Saurabh, Rochi
Cani, Anikamila
Möller, Marius
Busch, Hauke
Funding for this research was provided by:
Universität zu Lübeck
Article History
Received: 7 May 2024
Accepted: 28 October 2024
First Online: 3 December 2024
Competing interests
: The authors declare no competing interests.
: TriNetX is compliant with the Health Insurance Portability and Accountability Act (HIPAA), the US federal law which protects the privacy and security of healthcare data. TriNetX is certified to the ISO 27001:2013 standard and maintains an Information Security Management System (ISMS) to ensure the protection of the healthcare data it has access to and to meet the requirements of the HIPAA Security Rule. Any data displayed on the TriNetX Platform in aggregate form, or any patient-level data provided in a data set generated by the TriNetX Platform, only contains de-identified data as per the de-identification standard defined in Section §164.514(a) of the HIPAA Privacy Rule. The process of de-identifying data is attested to through a formal determination by a qualified expert as defined in Section §164.514(b)(1) of the HIPAA Privacy Rule, which supersedes the need for the waiver that was previously granted to TriNetX by the Western Institutional Review Board (WIRB). This formal determination by a qualified expert was refreshed in December 2020. The TriNetX network contains data provided by participating healthcare organizations (HCOs), each of which represents and warrants that it has all necessary rights, consents, approvals, and authority to provide the data to TriNetX under a Business Associate Agreement (BAA), so long as their name remains anonymous as a data source and their data are utilized for research purposes. The data shared through the TriNetX Platform are attenuated to ensure that they do not include sufficient information to facilitate the determination of which HCO contributed which specific information about a patient. In particular, this means that the HCOs guarantee under the BAA that they have obtained the informed consent of all patients whose data this study is based on, and that the need for further informed consent is waived by the WIRB and the formal determination. Furthermore, all the experimental procedures in this study were performed in accordance with the relevant guidelines.