Case Study Healthcare
Identifying, Masking and Democratizing Sensitive Patient Data on IDMC
Automated sensitive-data discovery, format-preserving masking, and governed self-service access for a large healthcare provider, built on Informatica IDMC
From scattered PHI to governed, self-service research access
Summary
A large healthcare provider needed to identify sensitive medical data scattered across disparate systems, protect it during testing and analytics, and safely open it up for research — all under strict HIPAA compliance requirements. aiDataWorks implemented Informatica's Intelligent Data Management Cloud (IDMC) in three phases: automated, ML-driven discovery and classification of sensitive patient data; dynamic, format-preserving masking applied consistently across development, testing, and analytics environments; and a self-service access layer with role-based controls and audit trails for researchers and analysts. The engagement strengthened data security and HIPAA compliance, preserved data utility for research, and accelerated medical research through safer, broader access to de-identified data.
The challenge
- Sensitive data scattered across disparate systems. The provider struggled to accurately identify and classify sensitive patient information spread across disparate systems and databases.
- Privacy versus data utility. Patient privacy needed to be protected during processing for research, analytics, and testing without compromising the usefulness of the underlying data.
- Restricted access held back innovation. Locked-down access to patient data limited research and analytics use, hindering innovation across the organization.
- HIPAA compliance as a non-negotiable priority. Regulatory compliance and data security were paramount organizational priorities that any solution had to satisfy.
The solution
How we built it
1. Sensitive data identification
- Used IDMC's automated metadata scanning and ML-based classification to identify sensitive patient data across structured and unstructured sources.
- Tagged sensitive data consistently as it was discovered, so downstream teams could act on a common classification.
- Produced a map of where sensitive patient data resided across the provider's systems and databases.
2. Data masking
- Implemented IDMC's dynamic, format-preserving data masking to de-identify sensitive patient details.
- Applied masking consistently across development, testing, and analytics environments.
- Preserved data integrity so masked datasets remained usable for downstream processing.
3. Democratization of data
- Enabled IDMC's self-service capabilities so authorized researchers and analysts could securely access de-identified datasets.
- Governed access with role-based access controls tied to user and purpose.
- Captured audit trails across access and use to support ongoing HIPAA compliance.
Outcomes
- Strengthened data security and HIPAA compliance, reducing the risk of data breaches and privacy violations.
- Preserved data utility for research and analytics despite masking, keeping de-identified datasets usable for downstream work.
- Accelerated the pace of medical research through democratized, governed access to sanitized data.
Solving something similar?
We will walk your current data landscape and show you what a governed, secure approach to sensitive data would take.
