute kidney injury , journal =

    Toma. A clinically applicable approach to continuous prediction of future acute kidney injury , journal =

  4. [4]

    FDA-Authorized AI/ML Tool for Sepsis Prediction: Development and Validation , journal =

    Bhargava, Akhil and L. FDA-Authorized AI/ML Tool for Sepsis Prediction: Development and Validation , journal =. 2024 , doi =

  5. [5]

    and Leskovec, Jure and Topol, Eric J

    Moor, Michael and Banerjee, Oishi and Abad, Zahra Shakeri Hossein and Krumholz, Harlan M. and Leskovec, Jure and Topol, Eric J. and Rajpurkar, Pranav , title =. Nature , volume =

  6. [6]

    Nature Medicine , volume =

    Tham, Yih Chung and Goh, Jocelyn Hui Lin and Zur, Dinah , title =. Nature Medicine , volume =

  7. [7]

    IEEE Reviews in Biomedical Engineering , volume =

    He, Yuting and Huang, Fuxiang and Jiang, Xinrui and Nie, Yuxiang and Wang, Minghao and Wang, Jiguang and Chen, Hao , title =. IEEE Reviews in Biomedical Engineering , volume =

  8. [8]

    Artificial Intelligence in Medicine , volume =

    Sun, Kai and Xue, Siyan and Sun, Fuchun and Sun, Haoran and Luo, Yu and Wang, Ling and Wang, Siyuan and Guo, Na and Liu, Lei and Zhao, Tian and Wang, Xinzhou and Yang, Lei and Jin, Shuo and Yan, Jun and Dong, Jiahong , title =. Artificial Intelligence in Medicine , volume =

Show all 103 references
  1. [9]

    npj Digital Medicine , volume =

    Guo, Lin Lawrence and Fries, Jason and Steinberg, Ethan and Fleming, Scott Lanyon and Morse, Keith and Aftandilian, Catherine and Posada, Jose and Shah, Nigam and Sung, Lillian , title =. npj Digital Medicine , volume =

  2. [10]

    MedGemma Technical Report , journal =

    Sellergren, Andrew and Kazemzadeh, Sahar and Jaroensri, Tiam and Kiraly, Atilla and Traverse, Madeleine and Kohlberger, Timo and Xu, Shawn and Jamil, Fayaz and Hughes, C. MedGemma Technical Report , journal =. 2025 , note =

  3. [11]

    and Shah, Nigam and Fries, Jason and Sung, Lillian , title =

    Guo, Lin Lawrence and Steinberg, Ethan and Fleming, Scott Lanyon and Posada, Jose and Lemmon, Joshua and Pfohl, Stephen R. and Shah, Nigam and Fries, Jason and Sung, Lillian , title =. Scientific Reports , volume =

  4. [12]

    and Was, Jaroslaw and Li, Quanzheng and Bates, David W

    Renc, Pawel and Jia, Yugang and Samir, Anthony E. and Was, Jaroslaw and Li, Quanzheng and Bates, David W. and Sitek, Arkadiusz , title =. npj Digital Medicine , volume =

  5. [13]

    2026 , month = jan, day =

    Introducing. 2026 , month = jan, day =

  6. [14]

    and Papaioannou, Jens-Michalis and Grundmann, Paul and Oberhauser, Tom and Figueroa, Alexei and L

    Han, Tianyu and Adams, Lisa C. and Papaioannou, Jens-Michalis and Grundmann, Paul and Oberhauser, Tom and Figueroa, Alexei and L. arXiv preprint arXiv:2304.08247 , year =

  7. [15]

    Research Square , year =

    Xie, Qianqian and Chen, Qingyu and Chen, Aokun and Peng, Cheng and Hu, Yan and Lin, Fongci and Peng, Xueqing and Huang, Jimin and Zhang, Jeffrey and Keloth, Vipina and Zhou, Xinyu , title =. Research Square , year =

  8. [16]

    Journal of the American Medical Informatics Association , volume =

    Benitez, Kathleen and Malin, Bradley , title =. Journal of the American Medical Informatics Association , volume =

