Loading Curie Briefs...
Getting the latest healthcare news for you
Getting the latest healthcare news for you

Hospitals are fixating on whether AI models were trained on patient data — but that's the wrong question. A one-size-fits-all privacy review can simultaneously under-govern risky generative AI and over-restrict narrow, low-risk models. Experts argue smarter, architecture-aware governance is the real path to protecting patients.
Hospital AI committees are increasingly focused on one question when vetting new tools: Was protected health information (PHI) used to train the model? According to healthcare technology and legal experts Peter Grantcharov and David Knobel, that framing is dangerously incomplete. A generative AI model that accepts open-ended clinical prompts and a narrow computer-vision model that simply labels surgical video frames may both have been trained on PHI — but their real-world privacy risks are worlds apart.
The authors argue that uniform checklists create a double failure: they can give hospitals false confidence about high-risk generative models (by missing key exposure pathways like adaptive querying or live record retrieval) while simultaneously blocking narrow AI tools that actually reduce PHI exposure by automating tasks currently handled manually by more people. Blocking controlled PHI use for model training, they note, can reduce accuracy and preserve riskier manual workflows.
Key Takeaways:
Why it matters: As hospitals deploy more AI tools, governance frameworks that treat every model the same can both endanger patients and stifle beneficial innovation. Smarter, architecture-specific privacy reviews are essential to getting this balance right.