Veterinary oncology is quietly becoming one of the most data-intensive corners of medicine. A single animal cancer patient may pass through emergency clinicians, radiologists, surgeons, medical oncologists, and radiation oncologists, generating bloodwork, ultrasound and CT images, biopsy reports, treatment plans, and dose records scattered across multiple institutions and information systems. A new framework published in the journal Veterinary Oncology by researchers at Cornell University’s College of Veterinary Medicine argues that this complexity, combined with the arrival of artificial intelligence, has outpaced the veterinary profession’s data privacy and management practices, leaving sensitive records more exposed than most owners realize.
The scale of the problem is not trivial. Unlike human healthcare, which operates under the Health Insurance Portability and Accountability Act in the United States and the General Data Protection Regulation in Europe, veterinary medicine has no equivalent overarching regulatory structure. Only 35 of the 50 US states impose specific regulations on protected animal information, and each implements them differently. The authors note that veterinary organizations have pursued no broad-ranging data security measures beyond financial privacy rules such as the Payment Card Industry Data Security Standard. The consequences are measurable: an estimated 11,000 smaller veterinary practices are attacked each year, and the average cyber claim costs around $135,000, with attacks on large academic institutions likely to incur escalating costs as cyberattacks on major human medical centers continue to rise.
What makes veterinary data uniquely difficult is the web of relationships surrounding each record. A single animal may have different owners over time, requiring careful handling of ownership information and consent for data sharing. Collaborative cancer care multiplies the number of practices, veterinarians, and caregivers involved, creating numerous points of vulnerability. The authors also distinguish between short-term clinical encounters, such as surgery for a stifle injury with follow-up rechecks, and the long-term client-patient-practitioner relationships typical of oncology, where data security and data use frameworks become central. Species diversity compounds the challenge, since desexing status, differing laboratory parameters, and species-specific conditions all shape how records must be structured and interpreted.
The fragmentation has real scientific costs. Despite growing dataset sizes in veterinary studies, the usage of informatics and big data approaches has not grown in step with human medicine, largely because established data-sharing frameworks are missing. Many practices, including large academic hospitals with full diagnostic, surgical, medical, and radiation oncology services, still maintain servers on-premises behind firewalls. Smaller clinics often lack the resources to manage complex data stores at all, and may need to turn to subscription-based software-as-a-service arrangements, in which case the authors recommend that practitioners specify data privacy guidelines in plain language before signing agreements. The COVID-19 pandemic offered a partial template, showing the value of independent intermediary bodies processing inputs from large and small contributors under consistent privacy practices, though veterinary medicine lacks the governing bodies and resources that made that effort possible.
At the technical core of the new framework are three pillars: encryption, access control, and anonymization. Encrypting electronic health records and client information both at rest and in transit prevents unauthorized access, while role-based authentication and user permission protocols limit data availability to authorized personnel. Anonymization techniques, such as stripping identifying information from research datasets and diagnostic images, allow data to be used for research without exposing owners. The authors highlight a marked gap between the de-identification standards applied to human and animal data, noting that there is sparse regulation on how veterinary data should be redacted when shared between institutions. In oncology, where rare cancers may cluster in specific towns or postal codes, generalizing epidemiological information to regional or state level may be necessary to achieve privacy protections comparable to human studies.
Cloud storage emerges as a pragmatic recommendation. Many veterinary practices in the United States still operate with paper records or on-premise servers, but cloud vendors often provide better security models than most organizations can achieve alone, thanks to dedicated teams and advanced data centers. The authors are careful to invoke the shared responsibility model, however: the cloud provider secures the infrastructure, but the institution remains responsible for securing its data and configurations within it. Novel approaches such as time-stamping authorities and blockchain-based methods can improve security against external attacks and maintain records of access to sensitive information, while regular backups, disaster recovery plans, and secure transmission channels such as virtual private networks and secure data portals offer safer alternatives to ordinary email.
Yet hardware and software are not the weakest link. Human error accounts for 88 to 95 percent of data breach incidents, with common failures including misdelivered sensitive data, weak passwords, phishing attacks, and lost or stolen devices. The authors argue that comprehensive staff training and periodic security updates are essential, citing evidence that even a short security course significantly improves an employee’s ability to identify phishing and false links. Regular audits, clear institutional privacy policies, and engagement with legal counsel round out the compliance picture, promoting transparency and accountability within veterinary healthcare institutions.
