🚨 124 Papers. Clinical AI Models Built on Data of Unknown Origin A new analysis linked more than 100 peer-reviewed studies to two widely used stroke and diabetes datasets with unknown origins and data patterns inconsistent with real patients. Some downstream models may already have reached clinical or public-facing settings. Open data sharing is critical for AI progress. But in clinical AI, openness without provenance is not transparency. Three points matter for implementation: • Dataset provenance is part of model validity If the origin, collection process, and population are unclear, performance metrics are not interpretable. • Robust dataset evaluation should be standard Basic checks (missingness patterns, value distributions, duplication) can already flag non-credible data. • External validation is not optional Models should be tested across independent external datasets. 👉 What should be the minimum standard before a clinical prediction model is considered deployable?
Patient Data Security
Explore top LinkedIn content from expert professionals.
-
-
I used Google Forms for my bachelor’s research. And now I realize I shouldn’t have. Not because I was careless, but because I didn’t know better. None of us did. In India, almost every psych or social work student I knew used Google Forms. It was free, easy, and accessible. We thought we were doing it right. But once I started my master’s in Germany, I noticed something strange: No one here uses Google Forms. Not even for tiny surveys. Why? Google stores form responses on servers mostly located in the U.S, meaning researchers outside the U.S have little control over where their participants’ data goes or how it’s protected. When you’re collecting personal or sensitive information, this lack of control becomes a serious ethical and sometimes legal concern. That hit me hard. Back then, people trusted me with their stories. And I unknowingly put that trust at risk. I’m not sharing this to blame anyone. I’m sharing it because we’re often not taught what ethical research actually looks like. So here’s what I wish someone had told me earlier: If you’re collecting data from people, especially in psychology or social work, privacy is not optional. There are a few alternatives available: 🔹 Zoho Survey: Free, Indian company, better data protection. 🔹 LimeSurvey: Open-source, widely used in academia. 🔹 Nextcloud Forms: Privacy-first, great if your institution supports it. 🔹SurveySparrow : Also based in India. Good if you're not collecting highly sensitive data. 🔹Jotform: If you want a form builder that feels like Google Forms but with more control. Just double check where the data is stored. And if you must use Google Forms: • Be transparent: Let the participant know where their data would be stored • Avoid collecting sensitive info • Download and delete data from the platform ASAP Research is not just about responses. It’s also about respecting the people who respond. If you’re a student reading this, I hope this helps you to take one step closer to doing research that’s not just smart, but safe.
-
🚨 Ghosts SOC – A Next-Generation Threat Intelligence Based SOC for Healthcare As part of our second year engineering curriculum at ESPRIT (Ecole Supérieure Privée d'Ingénierie et de Technologies) (Network Infrastructure & Data Security), we conducted a full-year capstone project: the design, deployment, and audit of a Next-Generation SOC tailored for the healthcare sector. The project followed a five-stage technical lifecycle and adheres to HIPAA and GDPR requirements — ensuring both patient safety and regulatory compliance. 🔐 1. Architecture Design We built a segmented, virtualized environment using pfSense, VLANs, DMZs, VPN IPSec, and honeynets — simulating a real-world hospital network. 🔎 2. SIEM Integration (ELK Stack + Wazuh) We deployed a log analytics and correlation engine to detect behavioral anomalies across all systems — EDR (Wazuh agents), firewalls, DNS, and Sysmon for domain controllers. We developed custom dashboards, compliance alerts, and detection rules adapted to healthcare threats. ⚙️ 3. SOAR Automation The combination of TheHive, Cortex, and Shuffle allowed us to automate incident triage, IOC enrichment, and response escalation. This enhanced our understanding of incident workflows and allowed us to design real-world playbooks (MITRE ATT&CK aligned). 🧠 4. Threat Intelligence Platform We engineered our own CTI solution based on our ML models, able to enrich, classify, and prioritize threat indicators. 🛡️ 5. Adversarial Audit We performed a structured audit of another group’s banking SOC, using real-world frameworks (NIST CSF, ISO 27035, PCI DSS). 💡 Key Takeaways & Added Value: ✔ Mastery of SIEM, SOAR, EDR, NDR and CTI toolchains ✔ Experience in designing secure virtual environments from scratch ✔ Deep understanding of healthcare-specific threat models ✔ Practice in compliance, documentation, and incident response ✔ Strong teamwork, technical communication, and project coordination over 8+ months This project was conducted under the guidance of Mrs. Fatma Louati and Mr. GHORBEL Ali and the general supervision of Mrs. Marwa CHAMEKH , Ph.D Thanks to my teammates Zeid Chouaieb , Rihem akkari , Souhail Aouadi and Gregoire Emmanuel EFFA MESSI Ghosts SOC is more than an a academic project, it’s the foundation of our readiness to join real-world SOC teams and contribute to cybersecurity innovation in healthcare and beyond. #SOC #SIEM #SOAR #CTI #Cybersecurity #Wazuh #ElasticStack #pfSense #TheHive #Cortex #Shuffle #ESPRIT #ThreatIntelligence #HIPAA #GDPR #HealthcareSecurity #Engineering #CapstoneProject #RedTeam #BlueTeam #NIST #MITREATTACK
-
+2
