PubMed HealthSearch

SEARCH · PubMed Health

Results for “privacy”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 recordsLinked to original sources

Protecting human research from an invasion of privacy: the unintended results of the Commonwealth Privacy Act 1988.

In accordance with the Privacy Act 1988 (Cth), interium guidelines for the protection of privacy in the conduct of medical research have been issued by the National Health and Medical Research Council (NHMRC) with the approval of the Privacy Commissioner. The guidelines are intended to ensure that the privacy of the individual is not interfered with when a researcher seeks the release of personal information held by a Commonwealth agency, or when a Commonwealth agency conducts medical research, and to ensure that the conduct of medical research is not inhibited by the privacy legislation. However, the procedures established by the guidelines and the responsibilities placed upon researchers and institutional ethics committees could themselves have the effect of inhibiting research. In considering amendment, NHMRC and the Privacy Commissioner are urged to produce final guidelines which do not act as the straw to break the back of the current system of institutional ethics committees, which seeks to ensure proper ethical scrutiny and the facilitation of human research.

Advisory Committees

Australian standards for privacy and confidentiality of health records in research: implications of the Commonwealth Privacy Act.

The current Australian legal, administrative and professional standards for individual rights to confidentiality and privacy of health records are examined and guidance is offered for the use of personal information in research. The implications of recently introduced privacy legislation for the conduct of research in Australia are discussed. Acquired immunodeficiency syndrome (AIDS) is cited as an example of the complex issues which face researchers and administrative bodies in balancing the privacy rights of individuals and the broader public interest.

Acquired Immunodeficiency Syndrome

Is a Win-Win possible? Achieving pareto-optimal privacy-utility balance in fine-tuned genome language model embeddings against embedding reconstruction attacks.

MOTIVATION: Genomic data is among the most sensitive categories of personal information, and the growing adoption of language models for sequence analysis raises significant privacy concerns. Prior work demonstrated that embeddings from general-purpose language models adapted for genomic sequences leak substantial single-nucleotide information under reconstruction attacks, and that fine-tuning embeddings can reduce this vulnerability at certain positions. However, three critical questions remain unaddressed: (i) whether privacy-utility tradeoffs are inherent constraints or configuration-dependent phenomena; (ii) whether genomic-specialized models such as DNABERT-base and Nucleotide Transformer exhibit different vulnerabilities than adapted general-purpose models; and (iii) how to statistically validate whether observed privacy improvements represent meaningful gains. Addressing these gaps is essential for guiding model selection in privacy-sensitive genomic applications. RESULTS: We systematically evaluated 13 transformer architectures, 9 general-purpose and 4 genomic-specialized, under position-specific embedding reconstruction attacks. We assessed the vulnerabilities of both pre-trained and fine-tuned models to the single-nucleotide inference-reconstruction attack using our new metrics, including error-based privacy gain and Pareto dominance scores, and statistically validated the results via paired t-tests. XLNet-Large achieved the best observed privacy protection among all evaluated models (+19.5% mean privacy gain) while maintaining competitive prediction performance. General-purpose models outperformed genomic-specialized models in 56% of pairwise comparisons. Tokenization strategy, rather than domain specialization, emerged as the primary determinant of the privacy-utility balance. These findings provide evidence-based guidance for selecting models in privacy-sensitive short-window genomic applications. All privacy claims in this work are specific to position-wise embedding reconstruction attacks and do not extend to other privacy risks, such as membership inference or training data extraction, which may respond differently to fine-tuning. AVAILABILITY AND IMPLEMENTATION: The code is publicly available at https://github.com/AnonymousISCBConf/Win-Win-Privacy-Utility-Analysis.

Genomics

Privacy-preserving framework for genomic computations via multi-key homomorphic encryption.

