Secondary Use of Health Data for Research vs. Original Consent Scope
Establish a tiered secondary-use framework separating de-identified quality analytics from identifiable research, applying proportionate consent and ethical review to each tier.
CyberTRIZ analysis · Healthcare contradiction HD003 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Business Context
Health data collected during routine clinical care has substantial potential value for research, quality improvement, and population health analysis, and appropriately de-identified or aggregated secondary use of this data can advance medical knowledge and improve care for future patients well beyond the individual patient from whom the data originated. However, this data was typically collected under a consent scope focused on direct treatment, and using it for research or analytics purposes not clearly contemplated by the original consent raises legitimate questions about whether the patient’s actual expectations and legal rights are being respected.
Healthcare TRIZ Resolution
Rather than restricting all secondary use to only data covered by explicit, purpose-specific research consent, which would eliminate most of the value of large-scale retrospective analysis, or treating original treatment consent as sufficient authorization for any secondary use, the resolution establishes a tiered secondary-use framework: sufficiently de-identified, aggregated data that meets defined re-identification risk thresholds may be used for internal quality improvement and population health analysis under existing governance oversight, without requiring new patient-level consent, while any use involving identifiable data, external data sharing, or research publication requires a defined ethical review process and, where legally required, additional patient consent or notification, keeping the two categories clearly separated rather than conflated.
Applicable TRIZ Principles
Principle 1 – Segmentation Separate secondary data use into a de-identified, lower-risk tier and an identifiable, higher-risk tier, each governed by different requirements.
Principle 3 – Local Quality Apply consent and review requirements proportionate to the actual re-identification and privacy risk of each specific use case.
Principle 24 – Intermediary Use a defined ethical review process as an intermediary governance step for higher-risk secondary uses.
Expected Outcome
Preserved research and quality improvement value
Respected patient consent expectations
Clear, defensible governance boundaries
Reduced ambiguity in secondary use decisions
Decision Indicators
Early indicators that this contradiction is limiting organizational performance include:
No formal governance framework distinguishing de-identified aggregate use from identifiable secondary use of health data
Research or analytics projects proceeding without a defined re-identification risk assessment
Patient or advocacy group concerns raised about secondary use of health data beyond original treatment purposes
No ethical review process required for secondary uses involving identifiable patient data
Inconsistent practice across departments regarding what secondary uses are considered adequately covered by original treatment consent
Monitoring these indicators helps privacy, research, and legal leadership ensure secondary data use practices remain both scientifically valuable and ethically defensible.