-
For better patient care, the ability to make data-driven decisions fast is everything. Imperial College Healthcare NHS Trust cut the process of accessing and preparing data from months to just days using the Snowflake AI Data Cloud. Tapping into a secure, unified platform allows their clinicians and researchers to collaborate seamlessly. Plus, they use the Snowflake Marketplace to tap into external data (like weather) to proactively predict demand (e.g., asthma spikes) to optimize their emergency services. 🔎 See how they're transforming healthcare: https://lnkd.in/gBQ4YbWb
-
Our health system still spends too much time moving and cleaning data across systems that weren’t designed to work together. That fragmentation slows providers, delays care, and limits our ability to deliver truly coordinated treatment. At Elevance Health we built Health OS to change that. It’s a bi-directional clinical data interoperability platform that securely connects systems and standardizes data—making it accessible, actionable, and AI-ready with privacy and security at the core. With AI and digital technologies, guided by human oversight, we’re replacing repetitive, disconnected work with intelligent systems that anticipate needs, automate routine tasks, and help care teams act faster. In the article below, Jeff Plante and I share how Health OS enables seamless information flow across providers, health plans, and member experiences—supporting earlier intervention, better coordination, and more proactive care at the right time. https://lnkd.in/gqx3UFfd
-
Ai innovation without physician oversight puts patients at risk! Last week, Utah launched a pilot program allowing an artificial intelligence tool to autonomously renew certain prescription medications without physician oversight. While innovation in health care is essential, this approach raises serious concerns about patient safety, clinical accountability, and the future of medicine. At the American Medical Association, we believe AI can be a powerful tool to support physicians. But medicine is not a simple equation. Every medication carries risks and benefits. Determining whether a prescription should be renewed often requires clinical judgment: reviewing a patient’s evolving symptoms, assessing side effects, considering drug interactions, and, in many cases, ordering or interpreting laboratory tests. These are not optional steps; they are fundamental to safe, high-quality care. Removing physicians from this decision-making process ignores the reality that patients change over time. What was appropriate six months ago may no longer be safe today. AI tools, no matter how sophisticated, lack the full clinical context and accountability required to make these determinations independently. Here’s the big-picture concern: This kind of legislation is the first step down a slippery slope. What may seem limited and low-risk today can quickly fast-track us toward agentic AI – systems making increasingly complex clinical decisions without human oversight. Once physicians are removed from one decision, it becomes easier to remove them from the next. There is a better way forward. AI should be designed to augment physicians, not replace them — flagging concerns, prompting necessary labs, and supporting clinical decisions while keeping a licensed clinician firmly in the loop. Responsible innovation means pairing technology with appropriate oversight, clear standards, and rigorous evaluation. Innovation must move health care forward, not around the safeguards that protect patients. We can embrace and maximize the opportunity of AI while maintaining the human judgment that lies at the heart of medicine. #ai #aihealth #prescribing #utah #prescriptionsrenewal
-
🚨 I’m excited to share OpenMed open-sourced 35 state-of-the-art PII detection models for HIPAA- and GDPR-aligned compliance. All Apache 2.0 licensed. All free. Forever. 🍀 Why This Matters Healthcare AI has a privacy problem. Before you can use clinical data for research, training, or analytics, you need to strip out sensitive information, names, SSNs, medical record numbers, addresses, and dozens of other identifiers. Most organizations either: - Pay for expensive commercial solutions - Build half-baked regex patterns - Skip de-identification entirely (yikes) I wanted to change that. What OpenMed Built 35 fine-tuned models supporting HIPAA, GDPR, and privacy compliance, spanning every major transformer architecture: - DeBERTa-v3 (the top performer at 96.08% F1) - RoBERTa, ModernBERT, XLM-RoBERTa - Biomedical specialists: BioClinical-ModernBERT, Bio_ClinicalBERT, Clinical-Longformer - Embedding models adapted for NER: BGE, E5, Snowflake Arctic, GTE 54 PII entity types covering: - Personal identifiers (SSN, passport, medical record numbers) - Contact information (emails, phones, addresses) - Financial data (bank accounts, credit cards) - Network identifiers (IP addresses, MAC addresses) - And much more... Sizes from 33M to 600M parameters pick the right trade-off between accuracy and inference speed for your use case. The Results OpenMed's top 10 models all exceed 95.7% F1. That's production-ready accuracy for automated de-identification pipelines. Enterprise Scale, On-Premise These models run entirely in your environment. No data leaves your infrastructure. - Regulatory-grade accuracy for Expert Determination under HIPAA Safe Harbor - Process billions of records using PySpark, Ray, or batch pipelines - Consistent obfuscation and tokenization for downstream analytics - No API calls, no cloud dependencies deploy on air-gapped systems if needed But here's what I'm most proud of: every single model is Apache 2.0 licensed. No gates. No waitlists. No "contact sales for pricing." Healthcare AI safety shouldn't be paywalled. De-identification tools should be a public good. Browse the full collection on Hugging Face: https://lnkd.in/eFqa_Ccp If you're working on healthcare AI, clinical NLP, or privacy-preserving ML, these models are for you. Star them, fork them, build something. 🔥 The community grows stronger when we build in the open. 🤗
