Compliance & Governance
Privacy-first platform built on rigorous de-identification, secure transmission, and comprehensive governance frameworks.
De-identified Data
All patient data in the Lighthouse platform has been de-identified using expert determination methods designed to comply with applicable privacy regulations, including the HIPAA Privacy Rule.
De-identification is performed prior to data entering our systems. Direct identifiers (names, addresses, dates of birth, medical record numbers, etc.) are removed, and indirect identifiers are generalized or suppressed to reduce re-identification risk.
Lighthouse does not collect, store, or transmit protected health information (PHI). All datasets provided to customers contain only de-identified data.
Governed Access
Access to Lighthouse datasets is controlled through formal data use agreements (DUAs) that specify permitted uses, security requirements, and compliance obligations.
Contracting: Every customer executes a DUA before receiving data. The agreement defines scope of use, security standards, and return/destruction obligations.
Permitted Uses: Data may only be used for the specific research, trial, or AI/ML purposes documented in the DUA. Use outside the stated purpose is prohibited.
Auditability: Lighthouse maintains audit logs of data delivery, access, and customer interactions to support compliance reviews and regulatory inquiries.
Security Posture
Lighthouse employs enterprise-grade security controls to protect data confidentiality and integrity throughout the dataset assembly and delivery process.
Encryption: Data in transit is protected using TLS/SSL encryption. Data at rest is encrypted using industry-standard methods.
Secure Transfer: Datasets are delivered via secure channels (e.g., encrypted S3 buckets, SFTP, Snowflake secure share) with access limited to authorized recipients.
Access Controls: Role-based access controls, multi-factor authentication, and least-privilege principles govern internal access to systems and data.
Customer Obligations
Customers receiving Lighthouse datasets are subject to specific obligations designed to maintain privacy protections and appropriate use.
No Re-identification: Customers must not attempt to re-identify individuals or link Lighthouse data to other datasets in a manner that could reveal patient identity.
Use Limitations: Data must be used only for the purposes specified in the data use agreement. Prohibited uses include marketing, credit/insurance underwriting, and individual decision-making.
Security Standards: Customers must implement appropriate administrative, technical, and physical safeguards to protect the confidentiality of received datasets.
Data Handling: Upon completion of the authorized use or termination of the agreement, customers must return or destroy datasets as specified in the DUA.
Important Notice
Do not submit protected health information (PHI) through this website or any web forms.Lighthouse provides access to de-identified data only. If you need to discuss specific patient cases or PHI as part of a data request, please contact us directly to establish a secure communication channel.
Questions About Compliance?
We're happy to discuss our governance framework, security controls, and compliance processes in detail.
Request Access