Tech Trends Today publication

Storage encryption protects patient data while it is stored. Conventional AI inference requires the data to be decrypted for processing, creating an exposure point during use.

The protection gap begins at inference

A healthcare AI lead can point to encrypted databases, encrypted backups, and encrypted storage buckets. Then an inference workflow starts, and the model needs data it can process.

That is the boundary encryption at rest does not cross on its own. A clinical note, image, or patient record may be protected on disk. To run a typical inference job, the system decrypts the relevant input, makes it available to the application and compute environment, then produces an output. Controls around that workflow still matter, including access permissions, logging, isolation, key management, and retention. The data is no longer protected by storage encryption alone.

For teams handling sensitive health information, this changes the security question. “Is our data encrypted?” is incomplete. The useful question is: where, exactly, does readable patient data appear while the model is working?

Google’s HEIR points toward encrypted inference

Google has presented HEIR, an open-source compiler in its Private Computing Toolkit intended to enable AI inference over homomorphically encrypted data.

Homomorphic encryption is designed for a difficult job: allow computation on encrypted data without first converting it into readable plaintext. If that approach works for a given model and workload, the system can process protected inputs while reducing the need to expose their contents during inference.

That possibility matters most where the data itself creates the risk. A healthcare organization may want a model to classify information, flag a pattern, or support a workflow without broadly revealing the underlying record to the infrastructure performing the computation.

The distinction is practical. Encryption at rest protects a file waiting in storage. Encrypted computation addresses the period when that file would otherwise need to become readable for a model.

The hard part is deciding where it fits

HEIR’s arrival does not erase the operating questions. Healthcare teams need to establish which inference workloads are suitable for homomorphic encryption, what model changes may be required, and what performance tradeoffs the approach introduces.

A narrow, high-sensitivity task may be a better starting point than a broad model workflow. The useful evaluation begins with the data path: identify the patient fields required for inference, where those fields are decrypted today, which systems can access them, and how long they remain available.

Then test the real job. A privacy-preserving inference method has to meet the clinical or operational need within an acceptable time and cost envelope. A system that protects data but cannot support the required workflow remains a research result, not a deployed safeguard.

This is also a reminder to separate a tool announcement from a production claim. Google presented HEIR as an open-source compiler designed for this type of encrypted AI inference. That establishes a direction and a capability target. It does not establish that every healthcare AI workflow can adopt the approach immediately.

Security reviews need a “data in use” column

Security reviews often divide controls into data at rest and data in transit. AI systems need a third, explicit category: data in use.

For each model workflow, document:

  • Which patient data enters the model.
  • Where plaintext appears before, during, and after inference.
  • Which services, people, and logs can access it.
  • Whether the workflow can use encrypted computation for part of the task.
  • What evidence supports the security and performance assumptions.

That inventory can reveal a mismatch between a strong storage posture and a weak processing posture. It can also prevent a common mistake: treating encryption at rest as proof that an AI workflow never handles readable sensitive data.

The first useful action is small. Pick one inference path this week and trace it from stored record to model output. Mark every point where patient data becomes readable. That map will tell you whether encrypted computation is a meaningful next test, or whether simpler access and architecture changes deserve attention first.

Sources

Google presented HEIR, an open-source compiler in its Private Computing Toolkit for AI inference over homomorphically encrypted data.

Comments

No comments yet.