  9. [17]

    The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural Networks , booktitle =

    Carlini, Nicholas and Liu, Chang and Erlingsson,. The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural Networks , booktitle =

  10. [18]

    arXiv preprint arXiv:1911.00172 , year =

    Khandelwal, Urvashi and Levy, Omer and Jurafsky, Dan and Zettlemoyer, Luke and Lewis, Mike , title =. arXiv preprint arXiv:1911.00172 , year =

  11. [19]

    Advances in Neural Information Processing Systems , volume =

    Biderman, Stella and Prashanth, USVSN Sai and Sutawika, Lintang and Schoelkopf, Hailey and Anthony, Quentin and Purohit, Shivanshu and Raff, Edward , title =. Advances in Neural Information Processing Systems , volume =

  12. [20]

    and Zettlemoyer, Luke and Aghajanyan, Armen , title =

    Tirumala, Kushal and Markosyan, Aram H. and Zettlemoyer, Luke and Aghajanyan, Armen , title =. Advances in Neural Information Processing Systems , volume =

  13. [21]

    Breach Report , year =

  14. [22]

    Health Insurance Portability and Accountability Act of 1996 , year =

  15. [23]

    Official Journal of the European Union , volume =

    Regulation (. Official Journal of the European Union , volume =

  16. [24]

    Computer Law & Security Review , volume =

    Novelli, Claudio and Casolari, Federico and Hacker, Philipp and Spedicato, Giorgio and Floridi, Luciano , title =. Computer Law & Security Review , volume =

  17. [25]

    2025 , month = apr, howpublished =

    Barber. 2025 , month = apr, howpublished =

  18. [26]

    Computer Law & Security Review , volume =

    Holzenberger, Nils and Maxwell, Winston , title =. Computer Law & Security Review , volume =

  19. [27]

    npj Digital Medicine , volume =

    Xie, Qianqian and Chen, Qingyu and Chen, Aokun and Peng, Cheng and Hu, Yan and Lin, Fongci and Peng, Xueqing and Huang, Jimin and Zhang, Jeffrey and Keloth, Vipina and Zhou, Xinyu and Qian, Lingfei and He, Huan and Shung, Dennis and Ohno-Machado, Lucila and Wu, Yonghui and Xu,...

  20. [28]

    and Parisien, Christopher and Compas, Colin and Martin, Cheryl and Costa, Anthony B

    Yang, Xi and Chen, Aokun and PourNejatian, Nima and Shin, Hoo Chang and Smith, Kaleb E. and Parisien, Christopher and Compas, Colin and Martin, Cheryl and Costa, Anthony B. and Flores, Mona G. and Zhang, Ying and Magoc, Tanja and Harle, Christopher A. and Lipori, Gloria and Mi...

  21. [29]

    Nature Communications , volume =

    Wu, Chaoyi and Zhang, Xiaoman and Zhang, Ya and Hui, Hui and Wang, Yanfeng and Xie, Weidi , title =. Nature Communications , volume =

  22. [30]

    Brandon and Jennum, Poul and Brink-Kjaer, Andreas and Mignot, Emmanuel and Zou, James , title =

    Thapa, Rahul and Kjaer, Magnus Ruud and He, Bryan and Covert, Ian and Moore, Hyatt, IV and Hanif, Umaer and Ganjoo, Gauri and Westover, M. Brandon and Jennum, Poul and Brink-Kjaer, Andreas and Mignot, Emmanuel and Zou, James , title =. Nature Medicine , volume =

  23. [31]

    and Moura, Valdery and Jin, Jiarui and Liu, Che and Zhong, Lanhai and Sun, Chenxi and Clifford, Gari D

    Li, Jun and Aguirre, Aaron D. and Moura, Valdery and Jin, Jiarui and Liu, Che and Zhong, Lanhai and Sun, Chenxi and Clifford, Gari D. and Westover, M. Brandon and Hong, Shenda , title =. NEJM AI , volume =

  24. [32]

