PubMed Health⌕ Search

SEARCH · PubMed Health

Results for “Privacy”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8Linked to original sources

Privacy, security, and reliability risks of artificial intelligence in healthcare: a systematic review of empirical evidence.

BACKGROUND: Artificial intelligence (AI) is increasingly integrated into healthcare information systems, supporting clinical decision-making, imaging analysis, and predictive modeling. While these applications offer operational and clinical benefits, they also introduce emerging risks to patient privacy, data security, and system reliability. OBJECTIVE: To systematically review empirical evidence on privacy breaches, security vulnerabilities, and misuse associated with AI applications in healthcare settings. METHODS: PubMed, Embase, Web of Science, Scopus, IEEE Xplore, and ACM Digital Library were searched for empirical studies published between January 2015 and November 2025 that evaluated AI use or misuse in clinical diagnosis, treatment, or decision-making. Two reviewers independently screened studies and extracted data using a standardized form. Findings were synthesized narratively due to heterogeneity in study designs, AI methods, and reported outcomes. RESULTS: Of 7,285 records identified through database searches and 205 through citation screening, 22 empirical studies met the inclusion criteria, spanning multiple clinical domains and data modalities, predominantly medical imaging applications. Five recurring threat categories were identified: patient re-identification, membership inference, unauthorized access and adversarial exploitation, input manipulation, and misuse or overinterpretation of AI outputs. Across studies, AI models were shown to encode latent biometric signals across diverse data types, limiting the effectiveness of traditional anonymization and synthetic data approaches. Adversarial attacks and input manipulation were also shown to compromise diagnostic performance and system integrity. CONCLUSION: This systematic review provides empirical evidence suggesting that contemporary AI systems in healthcare introduce privacy and security risks that may challenge traditional assumptions about data protection. These findings underscore the need for privacy- and security-by-design approaches and governance frameworks that address risks across the AI lifecycle.

Humans↗

Privacy and policy for genetic research.

I begin with a discussion of the value of privacy and what we lose without it. I then turn to the difficulties of preserving privacy for genetic information and other medical records in the face of advanced information technology. I suggest three alternative public policy approaches to the problem of protecting individual privacy and also preserving databases for genetic research: (1) governmental guidelines and centralized databases, (2) corporate self-regulation, and (3) my hybrid approach. None of these are unproblematic; I discuss strengths and drawbacks of each, emphasizing the importance of protecting the privacy of sensitive medical and genetic information as well as letting information technology flourish to aid patient care, public health and scientific research.

Access to Information↗

Genetic privacy and academic medicine: the Oregon experience.

Legislators are considering the conflicting concerns of consumers, researchers, health care providers, and business in the rapidly developing area of genetics. The Oregon Genetic Privacy Act of 1995 was written to protect the individual's right to genetic privacy by providing legal protection for medical information, tissue samples, and DNA samples. This legislation has had an impact on the academic medical center of Oregon Health Sciences University (OHSU) with its teaching hospital and associated clinics, both in providing medical services and in research. This impact has occurred in several areas: (1) informed consent, (2) ownership of genetic information, and (3) security of medical information. It affects both patient care and research. OHSU and other academic medical centers have a mandate to provide leadership in the education of medical students, residents, and physicians about genetic privacy and the issues and areas affected by it. As genetic privacy legislation is developed and enacted at state and federal levels, the needs of individuals must be balanced with the needs of institutions and of research in the larger context of societal needs.

Academic Medical Centers↗

Driving toward guiding principles: a goal for privacy, confidentiality, and security of health information.

As health care moves from paper to electronic data collection, providing easier access and dissemination of health information, the development of guiding privacy, confidentiality, and security principles is necessary to help balance the protection of patients' privacy interests against appropriate information access. A comparative review and analysis was done, based on a compilation of privacy, confidentiality, and security principles from many sources. Principles derived from ten identified sources were compared with each of the compiled principles to assess support level, uniformity, and inconsistencies. Of 28 compiled principles, 23 were supported by at least 50 percent of the sources. Technology could address at least 12 of the principles. Notable consistencies among the principles could provide a basis for consensus for further legislative and organizational work. It is imperative that all participants in our health care system work actively toward a viable resolution of this information privacy debate.