MOTIVATION: The affordability of genome sequencing and the widespread availability of genomic data have opened up new medical possibilities. Nevertheless, they also raise significant concerns regarding privacy due to the sensitive information they encompass. These privacy implications act as barriers to medical research and data availability. Researchers have proposed privacy-preserving techniques to address this, with cryptography-based methods showing the most promise. However, existing cryptography-based designs lack (i) interoperability, (ii) scalability, (iii) a high degree of privacy (i.e. compromise one to have the other), or (iv) multiparty analyses support (as most existing schemes process genomic information of each party individually). Overcoming these limitations is essential to unlocking the full potential of genomic data while ensuring privacy and data utility. Further research and development are needed to advance privacy-preserving techniques in genomics, focusing on achieving interoperability and scalability, preserving data utility, and enabling secure multiparty computation. RESULTS: This study aims to overcome the limitations of current cryptography-based techniques by employing a multi-key homomorphic encryption scheme. By utilizing this scheme, we have developed a comprehensive protocol capable of conducting diverse genomic analyses. Our protocol facilitates interoperability among individual genome processing and enables multiparty tests, analyses of genomic databases, and operations involving multiple databases. Consequently, our approach represents an innovative advancement in secure genomic data processing, offering enhanced protection and privacy measures. AVAILABILITY AND IMPLEMENTATION: All associated code and documentation are available at https://github.com/farahpoor/smkhe.

Computer Security

Safeguarding biomedical AI: a critical scoping review of privacy-enhancing technologies, hybrid approaches, and deployment models.

BACKGROUND: Biomedical artificial intelligence (AI) requires the integration of privacy-enhancing technologies (PETs) to safeguard sensitive clinical, imaging, and genomic data while preserving analytical utility. OBJECTIVES: This review critically and systematically maps applications of PETs across the biomedical AI lifecycle in accordance with PRISMA-ScR guidelines and evaluates their technical trade-offs, deployment feasibility, and residual risks. METHODS: We systematically searched PubMed, IEEE Xplore, ACM Digital Library, and Scopus for studies published between 2015 and 2025. Eligible studies addressed differential privacy, federated learning, secure multiparty computation, homomorphic encryption, or hybrid approaches in biomedical AI. Data were charted on PET type, modality, lifecycle stage, utility metrics, privacy parameters, and deployment considerations. A critical appraisal rubric assessed threat-model adequacy, methodological clarity, reproducibility, privacy-utility transparency, and deployment realism. Additionally, we hand-searched major venues (USENIX Security, NeurIPS, AAAI) and screened Google Scholar for grey literature, applying de-duplication across sources. RESULTS: We identified 87 studies spanning clinical decision support, genomics, and medical imaging. From 25,761 initial records, 3,754 underwent title/abstract screening and 1,968 underwent full-text assessment. PETs demonstrated distinct strengths and limitations: differential privacy provided provable guarantees but reduced performance on imbalanced data; federated learning improved data access but remained vulnerable to gradient leakage; and cryptographic methods ensured confidentiality at high computational cost. Synthetic data generation supported privacy-conscious data sharing and benchmarking but remained sensitive to disclosure risk, fidelity loss, and subgroup representation. Hybrid and emerging approaches, including trusted execution environments, zero-knowledge proofs, and privacy-preserving transformer architectures, mitigated composability gaps yet lacked full end-to-end assurance. Case studies at hospital and biobank scale illustrated practical feasibility and infrastructure demands. CONCLUSIONS: Situating PETs within technical and operational contexts clarifies their capabilities, limitations, and deployment challenges. Residual risks persist, including fairness concerns, inference-time leakage, and overreliance on PETs as compliance proxies. Sustained technical innovation and institutional governance remain essential for the trustworthy integration of PETs in biomedical AI.

biomedical AI

Privacy between physicians and patients: more than a matter of confidentiality.

