Skip to main content

Research & secondary use of health data — governance baseline

Status: Normative governance baseline (policy + technical hooks; legal text is external)
Date: 2026-04-11
Audience: MoPH, IRB/ethics, universities, donors


1. Scope

This document frames secondary use of data originating in the Ghasi platform (analytics, public health, research) while clinical care remains governed by module SPEC.md and COMPLIANCE_SECURITY.md.


2. Principles

  1. Primary use first: Care delivery and legally mandated reporting take precedence.
  2. Purpose limitation: Secondary use requires documented purpose (surveillance vs research vs quality improvement).
  3. Minimum necessary: access-policy and ABAC enforce scope.
  4. De-identification: Research datasets SHOULD use de-identified or limited datasets per national law; identifiable research requires consent and IRB approval.
  5. Audit: Exports and researcher access emit audit events per audit.

3. Technical hooks (existing)

CapabilityRole
Aggregate / cohort exportshealth-populationexports, quality metrics, cohort refresh
Access policyRow-level / attribute-level decisions for who may run analytics
Audit serviceEvidence of who exported or accessed datasets
FHIR gatewayStandard partner API for authorized flows

4. Not covered in application code

  • IRB protocols, data use agreements, national data protection lawMoPH / legal owns these artifacts.
  • Trusted research environment (TRE) or federated learningroadmap; may extend platform with separate deployables.