New AI research strengthens privacy protection in healthcare
NEWS
AI makes it possible to connect and analyse information across databases. However, this raises questions about user safety and privacy. How can sensitive data be used without risking the disclosure of more information than necessary?
“My research shows how a data management system can be developed to comply with GDPR, support different access levels, and still provide rapid access to critical information in emergencies,” says Divya Baura, who recently earned her PhD at Umeå University.
"Privacy is not only about who can access a piece of information. It is also about what can be inferred when different pieces of information are combined,” says Divya Baura, newly awarded PhD at the Department of Computing Science.
ImagePrivat
Artificial intelligence is increasingly being used across Swedish healthcare. Advances in AI technology can help improve diagnoses and treatments, streamline healthcare systems, and support research. However, they also introduce new risks.
"As it becomes easier to use and combine information, new privacy challenges emerge, particularly in healthcare, where the information is often highly sensitive,” says Divya Baura at the Department of computing science.
In her research, she has focused on how valuable health data can be made useful, without exposing sensitive information. “Doctors need access to information to treat patients. Researchers need it to understand diseases and develop better treatments, and hospitals need it to improve their operations,” says Divya Baura.
The solution, therefore, is not to lock away all information and restrict its use. Instead, the challenge is to make data useful for the right user, while protecting other users' privacy. Her research uses healthcare as a starting point, but the methods can also be used within other areas.
From theory to practice
An important motivation behind her research has been to bridge the gap between research and reality. Divya Baura has investigated how established privacy-preserving methods work in a data management system called virtual knowledge graphs. These graphs act as an advanced “layer” between users and the databases where information is stored. “In a hospital setting, this technology can help people and AI systems to find, understand, and connect information from multiple data sources without requiring the information to be copied into a new database.”
Strong theoretical models already exist in this area. Divya Baura wanted to understand how well these models perform in real-world systems.
"I wanted to investigate whether these methods work alongside real software systems, whether they meet the requirements of legislation such as the GDPR, and whether they can handle different access levels and emergency situations that frequently arise in healthcare,” says Divya Baura.
Four Components of the Research
Divya Baura’s research consists of four main components. First, she implemented the method in an open-source virtual knowledge graph platform to examine how it performs in practice.
Second, she studied how privacy rules can be used to meet data protection requirements, such as those set out in the GDPR, using real healthcare data and established health information standards. Third, Divya Baura extended the method to account for different user roles.
"A doctor, a researcher, and an administrator may all need to use the same underlying data, but they do not necessarily need to have access to the same information or be able to draw the same conclusions from it", she explains.
Also able to handle critical situations
Finally, Divya Baura investigated how the system can handle emergency situations. In healthcare, there are occasions when overly strict privacy protection can itself become a problem.
"For example, if a patient is admitted unconscious, a doctor may need immediate access to information about allergies or medications", Baura explains. To address this, Divya developed a dedicated mechanism that allows temporary access in emergencies while ensuring that all use is monitored and documented.
Can be built into existing systems
One important insight from her research is that privacy is not only about protecting individual pieces of information. The real problem can arise when multiple pieces of information are combined.
“We are moving towards systems where people can ask questions in natural language, where AI automatically retrieves and combines information from many different sources," says Divya Baura. "In such an environment, it is not enough simply to control who is allowed to open a particular database or file. We must also consider what conclusions can be drawn from the information that the system has access to”.
She sees her research as a step towards answering these questions. The most important conclusion is that privacy is not only about who can see your data. It is also about what can be inferred when different pieces of information are combined.
“Privacy is about more than a single data point. It depends on the context, what information is combined, and what conclusions can be drawn from it,” concludes Dr Baura.