Purpose-Scoped PHI Sanitization in Multi-Agent Healthcare AI Systems: A Formal Model, Statistical Evaluation, and Comparative Analysis of Internal-Channel Privacy Leakage
Agentic artificial intelligence (AI) systems are increasingly proposed for clinical workflows such as literature retrieval, patient history management, and diagnostic imaging support. These systems are built on large language models (LLMs) that coordinate through tool use and inter-agent communication, which creates new pathways for sensitive data to leak between agents. Prior work has shown that field-level, purpose-gated access-delegation architectures can reduce such leakage in general-purpose agent systems, and that structured access delegation can bound data-leakage threats. This paper presents a multi-agent clinical AI system composed of literature retrieval, patient history, and diagnostic imaging agents, connected through a purpose-scoped Protected Health Information (PHI) sanitization layer. The sanitization layer enforces HIPAA's Minimum Necessary Standard (45 CFR 164.502(b)) at the point of inter-agent retrieval, restricting each downstream agent's context window to only the fields required for its task. Using MedGemma-1.5-4B-it, the system is evaluated across 80 scenarios involving 20 synthetic patients and four radiological modalities (chest X-ray, skeletal X-ray, mammogram, and abdominal CT), with exact Clopper-Pearson confidence intervals and Fisher's exact test reported alongside observed leakage rates. The sanitized pipeline achieved 0% inter-agent leakage (95% CI [0.00%, 4.51%]) across all output and inter-agent channels for every modality, compared to 100% leakage (95% CI [95.49%, 100.00%]) for a naive baseline (p = 2.17 × 10⁻⁴⁷). Weighted blast-radius analysis shows a 76.2% reduction in sensitivity-weighted data exposure. The measured computational overhead of sanitization (2.9 ms) is negligible compared to vision-language model inference (19.2 s). On a labelled escalation test set of 30 cases, negation-aware detection improved F1 from 0.682 to 1.000. These results demonstrate that strong privacy guarantees and clinical oversight can be integrated into autonomous AI workflows with negligible computational overhead. The findings are further contextualized against related defenses at the capability-token and access-delegation layers.
Authors
- Sagar Neupane (ORCID: https://orcid.org/0009-0001-3163-9734)
Institutions
- University of Alabama (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-06
- DOI
- https://doi.org/10.5281/zenodo.23196437
- Primary Topic
- Privacy-Preserving Technologies in Data
- Type
- preprint