{"id":"2fd54f70-f65e-41ef-8237-01b7a624eb04","arxiv_id":"2608.07705","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"This review proposes a two-dimensional privacy risk framework for clinical foundation models, then analyzes whether current US and EU law can handle the leakage risks.","lead":"Foundation models trained on patient data can leak private information through their outputs, even when trained on de-identified records. The paper proposes a two-axis framework for assessing such leakage risk and maps it to US and EU privacy law.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The two-axis framework is internally inconsistent: 'leaked information' depends on prior information, so the axes are not orthogonal and the 'continuous risk' claim lacks a well-defined basis.","rationale":"The reader's weakest_assumption identified orthogonality and joint sufficiency as load-bearing, and my analysis confirms this with a concrete internal inconsistency. The central claim of the paper is that model-mediated leakage is poorly addressed by existing frameworks and that privacy risk is continuous rather than categorical; the two-axis framework is the paper's main technical contribution meant to support both claims. If the axes are not orthogonal, the framework cannot serve as a valid 'risk space,' and the policy recommendation derived from it loses its foundation. This is not a matter of disagreement with current consensus; it is an internal tension between the definitions in Section 3 and the context-relative identifiability doctrine the paper itself invokes in Appendix A and Table 2. The concrete test isolates this tension using the paper's own S1 example, requiring no external data. I agree with the reader that the framework is proposed as a validation target, but the issue is stronger: the framework is currently self-inconsistent. Therefore the paper should be accepted only if the authors either (a) reformulate Axis II so that leaked-information classification is independent of recipient capability, e.g., by fixing a threat model or defining sensitivity of the artifact itself, or (b) explicitly retract the orthogonality/sufficiency claims and present the framework as a qualitative checklist rather than a formal risk space. The legal analysis and scenario catalog remain valuable independent of the framework, so conditional acceptance with this required revision is appropriate.","tokens_in":21250,"tokens_out":8813,"duration_ms":79406,"concrete_test":"Apply the framework to scenario S1 while holding the model and output fixed. Consider two recipients of the same leaked near-replica MRI: (a) a recipient with no auxiliary information, and (b) a recipient who knows the model was trained on MRIs from a rare tumor clinic. Classify the leaked information under Axis II in both cases using the definitions in Section 3. If (a) yields 'linkable personal information' and (b) yields 'identifiable personal information,' then the y-coordinate changes with the x-coordinate, empirically falsifying the orthogonality claim without any new experiments.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"Section 3 introduces the framework as characterizing leakage along 'two orthogonal axes': prior information (Axis I) and leaked information (Axis II). The paper's own definitions make Axis II depend on Axis I. Axis II classifies data as 'identifiable personal information' if it 'could render an individual identifiable' (Section 3, Axis II). Yet the paper elsewhere adopts a context-relative account of identifiability (Appendix A, CJEU C-413/23), under which identifiability depends on the recipient's capabilities and auxiliary information. Consequently, the same leaked artifact changes category along Axis II purely as a function of the prior information available along Axis I. Example: in S1, a near-replica brain MRI is 'linkable personal information' for a recipient without cohort knowledge, but becomes 'identifiable personal information' if the recipient knows the model was trained on MRIs from a rare tumor clinic. The model output is identical; only the x-axis context changes. Thus the axes do not define an independent space. This is an internal inconsistency, not merely an unvalidated empirical claim. Moreover, the central conclusion that 'privacy risk is continuous rather than categorical' is not operationalized: the framework provides three coarse prior-information tiers and two leaked-information tiers, which is categorical, and no metric or aggregation rule is defined. The legal recommendation to move beyond identifiability therefore rests on the framework, but the framework's foundational orthogonality and sufficiency claims are unsupported and contradicted by its own example analysis.