C-PPDSS: A Comprehensive Patient Personal Data Sovereignty System for Real-Time PII Redaction in Healthcare LLM Workflows

Authors

DOI:

https://doi.org/10.58190/ijamec.2026.178

Keywords:

Patient Data Privacy, PII Redaction, Health Data Sovereignty, C-PPDSS, Healthcare AI, Real-Time Data Protection, Machine Learning, PIIRANHA Model, Large Language Models, Data Security in Healthcare

Abstract

Health surveillance in modern healthcare increasingly relies on AI, raising concerns about the exposure of patients' identifiable information (PII) in automated workflows. This paper presents the Comprehensive Patient Personal Data Sovereignty System (CPPDSS), a privacy-preserving framework designed to enforce real-time PII redaction during outbound interactions with large language models. C-PPDSS employs a fine-tuned Custom PIIRANHA model, based on Microsoft's DeBERTa-v2 architecture, to intercept and sanitize HTTP POST requests containing sensitive healthcare data before they reach external LLM services. Evaluated on a held-out test set of 20,927 annotated examples, Custom PIIRANHA achieved 99.51% token-level accuracy and a micro-averaged F1 score of 95.45%, outperforming a fine-tuned Distilled BERT baseline across all major metrics. Quantitative benchmarking demonstrated a mean inference latency of 229.66 ms per request, a model memory footprint of 305.7 MB, and a sustained throughput of 4.35 requests per second on CPU-only hardware, confirming suitability for real-time deployment on modest intranet infrastructure. By securing patient information at the network level, C-PPDSS bridges a gap left by previous static-document-focused systems, enabling safe AI integration in healthcare workflows. Its architecture ensures reproducibility and feasibility for deployment in hospital intranets or standard commodity hardware setups.

Downloads

Download data is not yet available.

References

[1] J. P. Albrecht, “How the GDPR Will Change the World,” Eur. Data Prot. Law Rev., vol. 2, no. 3, pp. 287–289, 2016, doi: 10.21552/EDPL/2016/3/4.

[2] V. Rathod, S. Nabavirazavi, S. Zad, and S. S. Iyengar, “Privacy and Security Challenges in Large Language Models,” in 2025 IEEE 15th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA: IEEE, Jan. 2025, pp. 00746–00752. doi: 10.1109/CCWC62904.2025.10903912.

[3] G. Sperlí, “Exploring Privacy and Security Risks in LLMs: Data Leakage, Prompt Injection, and Membership Inference,” in 2025 International Symposium on Multimedia (ISM), Naples, Italy: IEEE, Dec. 2025, pp. 5–12. doi: 10.1109/ISM66958.2025.00011.

[4] H. Alami, P. Lehoux, C. Papoutsi, S. E. Shaw, R. Fleet, and J.-P. Fortin, “Understanding the integration of artificial intelligence in healthcare organisations and systems through the NASSS framework: a qualitative study in a leading Canadian academic centre,” BMC Health Serv. Res., vol. 24, no. 1, p. 701, Jun. 2024, doi: 10.1186/s12913-024-11112-x.

[5] P. Goktas and A. Grzybowski, “Shaping the Future of Healthcare: Ethical Clinical Challenges and Pathways to Trustworthy AI,” J. Clin. Med., vol. 14, no. 5, p. 1605, Feb. 2025, doi: 10.3390/jcm14051605.

[6] E. Olaye, I. Omafovbe, W. O. Aigbe, and D. Obuh, “Personalized Governance Strategy for Patient Data in a Digital One Health Surveillance System,” Procedia Comput. Sci., vol. 254, pp. 20–29, 2025, doi: 10.1016/j.procs.2025.02.060.

[7] H. Roberts, “Digital sovereignty and artificial intelligence: a normative approach,” Ethics Inf. Technol., vol. 26, no. 4, p. 70, Dec. 2024, doi: 10.1007/s10676-024-09810-5.

[8] B. Murdoch, “Privacy and artificial intelligence: challenges for protecting health information in a new era,” BMC Med. Ethics, vol. 22, no. 1, p. 122, Dec. 2021, doi: 10.1186/s12910-021-00687-3.

[9] S. M. Williamson and V. Prybutok, “Balancing Privacy and Progress: A Review of Privacy Challenges, Systemic Oversight, and Patient Perceptions in AI-Driven Healthcare,” Appl. Sci., vol. 14, no. 2, p. 675, Jan. 2024, doi: 10.3390/app14020675.

[10] K. P. Anunita, S. R. Devisri, and C. Arumugam, “Federated Learning: Countering Label Flipping Attacks in Retinal OCT,” Procedia Comput. Sci., vol. 254, pp. 58–67, 2025, doi: 10.1016/j.procs.2025.02.064.