Computer Security↗

Genetic privacy and the law: an end to genetics exceptionalism.

While the proliferation of human genetic information promises to achieve many public benefits, the acquisition, use, retention, and disclosure of genetic data threatens individual liberties. States (and to a lesser degree, the federal government) have responded to the anticipated and actual threats of privacy invasion and discrimination by enacting several types of genetic-specific legislation. These laws emphasize the differences between genetic information and other health information. By articulating these differences, governments afford genetic data an "exceptional" status. The authors argue that genetic exceptionalism is flawed for two reasons: (1) strict protections of autonomy, privacy, and equal treatment of persons with genetic conditions threaten the accomplishment of public goods; and (2) there is no clear demarcation separating genetic data from other health data; other health data deserve protections in a national health information infrastructure. The authors present ideas for individual privacy protections that balance the societal need for genetic information and the claims for privacy by individuals and families.

Databases, Nucleic Acid↗

The need to know versus the right to know: privacy of patient medical data in an information-based society.

"Whatever, in connection with my professional practice, or not in connection with it, I see or hear, in the life of men, which ought not to be spoken of abroad, I will not divulge, as reckoning that all such should be kept secret."(1) "Safeguards to privacy in individual health care information are imperative to preserve the health care delivery relationship and the integrity of the patient record."(2) As early as the fourth and fifth centuries B.C., Hippocrates contemplated the importance of medical information to the care and treatment of patients. His oath suggests that privacy of a patient's medical information creates the foundation upon which a patient reposes trust in his or her physician. While defining the earliest version of the physician-patient privilege, the oath does not envision the extent of modern day access to healthcare information. A patient's relationship with the modern healthcare delivery system often includes a team of physicians, nurses, and other clinical support personnel. This relationship extends beyond direct caregivers and may include healthcare administrators, payor organizations, and persons unfamiliar with a patient's identity, such as researchers and public health officials. Accessing a patient's medical information links these participants to the patient's healthcare delivery relationship. The Hippocratic Oath does not contemplate such broad access, nor does it contemplate the emerging privacy crisis resulting from the application of computer technology to medical record storage and retrieval. The combination of broad access, individual privacy rights, and computer technology requires a rethinking of measures designed to protect the realities of the modern medical information society.

Computer Security↗

Potential impact of the HIPAA privacy rule on data collection in a registry of patients with acute coronary syndrome.

BACKGROUND: Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule has the potential to affect data collection in outcomes research. METHODS: To examine the extent to which data collection may be affected by the HIPAA Privacy Rule, we used a quasi-experimental pretest-posttest study design to assess participation rates with informed consent in 2 cohorts of patients eligible for the University of Michigan Acute Coronary Syndrome registry. The pre-HIPAA period included telephone interviews conducted at 6 months that sought verbal informed consent from patients. In the post-HIPAA period, informed consent forms were mailed to ask for permission to call to conduct a telephone interview. The primary outcome measure was the percentage of patients who provided consent. Incremental costs associated with the post-HIPAA period were also assessed. RESULTS: The pre-HIPAA period included 1221 consecutive patients with acute coronary syndrome, and the post-HIPAA period included 967 patients. Consent for follow-up declined from 96.4% in the pre-HIPAA period to 34.0% in the post-HIPAA period (P<.01). In general, patients who returned written consent forms during the post-HIPAA period were older, were more likely to be married, and had lower mortality rates at 6 months. Incremental costs for complying with the HIPAA Privacy Rule were $8704.50 for the first year and $4558.50 annually thereafter. CONCLUSIONS: The HIPAA Privacy Rule significantly decreases the number of patients available for outcomes research and introduces selection bias in data collection for patient registries.

Acute Disease↗

From Hippocrates to HIPAA: privacy and confidentiality in emergency medicine--Part I: conceptual, moral, and legal foundations.

Respect for patient privacy and confidentiality is an ancient and a contemporary professional responsibility of physicians. Carrying out this responsibility may be more challenging and more important in the emergency department than in many other clinical settings. Part I of this 2-part article outlines the basic concepts of privacy and confidentiality, reviews the moral and legal foundations and limits of these concepts, and highlights the new federal privacy regulations implemented under the Health Insurance Portability and Accountability Act of 1996. Part II of the article examines specific privacy and confidentiality issues commonly encountered in the ED.

