构建可合规医疗的智能体系统,自动保护患者隐私数据。
Towards a HIPAA Compliant Agentic AI System in Healthcare
- 用动态权限控制精细管理健康数据访问
- 结合正则与BERT模型清洗敏感信息防泄露
- 全程留痕审计,适配HIPAA合规要求
以大语言模型为推理核心的智能体AI系统正在改变临床工作流程,如自动生成医疗报告和总结,能自主分析敏感医疗数据并减少人工干预。然而,其应用必须严格遵守《健康保险可携性与责任法案》(HIPAA),尤其是在处理受保护健康信息(PHI)时。本文提出一种符合HIPAA的智能体AI框架,通过动态上下文感知策略实现监管合规。框架包含三大机制:(1) 基于属性的访问控制(ABAC),实现对PHI的细粒度管理;(2) 混合式PHI脱敏管道,结合正则表达式与BERT模型,有效降低数据泄露风险;(3) 不可篡改的审计日志,支持合规性验证。
原文摘要 · Abstract (English)
Agentic AI systems powered by Large Language Models (LLMs) as their foundational reasoning engine, are transforming clinical workflows such as medical report generation and clinical summarization by autonomously analyzing sensitive healthcare data and executing decisions with minimal human oversight. However, their adoption demands strict compliance with regulatory frameworks such as Health Insurance Portability and Accountability Act (HIPAA), particularly when handling Protected Health Information (PHI). This work-in-progress paper introduces a HIPAA-compliant Agentic AI framework that enforces regulatory compliance through dynamic, context-aware policy enforcement. Our framework integrates three core mechanisms: (1) Attribute-Based Access Control (ABAC) for granular PHI governance, (2) a hybrid PHI sanitization pipeline combining regex patterns and BERT-based model to minimize leakage, and (3) immutable audit trails for compliance verification.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。