Vision Token Masking for PHI Protection: A Negative Result
Research Code & Evaluation Framework
🚨 Key Finding: Vision-level token masking achieves only 42.9% PHI reduction - insufficient for HIPAA compliance
Overview
This repository contains the systematic evaluation code from our paper "Vision Token Masking Alone Cannot Prevent PHI Leakage in Medical Document OCR".
Author: Richard J. Young
Affiliation: DeepNeuro.AI | University of Nevada, Las Vegas
Status: Paper Under Review
The Negative Result
We evaluated seven masking strategies (V3-V9) across different architectural layers of DeepSeek-OCR using 100 synthetic medical billing statements from a corpus of 38,517 annotated documents.
What We Found
PHI Type
Reduction Rate
Patient Names
✅ 100%
Dates of Birth
✅ 100%
Physical Addresses
✅ 100%
SSN
❌ 0%
Medical Record Numbers
❌ 0%
Email Addresses
❌ 0%
Account Numbers
❌ 0%
Overall
⚠️ 42.9%
Why It Matters
All strategies converged to 42.9% regardless of architectural layer (V3-V9)
Spatial expansion didn't help - mask radius r=1,2,3 showed no improvement
Root cause identified - language model contextual inference reconstructs masked short identifiers from document context
⚠️ Research project only - NOT for production use with real PHI. Always consult legal and compliance teams before deploying PHI-related systems.
Note: This negative result establishes important boundaries for vision-level privacy interventions in VLMs and redirects the field toward more effective hybrid approaches.