    Foundation Models for General Medical AI: Third International Workshop, MedAGI 2025, Held in Conjunction with MICCAI 2025, Daejeon, South Korea, September 27, 2025, Proceedings , series =

  25. [33]

    and Bao, Erik L

    Jun, Hyeji and Tanaka, Yutaro and Johri, Shreya and Camp, Sabrina Y. and Bao, Erik L. and Carvalho, Filipe L. F. and Gui, Dan Y. and Jordan, Alexander C. and Labaki, Chris and Martin, Samantha D. and Nagy, Matthew and O'Meara, Tess A. and Pappa, Theodora and Pimenta, Erica Mar...

  26. [34]

    and Gilbert, Stephen , title =

    Freyer, Oscar and Jayabalan, Sanddhya and Kather, Jakob N. and Gilbert, Stephen , title =. Nature Medicine , volume =

  27. [35]

    2024 , howpublished =

    Regulation (. 2024 , howpublished =

  28. [36]

    2023 , howpublished =

    Regulation (. 2023 , howpublished =

  29. [37]

    2022 , howpublished =

    Regulation (. 2022 , howpublished =

  30. [38]

    2025 , howpublished =

    Regulation (. 2025 , howpublished =

  31. [39]

    European Artificial Intelligence Board (

  32. [40]

    Medical Device Coordination Group (MDCG) , howpublished =

  33. [41]

    Feedback on Guidelines 01/2021 on Examples regarding Data Breach Notification , year =

  34. [42]

    JMIR Formative Research , volume =

    Morley, Jessica and Murphy, Louise and Mishra, Aashima and Joshi, Isha and Karpathakis, Konstantinos , title =. JMIR Formative Research , volume =

  35. [43]

    and Kerkman, Drew and Hoberg, Amy A

    Davis, Heather A. and Kerkman, Drew and Hoberg, Amy A. and Countryman, Melissa and Beaver, Whitney and Bybee, Kevin and Blum, James M. and Knosp, Brian M. , title =. JAMIA Open , volume =

  36. [44]

    2022 , eprint =

    Ethan Perez and Saffron Huang and Francis Song and Trevor Cai and Roman Ring and Jordan Aslanides and Amelia Glaese and Nathan McAleese and Geoffrey Irving , title =. 2022 , eprint =. doi:10.48550/arXiv.2202.03286 , url =

  37. [45]

    The Canary's Echo: Auditing Privacy Risks of LLM-Generated Synthetic Text , year =

    Matteo Meeus and Lukas Wutschitz and Santiago Zanella-B. The Canary's Echo: Auditing Privacy Risks of LLM-Generated Synthetic Text , year =. doi:10.48550/arXiv.2502.14921 , url =. 2502.14921 , archivePrefix=

  38. [46]

    Dove , title =

    Regina Becker and Edward S. Dove , title =. International Data Privacy Law , year =. doi:10.1093/idpl/ipag001 , url =

  39. [47]

    Smit, Jeroen A. R. and Mostert, Monique and van der Graaf, Rieke and Grobbee, Diederick E. and van Delden, Johannes J. M. , title =. European Journal of Human Genetics , year =. doi:10.1038/s41431-023-01457-2 , url =

  40. [48]

    2021 , doi =

    Assessment of the EU Member States' Rules on Health Data in the Light of the GDPR , publisher =. 2021 , doi =

  41. [49]

    Rad and Shreya Shinde and Mohammad S

    Alessio Purpura and Sparsh Wadhwa and Jack Zymet and Ananya Gupta and Andrew Luo and Mohammad K. Rad and Shreya Shinde and Mohammad S. Sorower , title =. Proceedings of the 5th Workshop on Trustworthy Natural Language Processing (TrustNLP) , pages =. 2025 , publisher =. doi:10...