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This preprint argues that existing privacy frameworks (HIPAA, GDPR, and the EU AI Act) are underspecified for model-mediated privacy leakage from clinical foundation models. The authors propose a two-axis framework: Axis I is the prior information required for leakage (no/public information vs. linkable personal information), and Axis II is the type of leaked information (linkable vs. identifiable personal information). Six leakage scenarios are presented across local deployment and public release, mapped to GDPR/AIA roles and analyzed under U.S. and EU law. The paper concludes that privacy risk in foundation models is continuous and context-aware rather than categorical, and recommends complementary technical and legal mitigations, including DP, auditing, machine unlearning, and regulatory reform.","tokens_in":21538,"tokens_out":7625,"duration_ms":77215,"significance":"The legal analysis is careful, well-cited, and appropriately caveated, particularly on HIPAA's 'actual knowledge' provision and the untested status of privacy torts for generative-AI leakage. The six scenarios are concrete and cover distinct deployment pathways, and the paper is transparent about the absence of custom code or empirical data. If the two-axis framework could be made operational, it would bridge technical leakage auditing and legal privacy categories in a useful way. However, the framework is asserted rather than derived, and its central claims of orthogonality and continuity are internally inconsistent as stated. These issues are load-bearing because the framework is the manuscript's main contribution, so the paper requires substantial revision before the framework can support its conclusions.","major_comments":[{"comment":"The framework's claim that Axis I and Axis II are 'orthogonal' is contradicted by the paper's own definitions. Axis II classifies leaked information as 'identifiable personal information' if it 'could render an individual identifiable,' and identifiability depends on the recipient's prior and auxiliary information, as the paper itself recognizes in Appendix A's discussion of CJEU Case C-413/23. Consequently, the same leaked artifact shifts between Axis II categories as Axis I changes. In S1, for example, a near-replica brain MRI is 'linkable personal information' for a recipient without cohort knowledge but becomes 'identifiable personal information' if the recipient knows the model was trained on MRIs from a rare tumor clinic; the model output is identical. Section 6 repeats the error when it states that differential privacy reduces 'vertical movement on axis II ... regardless of prior knowledge.' The two axes therefore do not define an independent risk space, and conclusions built on that orthogonality lack a well-defined basis. This is an internal definitional problem, not merely an absence of empirical validation.","section":"Section 3, Figure 1b; Appendix A"},{"comment":"The central conclusion that 'privacy risk in these systems is continuous rather than categorical' is not operationalized. The framework provides two coarse tiers on Axis I and two on Axis II, so placing scenarios at one of four combinations is categorical, and no metric, ordering, or aggregation rule is defined that would make risk continuous. Section 3's statement that the framework 'is designed to focus on cases where the sensitivity of the leaked data is higher than the required prior information' gestures at a composite ordering but does not define it. The paper therefore cannot support its recommendation that legal standards 'evolve to better reflect gradations' (Section 7). A revision should either define a precise risk measure over the two dimensions and state how to elicit it, or soften the continuity claim to a claim about context-dependence and graded severity.","section":"Sections 3 and 7"},{"comment":"The framework's claim to characterize privacy risk in a two-dimensional space is further undermined by the paper's own concession that 'other factors, such as model architecture, scale, and training procedures, further affect leakage possibility, shaping the risk that sensitive medical details could be reproduced or inferred.' If these factors materially alter leakage possibility, then prior information and leaked information are not jointly sufficient to determine privacy risk, and the promised two-dimensional assessment is incomplete. The manuscript does not explain how these acknowledged factors are to be folded into Axis I or Axis II, nor why they can be treated as outside the framework.","section":"Section 3"}],"minor_comments":[{"comment":"Several copy-paste artifacts undermine the reliability of the scenario corpus: S4's training-data row repeats S3's wording exactly ('Trained on de-identified patient notes and finetuned on identifiable discharge summaries'), S4's privacy-risk analysis embeds a leftover prompt fragment ('draft the likely recent timeline to support handoff') in the running text, and S5 lists 'Clinical language support' as the intended use although