Key points are not available for this paper at this time.
Large language models (LLMs) are increasingly adopted across healthcare applications, including clinical decision support and medical documentation systems. However, their deployment in medical settings raises significant privacy and security concerns due to the sensitivity of protected health information and stringent regulatory requirements. Recent studies have shown that LLM-based medical applications can cause medical data leakage through related API usages. This raises ethical concerns and threatens HIPAA (Health Insurance Portability and Accountability Act) compliance, blocking the trustworthy deployment of LLMs in the medical domain. This review examines emerging privacy attacks and the related defense approaches in LLMs with a special focus on healthcare applications. We organize the attack and defense approaches based on Secure AI Framework (SAIF), systematically covering vulnerabilities across the data, model, application and infrastructure layers. We performed detailed analysis on major classes of privacy attacks and further examined state-of-the-art defense mechanisms under realistic healthcare application scenarios. A key finding of this review is the persistent privacy-utility tradeoff: stronger privacy protection often leads to substantial degradation in clinical performance, which may render models unsuitable for mission-critical medical tasks. The healthcare related deployment of LLMs needs to be evaluated against clinical utility thresholds rather than generic language modeling metrics. We identify open challenges in evaluation, system-level deployment and regulatory verification, and outline research directions that balance clinical utility with regulatory compliance.
Aroua et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: