Research
Our research database is built from clinical care and stripped of identity by design. Researchers see patterns, never people.
What the database holds
Measurements and clinical facts that matter for long-term health: laboratory results, imaging findings, vital signs, medications and supplements, diagnoses and screenings. Each fact is tied to a random study number, not to a person.
What it never holds
- Names, medical record numbers, email addresses, phone numbers and street addresses
- ZIP codes, dates of birth, and photographs
- Visit notes, transcripts and any free-text written by or about a patient
How identity is removed
HIPAA Safe Harbor
We follow the Safe Harbor method of the HIPAA Privacy Rule, which removes the listed categories of identifiers.
No real dates
Events are recorded as a count of days from each person’s own starting point, so the spacing between results is preserved without revealing when anything happened.
Ages capped at 90
Everyone older than 90 is grouped together, as Safe Harbor requires.
Random study numbers
Each person receives a randomly assigned number. It is not a scrambled version of any record number, so it cannot be worked backward.
Rebuilt every night
The research database is not edited by hand. It is wholly derived from the clinical record and rebuilt from scratch each night, so a correction in the medical record flows through automatically, and nothing lives only in the research copy.
A safeguard that errs on the side of caution
Test names and labels are screened before they enter the database. Anything that looks like it could contain a name is held back for review. We would rather lose a measurement than expose a person.
Who has access
Access is limited to named physician researchers. The only link between a study number and a real person is kept inside the medical practice’s own protected systems, never in the research database.
