CyberTRIZPEDIA

Secondary Use of Health Data for Research vs. Original Consent Scope

Establish a tiered secondary-use framework separating de-identified quality analytics from identifiable research, applying proportionate consent and ethical review to each tier.

CyberTRIZ analysis · Healthcare contradiction HD003 · one of 8,235 worked contradictions published by CyberTRIZ.AI

Regulations

Business Context

Health data collected during routine clinical care has substantial potential value for research, quality improvement, and population health analysis, and appropriately de-identified or aggregated secondary use of this data can advance medical knowledge and improve care for future patients well beyond the individual patient from whom the data originated. However, this data was typically collected under a consent scope focused on direct treatment, and using it for research or analytics purposes not clearly contemplated by the original consent raises legitimate questions about whether the patient’s actual expectations and legal rights are being respected.

Healthcare TRIZ Resolution

Rather than restricting all secondary use to only data covered by explicit, purpose-specific research consent, which would eliminate most of the value of large-scale retrospective analysis, or treating original treatment consent as sufficient authorization for any secondary use, the resolution establishes a tiered secondary-use framework: sufficiently de-identified, aggregated data that meets defined re-identification risk thresholds may be used for internal quality improvement and population health analysis under existing governance oversight, without requiring new patient-level consent, while any use involving identifiable data, external data sharing, or research publication requires a defined ethical review process and, where legally required, additional patient consent or notification, keeping the two categories clearly separated rather than conflated.

Applicable TRIZ Principles

Principle 1 – Segmentation Separate secondary data use into a de-identified, lower-risk tier and an identifiable, higher-risk tier, each governed by different requirements.

Principle 3 – Local Quality Apply consent and review requirements proportionate to the actual re-identification and privacy risk of each specific use case.

Principle 24 – Intermediary Use a defined ethical review process as an intermediary governance step for higher-risk secondary uses.

Expected Outcome

Preserved research and quality improvement value

Respected patient consent expectations

Clear, defensible governance boundaries

Reduced ambiguity in secondary use decisions

Decision Indicators

Early indicators that this contradiction is limiting organizational performance include:

No formal governance framework distinguishing de-identified aggregate use from identifiable secondary use of health data

Research or analytics projects proceeding without a defined re-identification risk assessment

Patient or advocacy group concerns raised about secondary use of health data beyond original treatment purposes

No ethical review process required for secondary uses involving identifiable patient data

Inconsistent practice across departments regarding what secondary uses are considered adequately covered by original treatment consent

Monitoring these indicators helps privacy, research, and legal leadership ensure secondary data use practices remain both scientifically valuable and ethically defensible.

TRIZ principles applied

P1 SegmentationP3 Local qualityP24 Intermediary