This study examined patients' perceptions (N = 427) of the meaning of privacy within the physician-patient dyad. The recognition of the importance of privacy, the norms that govern privacy, and the specific behaviors that may be considered to violate privacy in relationships has most often received only general attention by researchers. Recent evidence from the field of communication supports the multidimensional and situational nature of privacy. Thus, in contrast to the usual conception of patient confidentiality as an issue focused on information, confidentiality is cast as a topic within both the informational and psychological realms of privacy. Implications for current medical interviewing practices, especially with regard to questions that concern patients' sexual behavior, are discussed.

Adolescent

PRISM-G: an interpretable privacy scoring framework for assessing risk in synthetic human genome data.

MOTIVATION: Synthetic genomic data promises broader data access, but unresolved privacy risks remain a major concern. Existing evaluations often rely on similarity-based metrics that measure proximity between real and synthetic genomes, overlooking additional mechanisms through which genomic information may leak. RESULTS: We introduce PRISM-G, a model-agnostic framework that quantifies privacy exposure in synthetic genomic data across three complementary components: proximity to real genomes in genetic-coordinate space, replay of familial or population-structure patterns, and trait-linked exposure through rare variants and membership-inference signals. These components are normalized and combined through a risk-averse aggregation into a single 0-100 PRISM-G score. By pairing PRISM-G with downstream utility metrics, the framework also enables analysis of privacy-utility trade-offs across generative models. We evaluated PRISM-G on synthetic cohorts generated by a generative adversarial network (GAN), a restricted Boltzmann machine (RBM), and a logic-based SAT solver (Genomator). Our results show that privacy vulnerabilities arise along different axes across models and marker densities, demonstrating that a single similarity-based metric is insufficient to characterize genomic privacy risk. AVAILABILITY AND IMPLEMENTATION: The source code of PRISM-G is available at https://github.com/alejocrojo09/prismg.

Humans

Privacy, security, and reliability risks of artificial intelligence in healthcare: a systematic review of empirical evidence.

BACKGROUND: Artificial intelligence (AI) is increasingly integrated into healthcare information systems, supporting clinical decision-making, imaging analysis, and predictive modeling. While these applications offer operational and clinical benefits, they also introduce emerging risks to patient privacy, data security, and system reliability. OBJECTIVE: To systematically review empirical evidence on privacy breaches, security vulnerabilities, and misuse associated with AI applications in healthcare settings. METHODS: PubMed, Embase, Web of Science, Scopus, IEEE Xplore, and ACM Digital Library were searched for empirical studies published between January 2015 and November 2025 that evaluated AI use or misuse in clinical diagnosis, treatment, or decision-making. Two reviewers independently screened studies and extracted data using a standardized form. Findings were synthesized narratively due to heterogeneity in study designs, AI methods, and reported outcomes. RESULTS: Of 7,285 records identified through database searches and 205 through citation screening, 22 empirical studies met the inclusion criteria, spanning multiple clinical domains and data modalities, predominantly medical imaging applications. Five recurring threat categories were identified: patient re-identification, membership inference, unauthorized access and adversarial exploitation, input manipulation, and misuse or overinterpretation of AI outputs. Across studies, AI models were shown to encode latent biometric signals across diverse data types, limiting the effectiveness of traditional anonymization and synthetic data approaches. Adversarial attacks and input manipulation were also shown to compromise diagnostic performance and system integrity. CONCLUSION: This systematic review provides empirical evidence suggesting that contemporary AI systems in healthcare introduce privacy and security risks that may challenge traditional assumptions about data protection. These findings underscore the need for privacy- and security-by-design approaches and governance frameworks that address risks across the AI lifecycle.

Humans

Supervision and privacy in psychotherapy training.

Supervision is an essential element of training in psychotherapy, and the issue of privacy in relation to the supervisory process is an important one. The authors examine the attitude toward privacy implicit in each of the two major models of supervision, the so-called didactic and countertransference models. They consider the ways in which supervision, particularly the countertransference model, and the use of audiovisual devices intrude on the privacy of the therapist and the therapy. Finally, they consider how the institutional and professional structures within which supervision takes place deal with the issue of privacy.

