JMIR Medical Informatics
Clinical informatics, decision support for health professionals, electronic health records, and eHealth infrastructures.
Editor-in-Chief:
Arriel Benis, PhD, FIAHSI, SMIEEE, MACE, Adjunct Associate Professor in the Department of Biomedical Engineering, Duke University, NC, USA
Impact Factor 5.0 More information about Impact Factor CiteScore 7.5 More information about CiteScore
Recent Articles

In this Viewpoint, we highlight the principal cybersecurity measures that should be implemented to facilitate safe and effective integration of large language models (LLMs) into health care and propose a conceptual, life cycle–based framework synthesizing evidence from security and clinical informatics literature. While LLMs offer significant potential for applications in clinical documentation, triage, and medical education, their deployment creates novel vulnerabilities that can compromise patient safety and data confidentiality. We argue that these vulnerabilities must be addressed across the entire deployment life cycle, with distinct threats arising before and after a model enters clinical use. Predeployment risks include data and model poisoning, where an LLM’s training data or core parameters are maliciously corrupted to embed biases or backdoors. After deployment, LLMs are susceptible to inference attacks, such as prompt injection and adversarial inputs, which can be used to manipulate model behavior and extract sensitive information. Standard performance benchmarks are often insufficient to detect these sophisticated attacks. Therefore, we argue that a proactive, multilayered security framework combining technical safeguards, rigorous governance, and human-in-the-loop oversight is essential for the safe and trustworthy adoption of LLMs in clinical practice.

Health care organizations increasingly rely on business associates (BAs) to provide clinical, administrative, and technology services that require access to protected health information. While the Health Information Technology for Economic and Clinical Health (HITECH) Act and the Health Insurance Portability and Accountability Act (HIPAA) Omnibus Rule extended legal liability to BAs, the frequency and characteristics of data breaches involving BAs have not been systematically tracked across the entire post-HITECH reporting era. Understanding these trends is critical for health information managers and cybersecurity professionals who are directly responsible for managing third-party risk.

AI-based clinical decision support systems (CDSS) can improve diagnostics and treatment decisions, but they are rarely implemented in practice. Barriers include limited integration into clinical workflows, lack of transparency, and insufficient involvement of end users in system design. Participatory and user-centered approaches offer ways to address these challenges by aligning development processes with the needs and routines of clinical staff. However, systematic evidence on how such approaches are applied in the development of AI-based CDSS remains limited.

Access to eye care is a persistent challenge due to the high global burden of visual impairment and barriers to receiving eye care, such as transportation and cost. Conventional ophthalmic equipment is immobile and unsuitable for bedside or community use, and this limits timely diagnosis and care delivery. Portable ophthalmic devices, such as handheld slit-lamps and fundus cameras, offer the potential to extend diagnostic capabilities to nonclinical settings and improve accessibility of eye care.

Health data management during disasters enables responders to assess the needs of survivors, efficiently allocate resources, and monitor survivors’ health conditions. However, government agencies need to interpret health data in real time during disasters because the volume and complexity of such data can hinder timely decision-making.

Smart home technologies integrated with technology-enhanced health care (TEH) systems are transforming residential care by supporting independent living, continuous health monitoring, and remote clinical interventions. The Internet of Medical Things, wearable biosensors, and AI-driven analytics enable proactive health care delivery and personalized interventions, particularly for older adults and individuals with chronic conditions.

Misspellings in medication names can compromise patient safety, reduce data utility, and impede large-scale data initiatives that integrate medication information from electronic health records (EHRs). Existing methods for detecting misspelled medical terms are mostly dictionary-based and can lead to high false-positive rates when correctly spelled but previously unseen (out-of-vocabulary) terms are encountered.

Patient safety events (PSEs) are preventable incidents that cause, or have the potential to cause, harm to patients during their medical journey. Although incident reporting systems capture large volumes of such events, only a small proportion undergo comprehensive investigation due to the resource-intensive nature of the review process. Patient safety specialists are tasked with triaging PSEs to prioritize high-severity cases that warrant timely institutional investigation; however, the rapidly increasing volume of events has made manual triage increasingly impractical.


Although Digital Imaging and Communications in Medicine (DICOM) metadata are widely used to manage medical imaging data and support clinical workflows, their suitability as a sole basis for automatic computed tomography (CT) series labeling and characterization is limited. DICOM metadata are frequently inconsistently populated, institution specific, use unregulated private tags, and have variable reliability even within standardized fields. Consequently, automated series selection for downstream AI applications often remains unreliable, necessitating manual curation within clinical workflows.

Systematic strategies to harness electronic health record (EHR) workflows, reduce redundancy, and support decision-making remain limited in acute care surgery (ACS). Understanding how EHR systems and workflows intersect with time-sensitive settings is critical to improving decision-making and outcomes in ACS.
Preprints Open for Peer Review
Open Peer Review Period:
-