Codes of Ethics↗

Privacy and confidentiality in emergency medicine: obligations and challenges.

Respect for privacy and confidentiality have been professional responsibilities of physicians throughout recorded history. This article reviews the moral, religious, and legal foundations of privacy and confidentiality and discusses the distinction between these two closely related concepts. Current federal and state laws are reviewed, including HIPAA regulations and their implications for research and care in the emergency department. In the emergency department, privacy and confidentiality often are challenged by physical design, crowding, visitors, film crews, communication, and other factors. These problems are reviewed, and advice and guidelines are offered for helping preserve patients' dignity and rights to privacy and confidentiality.

Biomedical Research↗

How (not) to protect genomic data privacy in a distributed network: using trail re-identification to evaluate and design anonymity protection systems.

The increasing integration of patient-specific genomic data into clinical practice and research raises serious privacy concerns. Various systems have been proposed that protect privacy by removing or encrypting explicitly identifying information, such as name or social security number, into pseudonyms. Though these systems claim to protect identity from being disclosed, they lack formal proofs. In this paper, we study the erosion of privacy when genomic data, either pseudonymous or data believed to be anonymous, are released into a distributed healthcare environment. Several algorithms are introduced, collectively called RE-Identification of Data In Trails (REIDIT), which link genomic data to named individuals in publicly available records by leveraging unique features in patient-location visit patterns. Algorithmic proofs of re-identification are developed and we demonstrate, with experiments on real-world data, that susceptibility to re-identification is neither trivial nor the result of bizarre isolated occurrences. We propose that such techniques can be applied as system tests of privacy protection capabilities.

Algorithms↗

Health information: reconciling personal privacy with the public good of human health.

The success of the health care system depends on the accuracy, correctness and trustworthiness of the information, and the privacy rights of individuals to control the disclosure of personal information. A national policy on health informational privacy should be guided by ethical principles that respect individual autonomy while recognizing the important collective interests in the use of health information. At present there are no adequate laws or constitutional principles to help guide a rational privacy policy. The laws are scattered and fragmented across the states. Constitutional law is highly general, without important specific safeguards. Finally, a case study is provided showing the important trade-offs that exist between public health and privacy. For a model public health law, see www.critpath.org/msphpa/privacy.

Access to Information↗

Comments on privacy and medicine.

The ease of access to medical data on the one hand and the privacy rights of the individual on the other coexist in a delicate balance. Therefore, it is necessary to carefully consider the trade-offs between the two. One approach might be to consider the nature of possible violations of privacy and determine the costs and benefits of avoiding those violations. Not all violations are equally dangerous. Moreover, some violations of privacy are sanctioned by policy (for example, preexisting medical conditions). Society needs to be careful to distinguish between these kinds of privacy issues and those that require technical solutions. Technical solutions tend to be expensive and can create other dangers by impeding access to important medical information.

Access to Information↗

Privacy for defecation and fecal incontinence in older adults.

INTRODUCTION: Privacy during defecation is important to individuals and society at large and it has not been studied in older people with fecal incontinence. METHODS: One hundred twenty adults aged 65 years and with fecal incontinence who were either living in their own homes or in a nursing home or receiving care in an acute or rehabilitation elderly care ward were surveyed with a questionnaire that included questions on privacy during defecation. RESULTS: Privacy while defecating was often least achieved in the patients with fecal incontinence living in nursing homes (NH) (n=7, 23%) but usually was achieved in those living at home (H) (n=28, 93%) and by some being cared for in rehabilitation wards (R) (n=16, 53%) or in acute wards (AC) (n=15, 50%; P<.001). Very few participants with fecal incontinence were aware of leakage (NH: n=3, 10%; R: n=9, 30%; AC: n=9, 30%; H: n=15, 50%), able to clean themselves (NH: n=0, 0%; R: n=2, 7%; AC: n=5, 17%; H: n=24, 80%) or had access to patient information leaflets about fecal incontinence (NH: n=3, 10%; R: n=4, 13%; AC: n=1, 3%; H: n=16, 53%). CONCLUSION: Older people, especially those who are dependent, lack privacy during bowel movements. They are usually unaware of being incontinent of stool and are unable to clean themselves afterwards. Access to information about fecal incontinence is poor.

