PriEval-Protect: A Unified Framework for Privacy Evaluation and Protection in Healthcare Systems

📅 2026-07-15
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the limitations of current healthcare data privacy compliance approaches, which rely heavily on manual processes and treat policy auditing and technical risk assessment in isolation, leading to inefficiency and error-proneness. To overcome these challenges, the authors propose PriEval-Protect, a two-stage framework that integrates legal large language models with data-level privacy metrics during the evaluation phase. By leveraging retrieval-augmented generation (RAG), cryptographic identification, and analytic hierarchy process (AHP) weighting, the framework produces an interpretable, composite risk score. In the protection phase, it dynamically recommends mitigation strategies—such as federated learning or differential privacy—based on this score. Validated on real-world hospital data, PriEval-Protect enables synergistic compliance with GDPR and HIPAA, delivers precise risk assessment, and offers explainable privacy safeguards, significantly enhancing the automation and consistency of privacy governance.
📝 Abstract
Safeguarding patient privacy while enabling meaningful healthcare data use remains critical under GDPR and HIPAA. Existing compliance methods are manual, error-prone, and separate policy audits from data-level assessments. This paper presents PriEval-Protect, a two-phase framework for unified privacy risk evaluation and mitigation. The evaluation phase combines regulatory compliance scoring using a fine-tuned legal LLM with RAG, and technical analysis via encryption type, data architecture, and metrics including similarity, uncertainty, adversary success, and information gain/loss. A composite risk score uses weighted aggregation via Analytic Hierarchy Process. The protection phase recommends countermeasures including federated learning and differential privacy based on assessed risk. Results on hospital documents and datasets demonstrate regulation-aligned, explainable assessments, bridging legal conformance and data-level risk analysis.
Problem

Research questions and friction points this paper is trying to address.

privacy evaluation
healthcare systems
regulatory compliance
data privacy
risk assessment
Innovation

Methods, ideas, or system contributions that make the work stand out.

privacy evaluation
legal LLM with RAG
composite risk scoring
federated learning
differential privacy
🔎 Similar Papers
No similar papers found.
I
Ilef Chebil
National Institute of Applied Science and Technology INSAT, Tunis, Tunisia
A
Asma El Hadj
National Institute of Applied Science and Technology INSAT, Tunis, Tunisia
S
Souheib Yousfi
Efrei Research Lab, Efrei, Paris-Panthéon-Assas University, Paris, France
A
Aroua Hedhili
LARIA Research Lab, National School Of Computer Science ENSI, Tunis, Tunisia
L
Layth Sliman
Efrei Research Lab, Efrei, Paris-Panthéon-Assas University, Paris, France