PrivMeSA Uses Local-Remote LLM Collaboration to Protect Patient Privacy
Summary
PrivMeSA is a privacy-aware multi-agent system for clinical large language model agents that need access to more capable remote models without exposing patient information. The paper argues that removing explicit identifiers is insufficient because quasi-identifiers can accumulate across multi-turn consultations and repeated visits, enabling re-identification. In PrivMeSA, a local agent manages each encounter and consults remote specialist agents that can request additional information. Reinforcement learning balances clinical task accuracy against direct disclosure and registry-based re-identification risk, evaluating privacy over the complete outbound transcript of an encounter. The system also distills completed consultations into generalized clinical guidance, stores the lessons locally, and retrieves relevant lessons before transmission so later cases can reuse remote expertise without another remote exchange. This memory grows without additional outcome labels or parameter updates. On an emergency-department benchmark built from MIMIC-IV-ED records, PrivMeSA improved mean task accuracy over delegation by up to 15.8 percentage points. It also reduced cases disclosing personal details from 98.0% to 0.2%, while cases in which a patient could be narrowed to ten or fewer registry patients fell from 74% to 0%.