the scenario concerns a histopathology embedding model.","section":"Table 2"},{"comment":"The sentence 'In such settings, fine-tuning can use identifiable or de-identifiable.' is incomplete and should be finished or removed.","section":"Section 2"},{"comment":"The GDPR/AIA analysis contains a grammatical error ('The hospital, as controller and must ensure...') and the preceding paragraph has 'renewing conset' instead of 'renewing consent.'","section":"Section 5, S6"},{"comment":"The reference to CJEU Case C-413/23 should include the case name and year, as the docket number alone is less informative to readers outside EU law.","section":"Appendix A"}],"recommendation":"major_revision","confidential_remarks":"For the editor: the manuscript is best read as a legal-policy perspective with a technical framing. The stress-test concern about non-orthogonality is valid and should be addressed before publication; the legal analysis itself is sound and could stand even if the framework's more ambitious claims are substantially revised. I see no issues of citation or scope beyond the usual, and the authors' disclosure that no code or data were generated is appropriate for this type of work."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Read the paper. The legal analysis is the real contribution; the two-axis framework is a useful organizing device but the paper overclaims its rigor. The HIPAA/GDPR/AIA walk-through, especially the point that model-mediated leakage falls between the cracks, is carefully done and worth engaging. The six scenarios are concrete and will be useful for teaching and for anyone drafting risk assessments. The mitigation section is sensible, if standard.\n\nNow the soft spots. The orthogonality claim in Section 3 doesn't hold. Axis II classifies leaked information as identifiable when it could render an individual identifiable, and the paper itself adopts a context-relative account of identifiability (Appendix A, CJEU C-413/23). Under that account, whether a leaked artifact is linkable or identifiable depends on the recipient's auxiliary information, which is Axis I. The S1 example makes this concrete: a near-replica brain MRI is linkable for a recipient without cohort knowledge but identifiable if they know the training cohort is a rare tumor clinic. Same output, different Axis II category depending on Axis I. So the axes are not independent, and the framework's claim to define a space of risks is weaker than presented. This doesn't sink the legal analysis, but it means the framework should be presented as a heuristic, not a validated instrument.\n\nRelatedly, the 'continuous rather than categorical' conclusion is not operationalized. The framework gives three prior-info tiers and two leaked-info tiers; that is categorical. No metric, ordering, or aggregation rule is defined. If the authors want to claim continuity, they need to say what quantity varies continuously.\n\nAlso, Table 2 has copy-paste artifacts: S4's training data row duplicates S3's ('fine-tuned on identifiable discharge summaries'), and S5's intended use reads 'clinical language support' when the scenario is membership inference. Minor, but needs cleanup before publication.\n\nWho this is for: people working on governance of medical AI, privacy auditors, and policy folks. It is a perspective paper, not a technical result. It deserves a serious referee: the legal synthesis is good enough to warrant publication with revision, even though the framework needs reframing. I'd recommend conditional accept with the orthogonality claim softened and the continuity language either defined or dropped.","headline":"Useful legal synthesis and concrete scenarios, but the two-axis framework overclaims orthogonality and the continuity conclusion isn't supported.","tokens_in":22030,"tokens_out":2446,"would_cite":true,"duration_ms":23059,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Privacy risk in clinical foundation models is continuous rather than categorical, and laws built for static data handling — HIPAA in the US and the GDPR in the EU — give limited guidance for leakage that happens through the model itself.","keywords":["privacy risk","clinical foundation models","model-mediated leakage","re-identification","memorization","HIPAA","GDPR","EU AI Act"],"falsifier":"A concrete check would be a systematic audit of deployed clinical foundation models in which leakage incidents are scored on both axes and against actual re-identification outcomes: if two incidents at the same two-axis coordinates produce materially different real-world harms, or if any documented leakage event cannot be placed on either axis, the claim that the axes are orthogonal and jointly sufficient would be refuted. A lighter test would ask whether any scenario the framework ranks as low risk has already produced a documented patient