<?xml version="1.0"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "JATS-journalpublishing1.dtd" [
]>
<article xml:lang="en" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML"
  dtd-version="1.2" article-type="abstract">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">IJPDS</journal-id>
      <journal-title-group>
        <journal-title>International Journal of Population Data Science</journal-title>
        <abbrev-journal-title>IJPDS</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="epub">2399-4908</issn>
      <publisher>
        <publisher-name>Swansea University</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.23889/ijpds.v9i5.2521</article-id>
      <article-id pub-id-type="publisher-id">9:5:37</article-id>
      <title-group>
        <article-title>Developing a Framework for Safe AI Model Development on Sensitive Healthcare Data</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Hotchkiss</surname>
            <given-names initials="L">Lewis</given-names>
          </name>
          <xref ref-type="aff" rid="affil-1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Squires</surname>
            <given-names initials="E">Emma</given-names>
          </name>
          <xref ref-type="aff" rid="affil-1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Rittman</surname>
            <given-names initials="T">Timothy</given-names>
          </name>
          <xref ref-type="aff" rid="affil-2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Gallacher</surname>
            <given-names initials="J">John</given-names>
          </name>
          <xref ref-type="aff" rid="affil-3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Thompson</surname>
            <given-names initials="S">Simon</given-names>
          </name>
          <xref ref-type="aff" rid="affil-1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="affil-1"><label>1</label><institution>Swansea University</institution></aff>
      <aff id="affil-2"><label>2</label><institution>University of Cambridge</institution></aff>
      <aff id="affil-3"><label>3</label><institution>University of Oxford</institution></aff>
      <pub-date date-type="pub" publication-format="electronic">
        <day>18</day>
        <month>09</month>
        <year>2024</year>
      </pub-date>
      <pub-date date-type="collection" publication-format="electronic">
        <year>2024</year>
      </pub-date>
      <volume>9</volume>
      <issue>5</issue>
      <elocation-id>2521</elocation-id>
      <permissions>
        <license license-type="open-access" xlink:href="https://creativecommons.org/licences/by/4.0/">
          <license-p>This work is licenced under a Creative Commons Attribution 4.0 International License.</license-p>
        </license>
      </permissions>
      <self-uri xlink:href="https://ijpds.org/article/view/2521">This article is available from the IJPDS website at: https://ijpds.org/article/view/2521</self-uri>
    </article-meta>
  </front>
  <body>
    <p>The Dementias Platform UK (DPUK) Data Portal holds over 60 cohort datasets from over 3 million participants with a range of multi-modal data including neuroimaging and genomics. This has meant we have seen an increasing interest in the development of AI models with the potential for clinical implementation. However, this presents a unique challenge to disclosure control when it comes to assessing these AI models for release due to the risk of attacks such as membership inference, model inversion or even just vulnerabilities in the models like overfitting. This is why we hosted a series of workshops bringing together members of the public, expert researchers, and data owners across the UK to build a framework for allowing the safe development and release of AI models trained on sensitive healthcare data. From this, we have put together recommendations and guidelines for the use of privacy-preserving techniques in AI models to protect patient privacy, and to allow the safe deployment of these models outside of trusted research environments. We also identified the unique challenges to privacy and implementation of privacy-preserving techniques in AI models regarding the use of complex data such as neuroimaging and genomics. This framework has created a path forward for supporting safe AI model development which takes into consideration rapidly evolving ethical, legal and privacy considerations.</p>
  </body>
</article>