-
The draft of the new HIPAA cybersecurity rules dropped today, and it includes some major changes. 11 Big takeaways in proposal: 1) Enhanced Risk Management: 1.a) Formalizes and expands the risk analysis process to include evolving threats like ransomware and supply chain vulnerabilities. 1.b) Mandates comprehensive documentation of risk management activities, ensuring organizations take a more proactive and structured approach. 2) MFA required for all remote access systems containing ePHI 3) Mandates regular technical vulnerability assessments, such as penetration testing, to identify and mitigate security gaps 4) Requires encryption of ePHI at rest and in transit, adhering to NIST-recommended standards 5) Requires a formalized incident response plan with clear steps for detecting, containing, mitigating, and reporting incidents involving ePHI. 6) Formalizes supply chain risk management by requiring risk assessments for third-party vendors and integrating cybersecurity requirements into contracts and vendor oversight. 7) Mandates tailored cybersecurity training for specialized roles, such as incident response teams or system administrators. 8) Requires designated cybersecurity governance structures, ensuring accountability for cybersecurity policies and strategies. 9) Requires continuous monitoring tools and enhanced logging capabilities to detect and respond to anomalous activity. 10) Expands disaster recovery planning to specifically address cybersecurity considerations, including ransomware scenarios. 11) Updates and clarifies definitions to align with modern threats and technology, ensuring clearer compliance expectations and expanding scope to fit modern threat landscapes. #HealthcareCompliance #cybersecurity #riskmanagement #healthtech Link to proposed changes in comments 👇
-
I paused my ambient AI scribe mid-visit last week. Not because it failed. Because my patient stopped talking the way she used to. She glanced at the computer before answering my question about her housing. She shortened her response. She moved on. I have seen this pattern before, and not just once. Language concordance is one of the most effective tools in primary care. When I speak to a patient in Spanish without an interpreter, more context surfaces. More truth. But for patients who are undocumented, a recording device is not neutral. It is a risk variable. And the technology that helps me document better can undermine the trust that makes the visit work in the first place. The same tool that reduces cognitive load in one room creates harm in another. Not because the AI is different. Because the room is different. I now pause the scribe deliberately before any conversation that touches immigration status, housing instability, or intimate partner violence. I say it in Spanish: "Voy a pausar esta herramienta para que hablemos en privado." My patients visibly relax. That reaction tells me everything. I dig into this tension, the ethics of ambient AI in safety-net settings, and what informed consent actually requires in this week's MedTechxHeart. Do you pause your scribe in certain visits? What would it take for your clinic to have this conversation honestly? Read the full analysis: https://lnkd.in/ghzcedVT If this reflects what you are seeing in your own exam rooms, share it. #DigitalHealth #HealthEquity #FamilyMedicine #AIinPrimaryCare
-
AI in healthcare poses unique patient safety risks, but this study proposes 14 practical software design requirements to reduce them, structured around reliability, transparency, traceability, and responsibility. 1️⃣ AI systems should undergo continuous performance evaluation post-deployment, not just during development. 2️⃣ Usability testing and strong cybersecurity measures (e.g., encryption, field-tested libraries) are essential for real-world safety. 3️⃣ Semantic interoperability with EHRs (using HL7 or openEHR) ensures AI integrates smoothly into clinical environments. 4️⃣ An AI passport, a kind of datasheet explaining purpose, context, training, and known biases, boosts transparency. 5️⃣ Explainable AI (XAI) tools and bias detection techniques help clinicians trust and validate model outputs. 6️⃣ Assessing data quality across multiple dimensions (e.g., completeness, temporal stability) is key for safe AI predictions. 7️⃣ Traceability requires user access logs, audit trails, and regular case reviews to catch issues early. 8️⃣ Regulatory compliance checks, academic-use disclaimers, and clinician sign-offs clarify responsibility and legal status. 9️⃣ A sector survey of 216 professionals (clinicians, technicians, users, and decision-makers) rated these requirements as essential, especially AI explainability, data quality, audit trails, and regulatory safeguards. 🔟 Clinicians valued practical protections (e.g., performance tracking, encryption) more than technicians, while users rated transparency tools (e.g., AI passport) higher than decision-makers. ✍🏻 Juan M Garcia-Gomez, Vicent Blanes Selva-Selva, Celia Alvarez Romero, Jose Carlos de Bartolomé Cenzano, Felipe Pereira, Alejandro Pazos, Ascensión Doñate-Martínez. Mitigating patient harm risks: A proposal of requirements for AI in healthcare. Artificial Intelligence in Medicine. 2025. DOI: 10.1016/j.artmed.2025.103168