QuestionQ35

Governance, Risk, and Compliance

Which of the following explains why an organization should carefully consider whether to use AI to automate processes that interact with healthcare data?

Explanation

AI models trained on healthcare records are prime targets for model inversion, an attack in which an adversary repeatedly queries the model and analyzes its outputs or confidence scores to reconstruct sensitive training data, such as a patient's diagnosis or biometric information. Because organizations handling protected health information face the greatest exposure from this class of attack, the risk of a model inadvertently leaking the very patient data it was trained on is a primary reason to weigh AI automation carefully in healthcare contexts. Pipeline injection and social engineering describe manipulation of inputs or people rather than extraction of training data, making them less specific to this scenario.

Community Discussion

No comments yet. Be the first to start the discussion!