Compliance & Governance

Privacy-first platform built on rigorous de-identification, secure transmission, and comprehensive governance frameworks.

De-identified Data

All patient data in the Lighthouse platform has been de-identified using expert determination methods designed to comply with applicable privacy regulations, including the HIPAA Privacy Rule.

De-identification is performed prior to data entering our systems. Direct identifiers (names, addresses, dates of birth, medical record numbers, etc.) are removed, and indirect identifiers are generalized or suppressed to reduce re-identification risk.

Lighthouse does not collect, store, or transmit protected health information (PHI). All datasets provided to customers contain only de-identified data.

Governed Access

Access to Lighthouse datasets is controlled through formal data use agreements (DUAs) that specify permitted uses, security requirements, and compliance obligations.

Contracting: Every customer executes a DUA before receiving data. The agreement defines scope of use, security standards, and return/destruction obligations.

Permitted Uses: Data may only be used for the specific research, trial, or AI/ML purposes documented in the DUA. Use outside the stated purpose is prohibited.

Auditability: Lighthouse maintains audit logs of data delivery, access, and customer interactions to support compliance reviews and regulatory inquiries.

Security Posture

Lighthouse employs enterprise-grade security controls to protect data confidentiality and integrity throughout the dataset assembly and delivery process.

Encryption: Data in transit is protected using TLS/SSL encryption. Data at rest is encrypted using industry-standard methods.

Secure Transfer: Datasets are delivered via secure channels (e.g., encrypted S3 buckets, SFTP, Snowflake secure share) with access limited to authorized recipients.

Access Controls: Role-based access controls, multi-factor authentication, and least-privilege principles govern internal access to systems and data.

Customer Obligations

Customers receiving Lighthouse datasets are subject to specific obligations designed to maintain privacy protections and appropriate use.

No Re-identification: Customers must not attempt to re-identify individuals or link Lighthouse data to other datasets in a manner that could reveal patient identity.

Use Limitations: Data must be used only for the purposes specified in the data use agreement. Prohibited uses include marketing, credit/insurance underwriting, and individual decision-making.

Security Standards: Customers must implement appropriate administrative, technical, and physical safeguards to protect the confidentiality of received datasets.

Data Handling: Upon completion of the authorized use or termination of the agreement, customers must return or destroy datasets as specified in the DUA.

Important Notice

Do not submit protected health information (PHI) through this website or any web forms.Lighthouse provides access to de-identified data only. If you need to discuss specific patient cases or PHI as part of a data request, please contact us directly to establish a secure communication channel.

Questions About Compliance?

We're happy to discuss our governance framework, security controls, and compliance processes in detail.

Request Access
Lighthouse

Privacy-first platform for governed access to de-identified patient data.

© 2026 Lighthouse Data Solutions. All rights reserved.

Important: Lighthouse provides governed access to de-identified data only. All data has been anonymized in accordance with applicable privacy regulations. Do not submit protected health information (PHI) through this website.

base44
Edit with Base44