Attitude of Health Personnel

PRISM: privacy-preserving rare disease analysis using fully homomorphic encryption.

MOTIVATION: Rare diseases affect millions of people worldwide, yet their genomic foundations remain poorly understood due to limited patient data and strict privacy regulations, such as the General Data Protection Regulation (GDPR) (https://gdpr.eu/tag/gdpr/) in March 2025. These restrictions can hinder the collaborative analysis of genomic data necessary for uncovering disease-causing variants. RESULTS: We present PRISM, a novel privacy-preserving framework based on fully homomorphic encryption (FHE) that facilitates rare disease variant analysis across multiple institutions without exposing sensitive genomic information. To address the challenges of centralized trust, PRISM is built upon a Threshold FHE scheme. This approach decentralizes key management across participating institutions and ensures no single entity can unilaterally decrypt sensitive data. Our method filters disease-causing variants under recessive, dominant, and de novo inheritance models entirely on encrypted data. We propose two algorithmic variants: a multiplication-intensive (MUL-IN) approach and an addition-intensive (ADD-IN) approach. The ADD-IN algorithms minimize the number of costly multiplication operations, enabling up to a 17× improvement in runtime for recessive/dominant filtering and 22× for de novo filtering, compared to MUL-IN methods. While ADD-IN produces larger ciphertexts, efficient parallelization via SIMD and multithreading allows it to handle millions of variants in reasonable time. To the best of our knowledge, this is the first study that utilizes FHE for privacy-preserving rare disease analysis across multiple inheritance models, demonstrating its practicality and scalability in a single-cloud setting. AVAILABILITY AND IMPLEMENTATION: The source code and the data used in this work can be found in https://github.com/mdppml/PRISM.git.

Computer Security

Privacy-hardened and hallucination-resistant synthetic data generation with logic-solvers.

MOTIVATION: Machine-generated or synthetic data is a valuable resource for training artificial intelligence algorithms, evaluating rare workflows, and sharing data under stricter data legislations. However, current statistical and deep learning methods struggle with large data volumes, are prone to hallucinating scenarios incompatible with reality, and seldom quantify privacy meaningfully. RESULTS: Here, we introduce Genomator, a logic solving approach (SAT solving), which efficiently produces private and realistic representations of the original data. We demonstrate the method on genomic data, which arguably is the most complex and private information. We benchmark Genomator against state-of-the-art methodologies (Markov generation, Wasserstein Generative Adversarial Network and Conditional Restricted Boltzmann Machines), demonstrating a 40%-530% accuracy improvement and 57%-172% higher privacy. Genomator is also 3-100 times more efficient, making it the only tested method that scales to whole genomes. We show the universal trade-off between privacy and accuracy, and use Genomator's tuning capability to cater to all applications along the spectrum, from provable private representations of sensitive cohorts, to datasets with indistinguishable pharmacogenomic profiles. Demonstrating the production-scale generation of tuneable synthetic genomes hold great potential for balancing underrepresented populations in medical research and advancing global data exchange. AVAILABILITY AND IMPLEMENTATION: Genomator is available at https://github.com/csiro/genomator.

Algorithms

A Sociotechnical Approach to Genomic Data Privacy: A Comparative Analysis.

The sharing of genomic data across international borders presents significant privacy law challenges.Secured computed environments on smartphones allow the storing and processing of sensitive data without the underlying data being shared with processors.A novel technology, described here, to process genomic data within a secured computing environment seems to comport with EU and US privacy laws, despite their differing aims and rules.This technology suggests there may be technological solutions to privacy law fragmentation across jurisdictions, so long as data subjects socially trust the technology and have control over their data.

genome

Privacy-Preserving Linkage of Distributed Biological, Clinical, and Imaging Data Supporting Artificial Intelligence in Pediatric Oncology.

