Critical

Medical PII — Personal Medical/Health Data Request for Named Individual

This detects prompts that ask an AI assistant to reveal medical or health information about a specific named individual, using a family or relationship label like 'my daughter' or 'my husband' to sound legitimate. The pattern covers requests for diagnoses, medications, hospitalizations, allergies, SSNs, and similar sensitive data tied to that person.

How the attack works

An attacker frames a request as if they have a normal reason to ask, pairing a relationship label ('my daughter, Anne') with a first name to make the query look like an innocent family concern. The prompt then asks the AI system for medical history, current medications, diagnoses, or identifiers such as Social Security number or date of birth. This framing is designed to bypass an assistant's caution about sharing personal health data by disguising surveillance as concern. The rule flags this specific combination — named target plus relationship label plus medical/identity data request — rather than general health questions.

Netzilo detection

Netzilo reports this behaviour when it is observed.

Signature ID
f9bdeba1-5f51-497d-b980-9ad03865022a
Severity
Critical

Why it matters

If the AI system has access to real medical records or personal data stores, this pattern can be used to extract information later used for insurance fraud, identity theft, or stalking a specific person.

What you can do

  • Restrict AI agents from accessing or returning identifiable medical records unless the requester's authorization to that specific person's data is verified.
  • Treat relationship-based framing ('my daughter', 'my husband') as a social-engineering signal, not proof of authorization.
  • Log and review requests that combine a named individual with medical, SSN, or date-of-birth data.
  • Separate general health-information responses from any response that discloses data tied to a specific identified person.

Known benign look-alikes

  • Law enforcement or forensics professionals with authorized access
  • Academic discussion of the medical system without targeting a named individual
  • General health questions about symptoms, medications, or conditions without targeting a named person

References

Related threats