started · updated
AI and cybersecurity pose growing risks to patient privacy in hospitals
The integration of artificial intelligence in hospitals is driving significant advancements in medical imaging and clinical decision support, but it introduces critical risks to patient privacy. Research indicates that seemingly anonymous medical data, such as electrocardiograms, X-rays, and MRIs, can act as biometric identifiers. Some AI models have demonstrated the ability to reconstruct patient faces from skull scans or identify individuals through retinal images, with re-identification rates in certain studies ranging from 26% to as high as 94%.
Parallel to privacy concerns, the healthcare sector faces escalating cybersecurity threats. According to the European Union Agency for Cybersecurity (ENISA), ransomware is the primary threat, accounting for 54% of analyzed incidents in the sector. These attacks do not only disrupt hospital operations and patient care continuity but also target the theft or disclosure of sensitive clinical data. To balance the need for large datasets to train AI and conduct clinical research with the necessity of data protection, the use of synthetic data is being explored as a potential model for innovation and security.