Protecting patient privacy in clinical foundation models: Technical and legal perspectives
Authors: Sana Tonekaboni, Lena Stempfle, Sasha Ronaghi, Corinna Coupette, I. Glenn Cohen, Emily Alsentzer, Marzyeh Ghassemi
Organizations: Massachusetts Institute of Technology (MIT), Cambridge, Massachusetts, USA · Broad Institute of MIT and Harvard, Cambridge, Massachusetts, USA · Stanford University, Stanford, California, USA · Aalto University, Espoo, Finland · Max Planck Institute for Tax Law and Public Finance, Munich, Germany · Stanford Center for Legal Informatics, Stanford Law School, Stanford, California, USA · Harvard Law School, Cambridge, Massachusetts, USA · Petrie-Flom Center for Health Law Policy, Biotechnology, and Bioethics, Cambridge, Massachusetts, USA
Clinical foundation models trained on large-scale patient data are increasingly used for decision support, screening, and public health planning. As deployment expands, privacy risk arises from model-mediated leakage, yet its prevalence and severity remain poorly quantified. Models can disclose sensitive training artifacts, enabling patient re-identification in ways not captured by data-handling controls alone. As a result, existing frameworks, including HIPAA and GDPR, offer limited protection against assessing and addressing. We propose a practical framework for assessing privacy risk in clinical foundation models, illustrate realistic leakage scenarios across deployment settings, map them to legal regimes, and outline complementary technical and legal mitigations. Our analysis provides a context-aware risk assessment grounded in realistic usage to preserve the value of medical foundation models while rigorously safeguarding patient privacy.