Metadata, which refers to non-image information such as patient identifiers, acquisition parameters and institutional details, has long been the primary focus of de-identification efforts when constructing datasets for artificial intelligence (AI) applications in medical imaging. However, it is now evident that information intrinsic to the image itself, at the pixel level (eg, intensity values), can also be exploited by deep learning models, potentially revealing sensitive patient data and posing privacy risks. This manuscript discusses both metadata and sources of identifiable information in medical imaging studies, highlighting the potential risks of overlooking their presence. Privacy-preserving approaches such as federated learning and synthetic data generation are also reviewed, with emphasis on their limitations—particularly vulnerabilities to model inversion and inference attacks—that must be considered when developing and deploying AI in medical imaging. ©RSNA, 2025
Giouroukou et al. (2025) studied this question.