← Back to news

Enabling Medical Data Privacy in AI

Confidential Medical AI

Yma Health lessons from live VPN for Healthcare implementations in the UAE

The Problem: Medical Data is Needed But Cannot Be Shared “As Is”

Personalized medicine and clinical AI services rely on comprehensive medical histories including diagnoses, prescriptions, test results, and visit chronology. Simple “de-identification” (replacing names with IDs) is insufficient, as combinations of dates, rare diagnoses, age, and events can still reveal a patient’s identity.

DHA policy is clear: effective anonymization must remove both direct identifiers and quasi-identifiers; after such anonymization, the data is no longer considered personal.

“Super Protocol’s TEE technology helped us solve a fundamental challenge in medical data transfer. Previously, we had to write extensive custom anonymization code. Now, Google’s medical AI model MedGemma handles this within the secure environment. I’m confident this approach will soon become standard across the health tech industry.”
Sergey Savvov. Co-founder and CTO, Yma Health

Yma Health Solution: “VPN for Healthcare” with Hardware Trust

The Concept: Just as a VPN protects internet traffic, our solution creates a secure channel for medical data where automatic anonymization happens before any further processing.

Zero-trust execution of healthcare data interpretation by AI systems

Solution Architecture

The entire solution operates on Super Protocolʼs decentralized, verifiable-by-design confidential AI cloud. Built on a zero-trust foundation, this architecture ensures that all data remains fully protected — inaccessible to anyone, including hardware, software and model providers involved, as well as Super Protocol itself.

All components and workloads are orchestrated, attested, and verified within Superʼs infrastructure. Before processing begins, the code, artifact hashes and environment integrity are cryptographically verified through Superʼs Certification System and Trusted Loader. If anything mismatches, the deployment is automatically rejected.

Auditable certificates allow third parties to verify that the exact build is running inside the verified TEE. Execution reports are automatically generated and immutably published on the blockchain — providing verifiable proof of what was executed, where, and how.

For this project, Super Protocol leveraged its serverless confidential computing infrastructure to run workloads across two independently operated environments:

  • Nebius AI Cloud — equipped with NVIDIA HGX B200 (Blackwell) GPUs and Intel TDX–enabled CPUs, used for large-model inference with Google MedGemma 27B.
  • Confidential Service Provider (CSP) — hosting AMD SEV-SNP–enabled CPUs for anonymization and preprocessing services.

Every data flow — from EHR extraction to anonymization to MedGemma inference — runs in TEE mode, with encrypted and verifiable communication through Super Protocolʼs Confidential Tunnels, providing full end-to-end protection and regulatory compliance.

The open-source service runs inside Super Protocol on CPU-only confidential instances. Since anonymization and preprocessing are not computationally intensive, it does not require GPU acceleration. This service processes data extracted from EHR systems and prepares it for secure AI inference.

Super Protocol Confidential Tunnels

  • API publication and data exchange occur exclusively through Super’s tunnels:
  • Tunnel server receives a public IP/443 and accepts HTTPS traffic.
  • Tunnel client deploys a local HTTPS server and remains hidden; application access is only available through token authentication and a valid TLS certificate.
  • Both components operate inside TEEs, and the connection is configured through DNS A and TXT records.

The above architecture provides web access, load balancing, and complete isolation of the application from direct external access and exposure.

Beyond secure communication, Superʼs Tunnels also enable confidential scaling — connecting multiple TEE-based deployments into a unified, verifiable environment that balances load, ensures confidentiality, and provides fault tolerance across providers or environments.

  • “Smart” Anonymization with Open Models;
  • The anonymization process uses Google MedGemma 27B-multimodal, an open medical model collection based on Gemma 3, specially adapted for medical text and images;
  • It preserves clinical meaning while removing Protected Health Information (PHI). The model is served through vLLM with an OpenAI-compatible API and high throughput;
  • Performance and Confidentiality on GPU;
  • Model inference runs on NVIDIA HGX B200 GPUs in confidential mode protecting models and data during execution. These Blackwell (B200) GPU resources are provided by Nebius AI Cloud and operate entirely within Super Protocolʼs verifiable confidential layer. The combination of Blackwellʼs 192 GB memory and the vLLM inference engine enables MedGemma-27B to fit efficiently on a single GPU in TEE mode — ensuring high performance while keeping all computations secure and data fully confidential.

How It Works (Data Flow)

VPN for Healthcare Architecture
  • Yma Health requests patient data through the secure anonymization service within UAE
  • Anonymization Middleware (running in a protected environment) forwards the request to the Electronic Health Record (EHR) system
  • EHR returns raw patient data back to the middleware through secure tunnels
  • Smart AI processing: The data is sent to MedGemma AI model (also in protected environment) which understands medical context
  • Intelligent anonymization: MedGemma removes all personal identifiers while preserving medical value.
  • Clean data returns to Yma Health — fully anonymized and ready for AI analysis

Legal Compliance & Security Guarantees

  • DHA Health Information Sharing Policy requires anonymization to exclude both direct identifiers and quasi-identifiers; properly anonymized data is no longer considered personal. Yma Health’s process model complies with this requirement: PHI is never used outside attested TEEs, and only anonymized results are released.
  • Confidential Computing and Attestation: Super Protocol automates remote attestation, verifies bootloader/workload hashes, and publishes confirmations; execution is blocked if verification fails. This allows external parties to verify the environment and code without accessing the actual data

Implementation Cases:

Case 1: Simplex Himes — Expanding EHR Capabilities

Simplex Himes is a certified EHR provider in UAE serving many clinics. The company wanted to add AI functionality but couldn’t transfer patient data to external AI services due to regulatory restrictions.

Solution: We integrated anonymization middleware as a proxy layer where all EHR data passes through anonymization before AI processing while maintaining full compliance with Dubai data protection requirements.

Result: Simplex now offers AI-assisted clinical workflows, clinics get expanded functionality without risks, and the system has the ability to scale across the entire clinic network.

“We wanted to partner with AI-native companies like YMA, but secure data transfer was always the blocker. The anonymization solution from YMA and Super Protocol finally solves this — we can now confidently share medical data knowing it’s fully protected in their secure environment.”

Giri Rajan. CTO / Managing Director Simplex Himes

Case 2: JointSpace Clinic — Secure AI for Physical Therapy

JointSpace is a physical therapy clinic that accumulated valuable patient treatment data but couldn’t use it for AI analysis due to concerns about confidential information leaks.

Solution: Using the interface JointSpace could securely upload patient medical histories. The system automatically anonymizes all data before transferring it to Yma AI for processing, which then generates clinical valid insights based on anonymized information.

Result: This implementation enabled the clinic to safely leverage AI technology for the first time. Their treatment plans improved significantly based on comprehensive data analysis, and patients reported increased trust in the clinic due to the strong privacy guarantees provided by the system.

“We wanted to use AI for personalized patient communication, but sending data to external APIs was a non-starter. YMA’s anonymization service solved this perfectly — now we can leverage advanced AI while our patient data stays completely protected.”

Kris Rai. Co-founder / Clinical Director Joint Space

Conclusion

YMA Health, in partnership with Super Protocol, Nebius, NVIDIA, and Google, has created a breakthrough solution that for the first time allows safe use of medical data for AI while maintaining complete patient privacy — pioneering this approach in the UAE.

“VPN for Healthcare” is not just a technology but a new paradigm for working with medical data where privacy and innovation no longer contradict each other.

The solution has already proven its effectiveness with real customers — Simplex Himes and JointSpace Clinic — and is ready to scale across the entire healthcare industry.