re-identification.","tokens_in":21101,"feed_emoji":"🛡️","tokens_out":9511,"duration_ms":75764,"temperature":0.7,"pith_summary":"This paper argues that the dominant privacy threat from clinical foundation models is no longer the handling of patient records but what the trained model itself reveals: models can reproduce memorized images, notes, or diagnostic details that enable patient re-identification even when the training data was de-identified. It claims that existing US and EU frameworks — HIPAA, the GDPR, and the EU AI Act — were built to govern static data handling and therefore give little practical guidance for this indirect, model-mediated leakage. The paper proposes a two-axis framework for assessing such risk: how much prior information a user needs to trigger a leak, and how sensitive the leaked information is. If the paper is right, privacy assessment should be continuous and context-aware, tied to realistic deployment scenarios rather than to the binary question of whether data was anonymized.","feed_headline":"Medical AI leaks patient data that HIPAA and GDPR miss","feed_subtitle":"Medical AI can reproduce patient data; two axes map how much prior knowledge a leak needs and how sensitive the leak is.","key_machinery":"The load-bearing object is the paper's two-dimensional privacy-risk framework (Figure 1b). Axis I — prior information — runs from no prior or publicly accessible information up to linkable personal information such as a medication list or a single diagnostic test; Axis II — leaked information — runs from linkable personal information up to identifiable personal information such as a near-verbatim clinical note. The framework's job is to locate every leakage scenario at a coordinate, so that risk is read jointly: leakage that requires little prior knowledge and reveals identifiable information sits at the top of the risk space, and mitigation is calibrated to that position. The six illustrative scenarios are the concrete carriers of the argument: they connect the axes to real deployment channels (institutional fine-tuning versus APIs, web interfaces, and open weights) and to the legal analysis, since each scenario is checked against GDPR roles and obligations and against AI Act high-risk classification.","core_discovery":"The paper's central claim is that privacy risk in clinical foundation models is continuous rather than categorical, and that the right unit of analysis is the joint position of a leakage event on two orthogonal axes: the prior information required to elicit the leak, and the type and sensitivity of the information leaked. The highest-risk events are those that need little or no prior information and yet yield linkable or identifiable personal information — for example, a generic prompt that produces a near-replica of a training brain MRI, or an autocomplete that copies another patient's phone number and name into a chart. Through six scenarios spanning local hospital deployment and public release (reconstruction, memorization, leaked autocompletion, autocompletion, membership leakage, and secondary use), the paper shows that identical model behavior can carry very different risk depending on who can query the model and what auxiliary data they can combine with its outputs. Mapping the scenarios onto HIPAA, the GDPR, and the EU AI Act, it finds the legal frameworks underspecified: obligations attach to disclosure of personal data, yet models frequently leak probabilistic, fragmentary, or membership-level signals that fall short of explicit record release. The conclusion is that identifiability alone is too blunt a legal trigger, and that regulation should evolve toward context-aware assessment that weighs prior information and leaked information together.","pith_inferences":["If the continuous-risk claim is right, the all-or-nothing legal category of 'personal data' becomes a poor regulatory trigger; a testable extension is whether regulators can define graduated duties that scale with the two-axis risk coordinate rather than with identifiability alone.","The framework implies a concrete, comparable benchmark: report each deployed model's 'leakage threshold profile' — the minimum prior information that elicits linkable or identifiable output in each scenario class — so that risk can be compared across models and releases.","The orthogonality assumption is itself testable: a corpus of leakage attempts that vary prior information and output sensitivity independently could reveal whether the risk surface is genuinely two-dimensional or whether the axes interact, for example if highly sensitive leaks systematically require more prior information than the framework assumes."],"forward_implications":["Risk assessment for clinical foundation models should shift from certifying that training data was de-identified toward deployment-specific evaluation of what the model can be made to reveal and who can plausibly elicit it.","A model trained on de-identified