[11] C. Mennella, U. Maniscalco, G. De Pietro, and M. Esposito, “Ethical and regulatory challenges of AI technologies in healthcare: A narrative review,” Heliyon, vol. 10, no. 4, p. e26297, Feb. 2024, doi: 10.1016/j.heliyon.2024.e26297.

[12] P. L. Chong et al., “Integrating artificial intelligence in healthcare: applications, challenges, and future directions,” Future Sci. OA, vol. 11, no. 1, p. 2527505, Dec. 2025, doi: 10.1080/20565623.2025.2527505.

[13] S. Gawankar, S. Nair, V. Pawar, A. Vhatkar, and P. Chavan, “Patient Privacy and Data Security in the Era of AI-Driven Healthcare,” in 2024 8th International Conference on Computing, Communication, Control and Automation (ICCUBEA), Pune, India: IEEE, Aug. 2024, pp. 1–6. doi: 10.1109/ICCUBEA61740.2024.10775004.

[14] B. Rodrigues, I. Amorim, I. Costa, and A. Mendes, “Patient-centric health data sovereignty: an approach using Proxy re-encryption,” 2023, arXiv. doi: 10.48550/ARXIV.2307.01175.

[15] A. Alabdulatif, I. Khalil, X. Yi, and M. Guizani, “Secure Edge of Things for Smart Healthcare Surveillance Framework,” IEEE Access, vol. 7, pp. 31010–31021, 2019, doi: 10.1109/ACCESS.2019.2899323.

[16] S. Chandra, S. Ray, and R. T. Goswami, “Big Data Security in Healthcare: Survey on Frameworks and Algorithms,” in 2017 IEEE 7th International Advance Computing Conference (IACC), Hyderabad, India: IEEE, Jan. 2017, pp. 89–94. doi: 10.1109/IACC.2017.0033.

[17] T. Bhaskar, M.N. Narsaiah, and M. Ravikanth, “Central Medical Centre Healthcare Data Security with Lightweight Blockchain Model in IoT Sensor Environment”, JSIHS, vol. 1, no. 1, pp. 15–26, Dec. 2023, doi: 10.69996/jsihs.2023002.

[18] G. P. Tobia et al., “Privacy in Italian Clinical Reports: A NLP-Based Anonymization Approach,” in 2025 IEEE 13th International Conference on Healthcare Informatics (ICHI), Rende, Italy: IEEE, Jun. 2025, pp. 630–635. doi: 10.1109/ICHI64645.2025.00077.

[19] L. Mainetti and A. Elia, “Detecting Personally Identifiable Information Through Natural Language Processing: A Step Forward,” Appl. Syst. Innov., vol. 8, no. 2, p. 55, Apr. 2025, doi: 10.3390/asi8020055.

[20] L. R. Kumar, C. Ashokkumar, P. S. Pandey, S. K. Kannaiah, B. J, and M. I. T. Hussan, “Security Enhancement in Surveillance Cloud Using Machine Learning Techniques,” Int. J. Recent Innov. Trends Comput. Commun., vol. 11, no. 3s, pp. 46–55, Mar. 2023, doi: 10.17762/ijritcc.v11i3s.6154.

[21] M. Nankya, A. Mugisa, Y. Usman, A. Upadhyay, and R. Chataut, “Security and Privacy in E-Health Systems: A Review of AI and Machine Learning Techniques,” IEEE Access, vol. 12, pp. 148796–148816, 2024, doi: 10.1109/ACCESS.2024.3469215.

[22] N. V. D. P. Raju, “Design and Implementation of Artificial Intelligence and Machine Learning Techniques for Security of Healthcare Systems,” in 2024 Asian Conference on Intelligent Technologies (ACOIT), KOLAR, India: IEEE, Sep. 2024, pp. 1–7. doi: 10.1109/ACOIT62457.2024.10941611.

[23] J. Ganesh and A. Bansal, “Transformer-based Automatic Mapping of Clinical Notes to Specific Clinical Concepts,” in 2023 IEEE 47th Annual Computers, Software, and Applications Conference (COMPSAC), Torino, Italy: IEEE, Jun. 2023, pp. 558–563. doi: 10.1109/COMPSAC57700.2023.00080.

Downloads

Published

30-09-2026

Issue

Section

Research Articles

How to Cite

[1]
E. Olaye, W. O. Aigbe, D. Onwuka, D. Obuh, and A. Madukwe, “C-PPDSS: A Comprehensive Patient Personal Data Sovereignty System for Real-Time PII Redaction in Healthcare LLM Workflows”, J. Appl. Methods Electron. Comput., vol. 14, no. 3, pp. 110–119, Sep. 2026, doi: 10.58190/ijamec.2026.178.

Similar Articles

121-130 of 308

You may also start an advanced similarity search for this article.