{
  "id": 5107,
  "url": "https://arxiv.org/abs/2605.00796v1",
  "title": "When RAG Chatbots Expose Their Backend: An Anonymized Case Study of Privacy and Security Risks in Patient-Facing Medical AI",
  "summary": "Background: Patient-facing medical chatbots based on retrieval-augmented generation (RAG) are increasingly promoted to deliver accessible, grounded health information. AI-assisted development lowers the barrier to building them, but they still demand rigorous security, privacy, and governance controls. Objective: To report an anonymized, non-destructive security assessment of a publicly accessible patient-facing medical RAG chatbot and identify governance lessons for safe deployment of generativ",
  "authors": "Alfredo Madrid-García, Miguel Rujas",
  "category": "research",
  "topics": "regulation,privacy-surveillance,healthcare",
  "orgs": null,
  "regions": null,
  "published_at": "2026-05-01T17:29:09.000Z",
  "fetched_at": "2026-07-14T16:31:31.211Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/5107",
  "original_url": "https://arxiv.org/abs/2605.00796v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}