Erm, in the United States we have HIPAA which directly makes "a third-party cloud service" "legally obliged to respect the privacy of their patients and the confidentiality of medical data". Besides, using AI doesn't have to mean using centralized cloud architecture.