RESEARCH DATA USE
Pending legal reviewPurpose-bound research data use.
This draft policy describes the intended safeguards shown in the Research workspace. It is not an ethics approval, data-use agreement, or de-identification determination.
Aggregate-first feasibility
Researchers see cohort counts and data-fitness measures before any participant-level output. Small cells are suppressed, unknown values remain separate from exclusions, and direct identifiers stay out of research exports.
Permission and approval
Requests attach a study identifier and purpose, ethics or IRB status, data-use agreement status, access duration, expiry, region, and onward-sharing rule. Exports remain disabled until the required approvals and an active patient permission are present.
Anonymized and pseudonymized are different
Pseudonymized data replaces direct identity with a scoped code but may remain linkable under controlled conditions. Anonymized data is intended to fall outside identification risk under the applicable legal standard. Caduceus does not treat pseudonymous output as anonymous.
Secure analysis by default
The intended default is a secure analysis environment with organization isolation, role-based access, audit history, export controls, retention limits, and revocation enforcement. Production design and assurance remain pending technical and legal validation.
Data minimization and provenance
Approved data should remain limited to the declared study purpose and approved fields. Source, collection date, recency, missingness, methods, limitations, permission basis, and export history remain attached or visible.
Revocation and deletion
Revocation stops future access under the permission. It may not automatically undo processing already lawfully completed; deletion, retention, archival, and research-integrity exceptions must be defined in the final agreement and notice.
Last updated August 4, 2026. Placeholder text is not a final legal notice, contract, certification, or compliance claim.