  42. [50]

    Proceedings on Privacy Enhancing Technologies , volume =

    Bogdan Kulynych and Mohammad Yaghini and Giovanni Cherubin and Michael Veale and Carmela Troncoso , title =. Proceedings on Privacy Enhancing Technologies , volume =. 2022 , doi =

  43. [51]

    Federal and State Health Laws , year =

  44. [52]

    HIPAA Journal , howpublished =

    Steve Alder , title =. HIPAA Journal , howpublished =. 2025 , month = mar, day =

  45. [53]

    Computer Law & Security Review , volume =

    Cobbe, Jennifer , title =. Computer Law & Security Review , volume =

  46. [54]

    Comments on the European Data Protection Board's Guidelines 01/2021 on Examples Regarding Data Breach Notification , year =

  47. [55]

    Proceedings of the 28th International Conference on Artificial Intelligence and Statistics , series =

    Azhar, Asfandyar and Thielen, Paul and Langlotz, Curtis , title =. Proceedings of the 28th International Conference on Artificial Intelligence and Statistics , series =

  48. [56]

    and Joffe, Steven and Henderson, Gail E

    Spector-Bagdady, Kayte and Pentz, Rebecca D. and Joffe, Steven and Henderson, Gail E. and Kardia, Sharon L. R. and Bollinger, Jennifer and Kraft, Stephanie A. and McGraw, Deven and Trinidad, Susan B. and Wilfond, Benjamin S. and Shah, Niraj H. and Platt, Richard and Roden, Dan...

  49. [57]

    Secondary Use of Clinical Data in Data-Gathering, Non-Interventional Research or Learning Activities: Definition, Types, and a Framework for Risk Assessment , journal =

    Jungkunz, Miriam and K. Secondary Use of Clinical Data in Data-Gathering, Non-Interventional Research or Learning Activities: Definition, Types, and a Framework for Risk Assessment , journal =

  50. [58]

    arXiv preprint arXiv:2505.11413 , year =

    Chen, Sijia and Li, Xiaomin and Zhang, Mengxue and Jiang, Eric Hanchen and Zeng, Qingcheng and Yu, Chen-Hsiang , title =. arXiv preprint arXiv:2505.11413 , year =

  51. [59]

    Unconditional Latent Diffusion Models Memorize Patient Imaging Data , journal =

    Dar, Syed Uzair and Seyfarth, Moritz and Ayx, Ingo and Papavassiliu, Thomas and Schoenberg, S. Unconditional Latent Diffusion Models Memorize Patient Imaging Data , journal =

  52. [60]

    31st USENIX Security Symposium (USENIX Security 22) , pages =

    Stadler, Theresa and Oprisanu, Bristena and Troncoso, Carmela , title =. 31st USENIX Security Symposium (USENIX Security 22) , pages =

  53. [61]

    and Brune, Peter and Kong, Fanyu and Anderson, Dave and Lee, George and Meir, Arie and Bandukwala, Farhana and Kanal, Elli and Arık, Sercan Ö

    Yoon, Jinsung and Mizrahi, Michel and Ghalaty, Nahid Farhady and Jarvinen, Thomas and Ravi, Ashwin S. and Brune, Peter and Kong, Fanyu and Anderson, Dave and Lee, George and Meir, Arie and Bandukwala, Farhana and Kanal, Elli and Arık, Sercan Ö. and Pfister, Tomas , title =. np...

  54. [62]

    Sarkar, A. R. and Chuang, Yu-Sheng and Mohammed, Noman and Jiang, Xiaoqian , title =. Scientific Reports , volume =

  55. [63]

    arXiv preprint arXiv:2510.12950 , year =

    Tonekaboni, Sana and Stempfle, Lena and Fallahpour, Ashkan and Gerych, Walter and Ghassemi, Marzyeh , title =. arXiv preprint arXiv:2510.12950 , year =

  56. [64]

    Scientific Reports , volume =

    Packhäuser, Kai and Schaub, Daniel and Huber, Tobias and Pfeiffer, Michael and Schmidt, Gernot and Kather, Jakob Nikolas and Truhn, Daniel and Bruners, Peter and Penzkofer, Tobias and Pinto dos Santos, Daniel and Maier-Hein, Klaus and Baeßler, Bettina , title =. Scientific Rep...