Activities of Daily Living↗

Genetic privacy.

During the past 10 years, the number of genetic tests performed more than tripled, and public concern about genetic privacy emerged. The majority of states and the U.S. government have passed regulations protecting genetic information. However, research has shown that concerns about genetic privacy are disproportionate to known instances of information misuse. Beliefs in genetic determinacy explain some of the heightened concern about genetic privacy. Discussion of the debate over genetic testing within families illustrates the most recent response to genetic privacy concerns.

Confidentiality↗

The influence of nurses' attitudes, subjective norms and perceived behavioral control on maintaining patients' privacy in a hospital setting.

The research reported in this article examined the influence of nurses' attitudes, subjective norms and perceived behavioral control on maintaining patients' privacy during hospitalization. The data were gathered from 109 nurses in six internal medicine wards at an Israeli hospital. The research was based on the theories of reasoned action and planned behavior. A positive and significant correlation was shown between nurses' attitude to promoting and maintaining patient privacy and their planned behavior, while perceived behavioral control was the best variable for predicting the nurses' behavior. Better educated nurses believed that they had fewer resources and anticipated more obstacles in acting to promote and maintain patient privacy. This research adds a new dimension to what is already known about nurses' attitudes to maintaining patients' privacy, nurses' planned behavior and their actual behavior. The practical implications of the findings are the identification of factors that influence the attitudes and behavior of nursing staff, which, in turn, will enable allocation of resources for solving difficulties and removing obstacles. The results will allow the formulation of educational programs to guide staff and also the application of policies based on both patient and nursing staff needs.

Adult↗

Understanding privacy in occupational health services.

The aim of this study was to gain a deeper understanding of privacy in occupational health services. Data were collected through in-depth theme interviews with occupational health professionals (n = 15), employees (n = 15) and employers (n = 14). Our findings indicate that privacy, in this context, is a complex and multilayered concept, and that companies as well as individual employees have their own core secrets. Co-operation between the three groups proved challenging: occupational health professionals have to consider carefully in which situations and how much they are entitled to release private information on individual employees for the benefit of the whole company. Privacy is thus not an absolute right of an individual, but involves the idea of sharing responsibility. The findings open up useful new perspectives on ethical questions of privacy and on the development of occupational health practices.

Adult↗

Security, privacy, and confidentiality issues on the Internet.

We introduce the issues around protecting information about patients and related data sent via the Internet. We begin by reviewing three concepts necessary to any discussion about data security in a healthcare environment: privacy, confidentiality, and consent. We are giving some advice on how to protect local data. Authentication and privacy of e-mail via encryption is offered by Pretty Good Privacy (PGP) and Secure Multipurpose Internet Mail Extensions (S/MIME). The de facto Internet standard for encrypting Web-based information interchanges is Secure Sockets Layer (SSL), more recently known as Transport Layer Security or TLS. There is a public key infrastructure process to 'sign' a message whereby the private key of an individual can be used to 'hash' the message. This can then be verified against the sender's public key. This ensures the data's authenticity and origin without conferring privacy, and is called a 'digital signature'. The best protection against viruses is not opening e-mails from unknown sources or those containing unusual message headers.

Computer Security↗

Implementation of data security and data privacy provisions will bring sweeping changes to laboratory service providers.

The Health Insurance Portability and Accountability Act included substantial changes involving handling of health information by establishing national standards for electronic transactions, data privacy, and data security. The first final rule for electronic transaction standards was published August 17, 2000. The remaining final rules are expected to be published in Winter 2000. Providers, such as clinical laboratories, will have 26 months from the data of publication to comply. The civil monetary fines for noncompliance are substantial. This article will review the key provisions of the data security and data privacy proposed rules. These provisions will touch virtually every aspect of electronic claims submissions, electronic data transactions, and the electronic storage of medical information. The proposed rules will require a coordinated approach by providers to develop the policies and procedures, and the technical and physical infrastructure to protect health information. Moreover, providers will need to identify a privacy officer, to review existing privacy policies to compare the proposed rule with any existing state laws to determine which may be more stringent, and to develop new policies to address the particular requirements of the final rule.

Centers for Medicare and Medicaid Services, U.S.↗