PriEval-Protect: A Unified Framework for Privacy Evaluation and Protection in Healthcare Systems
This work addresses the limitations of current healthcare data privacy compliance approaches, which rely heavily on manual processes and treat policy auditing and technical risk assessment in isolation, leading to inefficiency and error-proneness. To overcome these challenges, the authors propose PriEval-Protect, a two-stage framework that integrates legal large language models with data-level privacy metrics during the evaluation phase. By leveraging retrieval-augmented generation (RAG), cryptographic identification, and analytic hierarchy process (AHP) weighting, the framework produces an interpretable, composite risk score. In the protection phase, it dynamically recommends mitigation strategies—such as federated learning or differential privacy—based on this score. Validated on real-world hospital data, PriEval-Protect enables synergistic compliance with GDPR and HIPAA, delivers precise risk assessment, and offers explainable privacy safeguards, significantly enhancing the automation and consistency of privacy governance.