  57. [65]

    Journal of Medical Internet Research , volume =

    Jeong, Young Uk and Yoo, Seung and Kim, Young-Hak and Shim, Woo Hyun , title =. Journal of Medical Internet Research , volume =

  58. [66]

    and Shi, Xiaoqian , title =

    Chen, Jiayuan and Wang, Wei H. and Shi, Xiaoqian , title =. Pacific Symposium on Biocomputing , volume =

  59. [67]

    Pseudonymisation of Neuroimages and Data Protection: Increasing Access to Data While Retaining Scientific Utility , journal =

    Eke, Damian and Aaseb. Pseudonymisation of Neuroimages and Data Protection: Increasing Access to Data While Retaining Scientific Utility , journal =

  60. [68]

    and de Montjoye, Yves-Alexandre , title =

    Rocher, Luc and Hendrickx, Julien M. and de Montjoye, Yves-Alexandre , title =. Nature Communications , volume =

  61. [69]

    Interaction Data Are Identifiable Even Across Long Periods of Time , journal =

    Cre. Interaction Data Are Identifiable Even Across Long Periods of Time , journal =

  62. [70]

    and Jee, Justin and Pichotta, Karl and Paul, Morgan A

    Kehl, Kenneth L. and Jee, Justin and Pichotta, Karl and Paul, Morgan A. and Trukhanov, Pavel and Fong, Christopher and Waters, Michele and Bakouny, Ziad and Xu, Wenxin and Choueiri, Toni K. and Nichols, Chelsea and Schrag, Deborah and Schultz, Nikolaus , title =. Nature Commun...

  63. [71]

    Journal of Medical Internet Research , volume =

    Chen, Yan and Esmaeilzadeh, Pouyan , title =. Journal of Medical Internet Research , volume =

  64. [72]

    Automatic De-identification of Textual Documents in the Electronic Health Record: A Review of Recent Research , journal =

    Meystre, St. Automatic De-identification of Textual Documents in the Electronic Health Record: A Review of Recent Research , journal =

  65. [73]

    EClinicalMedicine , volume=

    Navigating open data sharing and privacy in the age of clinical AI research: from reidentification to pseudo-reidentification , author=. EClinicalMedicine , volume=. 2026 , publisher=

  66. [74]

    arXiv preprint arXiv:2202.07646 , year =

    Carlini, Nicholas and others , title =. arXiv preprint arXiv:2202.07646 , year =

  67. [75]

    Analysing the Status of an

  68. [76]

    Blind Baselines Beat Membership Inference Attacks for Foundation Models , journal =

    Das, Debopam and Zhang, Jingwen and Tram. Blind Baselines Beat Membership Inference Attacks for Foundation Models , journal =

  69. [77]

    2021 IEEE International Conference on Data Mining (ICDM) , pages =

    Hu, Hongsheng and Salcic, Zoran and Sun, Lichao and Dobbie, Gillian and Zhang, Xuyun , title =. 2021 IEEE International Conference on Data Mining (ICDM) , pages =

  70. [78]

    arXiv preprint arXiv:2310.02664 , year =

    Gu, Xiang and Du, Chao and Pang, Tianyu and Li, Changyou and Lin, Min and Wang, Yisen , title =. arXiv preprint arXiv:2310.02664 , year =

  71. [79]

    arXiv preprint arXiv:2408.17003 , year =

    Li, Shuo and Yao, Lan and Zhang, Lei and Li, Yang , title =. arXiv preprint arXiv:2408.17003 , year =

  72. [80]

    Foundations and Trends in Theoretical Computer Science , volume =

    Dwork, Cynthia and Roth, Aaron , title =. Foundations and Trends in Theoretical Computer Science , volume =

  73. [81]

    Brendan and Mironov, Ilya and Talwar, Kunal and Zhang, Li , title =

    Abadi, Martin and Chu, Andy and Goodfellow, Ian and McMahan, H. Brendan and Mironov, Ilya and Talwar, Kunal and Zhang, Li , title =. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security , pages =

