Paradox of De-identification: A Critique of HIPAA Safe Harbour in the Age of LLMs

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Jiang, Lavender Y., Liu, Xujin Chris, Cho, Kyunghyun, Oermann, Eric K.
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866914315926241280
author Jiang, Lavender Y.
Liu, Xujin Chris
Cho, Kyunghyun
Oermann, Eric K.
author_facet Jiang, Lavender Y.
Liu, Xujin Chris
Cho, Kyunghyun
Oermann, Eric K.
contents Privacy is a human right that sustains patient-provider trust. Clinical notes capture a patient's private vulnerability and individuality, which are used for care coordination and research. Under HIPAA Safe Harbor, these notes are de-identified to protect patient privacy. However, Safe Harbor was designed for an era of categorical tabular data, focusing on the removal of explicit identifiers while ignoring the latent information found in correlations between identity and quasi-identifiers, which can be captured by modern LLMs. We first formalize these correlations using a causal graph, then validate it empirically through individual re-identification of patients from scrubbed notes. The paradox of de-identification is further shown through a diagnosis ablation: even when all other information is removed, the model can predict the patient's neighborhood based on diagnosis alone. This position paper raises the question of how we can act as a community to uphold patient-provider trust when de-identification is inherently imperfect. We aim to raise awareness and discuss actionable recommendations.
format Preprint
id arxiv_https___arxiv_org_abs_2602_08997
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Paradox of De-identification: A Critique of HIPAA Safe Harbour in the Age of LLMs
Jiang, Lavender Y.
Liu, Xujin Chris
Cho, Kyunghyun
Oermann, Eric K.
Computers and Society
Computation and Language
Privacy is a human right that sustains patient-provider trust. Clinical notes capture a patient's private vulnerability and individuality, which are used for care coordination and research. Under HIPAA Safe Harbor, these notes are de-identified to protect patient privacy. However, Safe Harbor was designed for an era of categorical tabular data, focusing on the removal of explicit identifiers while ignoring the latent information found in correlations between identity and quasi-identifiers, which can be captured by modern LLMs. We first formalize these correlations using a causal graph, then validate it empirically through individual re-identification of patients from scrubbed notes. The paradox of de-identification is further shown through a diagnosis ablation: even when all other information is removed, the model can predict the patient's neighborhood based on diagnosis alone. This position paper raises the question of how we can act as a community to uphold patient-provider trust when de-identification is inherently imperfect. We aim to raise awareness and discuss actionable recommendations.
title Paradox of De-identification: A Critique of HIPAA Safe Harbour in the Age of LLMs
topic Computers and Society
Computation and Language
url https://arxiv.org/abs/2602.08997