Panel: AI × Health Data: Navigating Privacy in the Age of Generative Models
When AI Meets Health Data: Practical Lessons from the Front Line
What does it really mean, in practice, to navigate privacy at the intersection of AI and health data in the age of generative models?
In the age of AI, health data has become the oil of the 21st century. But when AI systems analyze this data to predict, diagnose, or treat, the issue is no longer merely technological. It is also profoundly linked to fundamental rights, governance, and trust. This question was explored during the panel discussion at the Data Privacy for Health Summit, organised by MyData Trust. Rather than focusing on theory or regulation alone, the session examined concrete use cases and lived experience, with insights from experts working directly in healthcare AI, hospital operations, and privacy law: Astou Ndiaye, Founder and CEO at Hale-X; Scott Russell, Founder and CEO at Innatify; Michael Brown, Privacy, AI and Technology Lawyer; and Elisabeth Dehareng, Partner at Baker McKenzie Belgium leading the IP & Tech team.
Moderated by Elisabeth Dehareng, the discussion opened with the observation that legal practice in AI is expanding beyond privacy to include data governance, AI risk management, cybersecurity, and sector-specific compliance frameworks. Healthcare exemplifies this shift, combining highly sensitive data, strict regulatory expectations, and strong pressure to innovate at speed.
From a clinical standpoint, Astou Ndiaye described how AI is enabling truly personalised medicine. Hale-X develops patient-specific digital twins that replicate an individual’s biological state using real-time data. These digital models allow clinicians to simulate disease progression and treatment outcomes for specific patients rather than relying on generalised population data. She highlighted that the biggest hurdle is not data scarcity, but fragmentation. “I really hope that in five to ten years, everyone will have their own digital twins, at hospitals and on themselves. Maybe a smartwatch where all your data are stored… If you travel and have an accident, clinicians can still access your data to treat you. I would love to live in that world…” she said. Beyond technical integration, such a vision raises profound questions around data portability, interoperability, cybersecurity and secondary use of health data, particularly as these solutions move toward consumer-facing applications.
Scott Russell shared a complementary perspective on operational efficiency. His work addresses administrative burdens on hospital staff, aiming to optimise workflows with AI to free time for leadership and patient care. “The AI risks weren’t really the biggest thing; it was the fundamentals—data quality, fragmentation, awareness, literacy, trust. We had to go back to basics and start with trust”, he explained. Security and data protection measures, such as on-premises deployment and strong encryption, were designed as both technical safeguards and confidence-building tools for hospital decision-makers. “They can look at it and go, that’s secure, that’s safe… You can move through that gate” he added.
Turning to the legal perspective, Michael Brown highlighted how healthcare AI projects engage multiple areas of law, with data protection and AI regulation at the forefront. Security remains critical due to the sensitivity of health data and prior enforcement history, while AI introduces new challenges like model leakage, where confidential information can surface unintentionally. Determining whether organisations act as controllers, processors, or joint controllers requires a granular, fact-based assessment of acutal decision-making power and data flows, rather than relying solely on contractual labels. This can pose particular challenges for smaller institutions.
Bias, fairness, and accuracy emerged as persistent AI-specific risks. AI mirrors the data and assumptions it is trained on, and historical healthcare datasets may embed structural biases. Addressing these risks requires continuous investment in data governance, testing, and human oversight. Both Scott and Michael emphasised the importance of explainability and human-in-the-loop mechanisms to preserve clinical accountability and professional judgement. Michael highlighted practical measures such as pseudonymisation, robust authentication, testing for model leakage, and bias/fairness audits to guide organisations toward compliance.
The discussion also explored practical data scenarios. Astou shared concerns about AI platforms like ChatGPT and potential insurer access to health data, illustrating the real-world balancing act between innovation, privacy, and regulation. Audience questions raised cloud versus device-based storage and the management of imperfect legacy datasets. Panelists stressed that data preparation and quality control often require more effort than anticipated, yet failures in these areas carry the highest risk. Treating accuracy and fairness as design principles, rather than afterthoughts, was repeatedly emphasised as essential for sustainable AI deployment and long-term public trust.
The session concluded with a clear takeaway: AI in healthcare is neither merely a compliance challenge nor a technological breakthrough in isolation. Its success depends on careful alignment of innovation, governance, legal responsibility, and professional judgment. When these elements coexist rather than compete, AI can improve efficiency, enhance clinical outcomes, and strengthen trust across the healthcare ecosystem provided that privacy and ethics remain embedded from design to deployment.
[Co-Authors: Myrto-Amaryllis Lappa, Giuseppe Chiapparo]
















