Privacy, security, and reliability risks of artificial intelligence in healthcare: a systematic review of empirical evidence.
Authors
Affiliations (3)
Affiliations (3)
- Department of Health, Exercise and Applied Science, Rangos School of Health Sciences, Duquesne University, Pittsburgh, PA 15282, United States. Electronic address: [email protected].
- Department of Public Health, Sarab Faculty of Medical Sciences, Sarab, Iran.
- Department of Health, Exercise and Applied Science, Rangos School of Health Sciences, Duquesne University, Pittsburgh, PA 15282, United States.
Abstract
Artificial intelligence (AI) is increasingly integrated into healthcare information systems, supporting clinical decision-making, imaging analysis, and predictive modeling. While these applications offer operational and clinical benefits, they also introduce emerging risks to patient privacy, data security, and system reliability. To systematically review empirical evidence on privacy breaches, security vulnerabilities, and misuse associated with AI applications in healthcare settings. PubMed, Embase, Web of Science, Scopus, IEEE Xplore, and ACM Digital Library were searched for empirical studies published between January 2015 and November 2025 that evaluated AI use or misuse in clinical diagnosis, treatment, or decision-making. Two reviewers independently screened studies and extracted data using a standardized form. Findings were synthesized narratively due to heterogeneity in study designs, AI methods, and reported outcomes. Of 7,285 records identified through database searches and 205 through citation screening, 22 empirical studies met the inclusion criteria, spanning multiple clinical domains and data modalities, predominantly medical imaging applications. Five recurring threat categories were identified: patient re-identification, membership inference, unauthorized access and adversarial exploitation, input manipulation, and misuse or overinterpretation of AI outputs. Across studies, AI models were shown to encode latent biometric signals across diverse data types, limiting the effectiveness of traditional anonymization and synthetic data approaches. Adversarial attacks and input manipulation were also shown to compromise diagnostic performance and system integrity. This systematic review provides empirical evidence suggesting that contemporary AI systems in healthcare introduce privacy and security risks that may challenge traditional assumptions about data protection. These findings underscore the need for privacy- and security-by-design approaches and governance frameworks that address risks across the AI lifecycle.