When data leaves the institution, as it routinely must in cancer care and multi-center research, the framework calls for formal data-sharing agreements that delineate terms of use, access rights, duration, and strict disclosure conditions. The authors draw a sharp distinction between commercial and academic partners. Commercial entities typically leverage data for market research and product development, often aggregating records from multiple centers through software products, and may seek exclusive ownership rights, requiring stringent confidentiality agreements. Academic institutions prioritize research, education, and open knowledge exchange, though the authors stress that ownership never means unrestricted access, and that data uses must always comply with confidentiality and consent agreements. To help smaller institutions that lack legal counsel, they propose that professional veterinary societies provide standardized boilerplate data-sharing agreements, and they recommend compliance audits by internal teams or independent third parties for large-scale arrangements.
Artificial intelligence raises the stakes considerably. The authors walk through the lifecycle of a single CT scan of a cat with a suspected nasal tumor, from raw projection data captured by the scanner, through reconstruction into DICOM files, migration to a picture archiving system, storage, retrieval, archiving, and eventual destruction, noting that veterinary-specific PACS may not adhere to HIPAA-style constraints such as automatic timeouts, individual logins, or secure image transmission. Feeding such heterogeneous records into AI pipelines demands preprocessing, labeling, and harmonization: one hospital’s diagnostic thresholds or terminology, such as labeling a tumor simply osteosarcoma versus appendicular osteosarcoma, can cause merged models to under- or over-predict risk. Standardized coding systems like SNOMED-VET CT could help, but are difficult to operationalize in routine care. Model performance also degrades through data shift and concept shift, where training populations differ from real-world deployment or the statistical properties of data change over time as treatments evolve.
The payoff, if these challenges are met, is substantial. In human medicine, radiology and radiation oncology AI products already dominate the FDA’s approved software-as-a-medical-device list, driven by digitalized foundations such as images, structures, and 3D dose distributions, and deep-learning auto-segmentation has recently been adapted for veterinary radiation planning. Multimodal machine learning that fuses imaging, pathology, genomics, and clinical data promises improved risk stratification and outcome prediction. The authors close with a call for standardized privacy regulations, data privacy education woven into veterinary curricula, and exploration of independent governed databases modeled on the National Surgical Quality Improvement Program, warning that regulation must be balanced against the real-world resource constraints of veterinary centers so that collaboration and innovation are not stifled. As AI moves deeper into clinical decision support and large language models begin synthesizing patient histories in veterinary practices, the question of who ingests, owns, and protects animal health data has become impossible to ignore.
Subject of Research: Data privacy and management frameworks for veterinary oncology records in the era of artificial intelligence
Article Title: Veterinary oncology data management in the era of artificial intelligence
Article References: Pu, S., Thompson, M., Ross, S., & Basran, P. S. (2025). Veterinary oncology data management in the era of artificial intelligence. Veterinary Oncology, 2(1), Article 29. https://doi.org/10.1186/s44356-025-00043-2
Image Credits: AI Generated
DOI: 10.1186/s44356-025-00043-2
Keywords: veterinary oncology, data privacy, artificial intelligence, data security, data sharing, encryption, anonymization, cybersecurity, machine learning, radiation oncology, data governance, veterinary informatics
Cite Scienmag News
Nathaniel Bowman. (October 1, 2026). Cancer Records for Cats and Dogs Expose a Data Privacy Gap AI Could Widen. Scienmag. https://scienmag.com/cancer-records-for-cats-and-dogs-expose-a-data-privacy-gap-ai-could-widen/
Nathaniel Bowman. "Cancer Records for Cats and Dogs Expose a Data Privacy Gap AI Could Widen." Scienmag, 1 October 2026, https://scienmag.com/cancer-records-for-cats-and-dogs-expose-a-data-privacy-gap-ai-could-widen/. Accessed 1 October 2026.
Nathaniel Bowman. "Cancer Records for Cats and Dogs Expose a Data Privacy Gap AI Could Widen." Scienmag. October 1, 2026. https://scienmag.com/cancer-records-for-cats-and-dogs-expose-a-data-privacy-gap-ai-could-widen/