BACKGROUND: Cancer remains the leading cause of disease-related mortality in children over the age of one in Europe, with over 35,000 new pediatric cases and more than 6,000 deaths annually. Due to the rarity of pediatric cancers, clinical trial protocols often substitute for formal treatment guidelines, resulting in many children being enrolled in multiple trials, with biological samples and genomic data stored in various biobanks. Data collection in pediatric oncology is challenging, with sparse data acquired over extended periods, underscoring the need for optimal utilization of all available information through linked, privacy-preserving datasets. METHODS: Here, we report the development of a distributed, privacy-preserving data infrastructure for the PRIMAGE project, a European initiative aimed at supporting artificial intelligence (AI)-driven image analysis for pediatric cancer prognostics. The infrastructure leverages the European Patient Identity (EUPID) Services for Privacy-Preserving Record Linkage, enabling pseudonymized data integration across clinical, biological, and imaging sources. The system incorporates EUPID's hashing and phonetic matching protocols to pseudonymize patient identifiers and link distributed datasets, facilitating secondary data use in compliance with the General Data Protection Regulation. RESULTS: Data from over 700 neuroblastoma patients from European trials and hospitals were linked and uploaded to the PRIMAGE platform, where AI models predict clinical outcomes. CONCLUSION: This infrastructure successfully facilitated AI model development, advancing pediatric oncology research, and offering a scalable framework for future European health data initiatives, such as the European Health Data Space.

Journal Article

Balancing the scales of public interest: medical research and privacy.

Guidelines for the protection of privacy in the conduct of medical research have been issued by the National Health and Medical Research Council, approved by the Commonwealth Privacy Commissioner, and gazetted on 1 July 1991 (Commonwealth of Australia Gazette No. P19) to remain in force until 30 June 1994. This paper examines the guidelines and seeks to inform researchers, institutional ethics committees and the institutions those committees represent of their content. Responsibilities are placed upon those engaged in the conduct of research and those involved in undertaking ethical review who now have to decide that the public interest in conducting the research substantially outweighs the public interest in privacy. There is also an emphasis on the requirement for surveillance of research projects by institutional ethics committees which has not previously been apparent. Questions are posed to assist in deciding whether a particular research protocol is subject to the guidelines.

Australia

Computerized databases: privacy issues in the development of the nursing minimum data set.

Nursing leaders promoting the development and use of computerized databases such as the Nursing Minimum Data Set (NMDS) have not adequately addressed the complex ethical issues involved with computerized information systems. The purpose of this article is to describe the privacy issues involved with the NMDS. Moral considerations and principles guiding resolution of ethical issues concerning violations of patient privacy are discussed. A paradigm case is used to demonstrate the significance of privacy violations in computerized databases. Two security systems currently being considered in other disciplines are included for their relevance to the development of the NMDS. The broader implications concerning the impact of technology on preservation of human dignity and the quality of life are addressed.

Biomedical Research

Impact of a privacy panel on the behavior of caged female rhesus monkeys living in pairs.

Thirty paired female rhesus monkeys were tested in a control situation when companions had no privacy, and in an experimental situation when they were offered the option to move behind a panel and be alone. Paired partners spent significantly more time in close proximity (same half of the cage) when the privacy panel was provided (means with panel = 76.0%/h vs. means no panel = 60.8%/h; p less than 0.005). At the same time, they were more engaged in affiliative interactions (means with panel = 37.4%/h vs. means no panel = 26.5%/h; p less than 0.025) while the incidence of agonistic interactions tended to decrease (means with panel = 0.3/h vs. means no panel = 2.2/h; p less than 0.1). It was concluded that rhesus monkeys have a need for companionship. They prefer to stay in close proximity with a compatible partner even though this may reduce their available cage space. It was further concluded that companions have no need for prolonged periods of visual seclusion, but occasional privacy is beneficial for their relationship.

Animals