data can still expose patients: near-replica MRI generation, verbatim note reproduction, and membership inference in cohort-specific models each constitute disclosure that data-handling controls alone do not prevent.","The same model behavior can be a minor nuisance in one deployment and a serious breach in another, so governance terms such as licenses, API controls, and interface design should be treated as part of the privacy control surface.","Because data embedded in model weights is difficult to remove, secondary-use scenarios create an unresolved tension with erasure rights such as GDPR Article 17, and the paper's analysis implies that upstream consent and purpose limitation deserve more weight than post-hoc unlearning.","Differential privacy primarily limits what a model can reveal regardless of prior knowledge, while larger and more diverse training cohorts dilute the exposure of any individual record — so mitigation choices should be matched to where on the two axes a scenario falls."],"supporting_citations":[{"why":"Establishes that re-identification can succeed even on de-identified records, the baseline threat model the paper's leakage analysis extends.","marker":"[Benitez and Malin, 2010]"},{"why":"Supplies the foundational evidence that neural networks memorize training data and can be prompted to reveal it, grounding the memorization and reconstruction scenarios.","marker":"[Carlini et al., 2019]"},{"why":"Documents unconditional latent-diffusion models reproducing patient imaging data, the direct evidence behind the S1 reconstruction scenario.","marker":"[Dar et al., 2025]"},{"why":"Shows that synthetic and de-identified data remain linkable and re-identifiable, supporting the linkable-information tier on the leaked-information axis.","marker":"[Stadler et al., 2022]"},{"why":"Demonstrates deep-learning-based patient re-identification from chest X-rays, evidence that reconstructed de-identified records can become identifiable.","marker":"[Packhäuser et al., 2022]"},{"why":"Argues that the GDPR's anonymisation and safeguards tests are quantitatively underspecified, the legal-gap claim this paper applies to clinical foundation models.","marker":"[Holzenberger and Maxwell, 2025]"},{"why":"Analyzes how identifiability shifts across actors in multi-party processing, underpinning the paper's actor-relative reading of GDPR in its scenarios.","marker":"[Cobbe, 2026]"},{"why":"Shows membership-inference risk concentrates on rare and atypical samples, supporting scenario S5 and the mitigation emphasis on large, diverse training cohorts.","marker":"[Kulynych et al., 2022]"}],"fun_headline_variants":["Clinical AI can leak patient data that laws miss","Two axes reveal privacy risk in medical AI","When AI reproduces patient data: a legal blind spot","A practical framework for clinical AI privacy"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The framework's load-bearing premise is that the two axes — prior information needed to trigger a leak and sensitivity of what is leaked — are independent of each other and together cover every meaningful way a clinical foundation model can compromise patient privacy; if a real leakage route falls outside this space, or if the two dimensions interact in ways the framework does not model, its risk rankings lose their grounding.","fun_headline_variants_meta":{"raw":{"variants":["Clinical AI can leak patient data that laws miss","Two axes reveal privacy risk in medical AI","When AI reproduces patient data: a legal blind spot","A practical framework for clinical AI privacy"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000198,"raw_usage":{"total_tokens":1358,"prompt_tokens":924,"completion_tokens":434,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":540,"completion_tokens_details":{"reasoning_tokens":376}},"tokens_in":540,"tokens_out":434,"duration_ms":4470,"temperature":1.0,"reasoning_tokens":376,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T00:21:40.161905+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete check would be a systematic audit of deployed clinical foundation models in which leakage incidents are scored on both axes and against actual re-identification outcomes: if two incidents at the same two-axis coordinates produce materially different real-world harms, or if any documented leakage event cannot be placed on either axis, the claim that the axes are orthogonal and jointly sufficient would be refuted. A lighter test would ask whether any scenario the framework ranks as low risk has already produced a documented patient re-identification.","supporting_citations":[{"cited_title":"Proceedings on Privacy Enhancing Technologies , volume =","cited_arxiv_id":null,"evidence_quote":"Shows membership-inference risk concentrates on rare and atypical samples, supporting scenario S5 and the mitigation emphasis on large, diverse training cohorts."}],"review_version":1}