Disparate Privacy Risks from Medical AI

Medical AI models can leak sensitive patient information through privacy attacks, even when average risk metrics look acceptable. This paper shows that while aggregate membership inference attack success often appears close to random guessing, individual patient-level risks can be extremely high— with some patients facing near-perfect identifiability.
The risks are also disparate: they disproportionately affect underrepresented groups (by race, disease prevalence, or insurance status). Larger models tend to increase these individual and group-level privacy vulnerabilities.
The study introduces patient-level privacy auditing across multiple real-world clinical datasets (chest X-rays, ECGs, EHRs) and demonstrates that current aggregate-focused evaluations can mask serious fairness and safety issues in medical AI deployment.
This Ledger Entry expands how readers think about responsible AI in healthcare by showing that privacy risks from medical AI models are highly uneven — with some patients facing near-certain identification while others face almost none — and that these risks disproportionately burden underrepresented groups, challenging the assumption that average-case privacy metrics are sufficient for safe deployment.