Researchers from Imperial College London, the Technical University of Munich, and the Hasso Plattner Institute have published findings in Nature showing that artificial intelligence models trained on medical data can be exploited to identify specific individual patients — sometimes with near-perfect accuracy, even when those patients' records have been de-identified.
The research represents one of the first patient-level privacy audits of medical AI, and its findings challenge a foundational assumption in healthcare AI development: that removing names and other identifiable information from medical records is sufficient to protect patient privacy when that data is used to train AI models.