  74. [82]

    Computer Law & Security Review , volume=

    From theory to practice: Data minimisation and technical review of verifiable credentials under the GDPR , author=. Computer Law & Security Review , volume=. 2025 , publisher=

  75. [83]

    The Lancet Digital Health , volume=

    Federated electronic health records for the European Health Data Space , author=. The Lancet Digital Health , volume=. 2023 , publisher=

  76. [84]

    Brendan and Ramage, Daniel and Talwar, Kunal and Zhang, Li , title =

    McMahan, H. Brendan and Ramage, Daniel and Talwar, Kunal and Zhang, Li , title =. International Conference on Learning Representations (ICLR) , year =

  77. [85]

    and Kirchhof, Michael and Tuzel, Oncel , title =

    Pouransari, Hadi and Grangier, David and Thomas, C. and Kirchhof, Michael and Tuzel, Oncel , title =. International Conference on Learning Representations (ICLR) , year =

  78. [86]

    Proceedings of the 42nd International Conference on Machine Learning , series =

    Ghosal, Gaurav Rohit and Maini, Pratyush and Raghunathan, Aditi , title =. Proceedings of the 42nd International Conference on Machine Learning , series =

  79. [87]

    arXiv preprint arXiv:1605.07277 , year=

    Transferability in machine learning: from phenomena to black-box attacks using adversarial samples , author=. arXiv preprint arXiv:1605.07277 , year=

  80. [88]

    International Conference on Learning Representations , volume=

    Privacy auditing of large language models , author=. International Conference on Learning Representations , volume=

  81. [89]

    International Conference on Learning Representations , volume=

    Llm unlearning with llm beliefs , author=. International Conference on Learning Representations , volume=

  82. [90]

    Second Key Update: Technical Safeguards and Risk Management , year =

  83. [91]

    Computer Law & Security Review , volume=

    ‘It's not personal, it's strictly business’: Behavioural insurance and the impacts of non-personal data on individuals, groups and societies , author=. Computer Law & Security Review , volume=. 2025 , publisher=

  84. [92]

    2024 , howpublished =

  85. [93]

    Nature medicine , volume=

    Privacy in the age of medical big data , author=. Nature medicine , volume=. 2019 , publisher=

  86. [94]

    Software as a Medical Device (SaMD): Clinical Evaluation , year =

  87. [95]

    Digital Health Center of Excellence , year =

  88. [96]

    and Fries, Jason and Shah, Nigam H

    Wornow, Michael and Xu, Yizhe and Thapa, Rahul and Patel, Bhavik and Steinberg, Ethan and Fleming, Scott and Pfeffer, Marc A. and Fries, Jason and Shah, Nigam H. , title =. npj Digital Medicine , volume =

  89. [97]

    EDPB--EDPS Joint Opinion 2/2026 on the Proposal for a Regulation as Regards the Simplification of the Digital Legislative Framework (Digital Omnibus) , year =

  90. [98]

    and Des Jardins, Terris R

    Allen, Christina G. and Des Jardins, Terris R. and Heider, Anne and Lyman, Kevin A. and McWilliams, Jennifer and Rein, Andy L. and Schachter, Amy A. and Silow-Carroll, Sharon and Wright, Amy and Friedman, Carol P. , title =. eGEMs , volume =

  91. [99]

    npj Digital Medicine , volume =

    Bodnari, Andreea and Travis, John , title =. npj Digital Medicine , volume =

  92. [100]

    and Koyejo, Sanmi , title =

    Wang, Angelina and Ho, Daniel E. and Koyejo, Sanmi , title =. arXiv preprint arXiv:2509.19364 , year =

  93. [101]

    Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence and Amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and D...

  94. [102]

    2022 , pages =

    De Bruyne, Jan and Van Leenhove, Cedric , title =. 2022 , pages =

  95. [103]

    International Journal of Law and Information Technology , volume =

    Noto La Diega, Guido and Bezerra, Luiz Carlos , title =. International Journal of Law and Information Technology , volume =

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.