Client-Side Ephemeral De-Identification of Protected Health Information (PHI) in Multi-Center Clinical Trial Analysis and Large Language Model Workflows: Validating Zero-Trust Data Sanitization Under HIPAA Safe Harbor Section 164.514(b)
This paper presents and validates Zero-Trust Data Sanitization (ZTDS), a client-side, on-device architectural framework that performs real-time, HIPAA Safe Harbor-compliant de-identification of Protected Health Information within volatile memory before transmission, thereby enabling secure, zero-trust utilization of public Large Language Models in clinical research without requiring Business Associate Agreements or risking data exfiltration.