Purpose-Scoped PHI Sanitization in Multi-Agent Healthcare AI Systems: A Formal Model, Statistical Evaluation, and Comparative Analysis of Internal-Channel Privacy Leakage

Agentic artificial intelligence (AI) systems are increasingly proposed for clinical workflows such as literature retrieval, patient history management, and diagnostic imaging support. These systems are built on large language models (LLMs) that coordinate through tool use and inter-agent communication, which creates new pathways for sensitive data to leak between agents. Prior work has shown that field-level, purpose-gated access-delegation architectures can reduce such leakage in general-purpose agent systems, and that structured access delegation can bound data-leakage threats. This paper presents a multi-agent clinical AI system composed of literature retrieval, patient history, and diagnostic imaging agents, connected through a purpose-scoped Protected Health Information (PHI) sanitization layer. The sanitization layer enforces HIPAA's Minimum Necessary Standard (45 CFR 164.502(b)) at the point of inter-agent retrieval, restricting each downstream agent's context window to only the fields required for its task. Using MedGemma-1.5-4B-it, the system is evaluated across 80 scenarios involving 20 synthetic patients and four radiological modalities (chest X-ray, skeletal X-ray, mammogram, and abdominal CT), with exact Clopper-Pearson confidence intervals and Fisher's exact test reported alongside observed leakage rates. The sanitized pipeline achieved 0% inter-agent leakage (95% CI [0.00%, 4.51%]) across all output and inter-agent channels for every modality, compared to 100% leakage (95% CI [95.49%, 100.00%]) for a naive baseline (p = 2.17 × 10⁻⁴⁷). Weighted blast-radius analysis shows a 76.2% reduction in sensitivity-weighted data exposure. The measured computational overhead of sanitization (2.9 ms) is negligible compared to vision-language model inference (19.2 s). On a labelled escalation test set of 30 cases, negation-aware detection improved F1 from 0.682 to 1.000. These results demonstrate that strong privacy guarantees and clinical oversight can be integrated into autonomous AI workflows with negligible computational overhead. The findings are further contextualized against related defenses at the capability-token and access-delegation layers.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-06
DOI
https://doi.org/10.5281/zenodo.23196437
Primary Topic
Privacy-Preserving Technologies in Data
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

Purpose-Scoped PHI Sanitization in Multi-Agent Healthcare AI Systems: A Formal Model, Statistical Evaluation, and Comparative Analysis of Internal-Channel Privacy Leakage

Sagar Neupane
Zenodo (CERN European Organization for Nuclear Research)
Privacy-Preserving Technologies in Data
preprint

Purpose-Scoped PHI Sanitization in Multi-Agent Healthcare AI Systems: A Formal Model, Statistical Evaluation, and Comparative Analysis of Internal-Channel Privacy Leakage

Sagar Neupane
preprint en

Abstract

Agentic artificial intelligence (AI) systems are increasingly proposed for clinical workflows such as literature retrieval, patient history management, and diagnostic imaging support. These systems are built on large language models (LLMs) that coordinate through tool use and inter-agent communication, which creates new pathways for sensitive data to leak between agents. Prior work has shown that field-level, purpose-gated access-delegation architectures can reduce such leakage in general-purpose agent systems, and that structured access delegation can bound data-leakage threats. This paper presents a multi-agent clinical AI system composed of literature retrieval, patient history, and diagnostic imaging agents, connected through a purpose-scoped Protected Health Information (PHI) sanitization layer. The sanitization layer enforces HIPAA's Minimum Necessary Standard (45 CFR 164.502(b)) at the point of inter-agent retrieval, restricting each downstream agent's context window to only the fields required for its task. Using MedGemma-1.5-4B-it, the system is evaluated across 80 scenarios involving 20 synthetic patients and four radiological modalities (chest X-ray, skeletal X-ray, mammogram, and abdominal CT), with exact Clopper-Pearson confidence intervals and Fisher's exact test reported alongside observed leakage rates. The sanitized pipeline achieved 0% inter-agent leakage (95% CI [0.00%, 4.51%]) across all output and inter-agent channels for every modality, compared to 100% leakage (95% CI [95.49%, 100.00%]) for a naive baseline (p = 2.17 × 10⁻⁴⁷). Weighted blast-radius analysis shows a 76.2% reduction in sensitivity-weighted data exposure. The measured computational overhead of sanitization (2.9 ms) is negligible compared to vision-language model inference (19.2 s). On a labelled escalation test set of 30 cases, negation-aware detection improved F1 from 0.682 to 1.000. These results demonstrate that strong privacy guarantees and clinical oversight can be integrated into autonomous AI workflows with negligible computational overhead. The findings are further contextualized against related defenses at the capability-token and access-delegation layers.

Zenodo (CERN European Organization for Nuclear Research)
University of Alabama (US)
Privacy-Preserving Technologies in Data
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.