AI can learn from data without ever having access to it
qz.com
qz.com
Without any special countermeasures, training a model on medical patient data and then releasing the model's parameters or even just making it possible for others to run the model on inputs they supply might allow someone to partially reconstruct the patient data.
This is a somewhat separate issue from whether the engineers building this system have access to the training data. You can achieve that by writing your training script and then running it in an environment that you don't personally have read access to.
On the real side, however, I think anyway in which we can keep people and their information safe in the face of progress are paths we should absolutely take.