Security
Patient data stays in your environment.
Clinical Extract runs inside your environment and exports only the variables your protocol approved, to storage you control.
Clinical Extract has read-only access, and no PHI is sent to us.
1 The data path
The data path runs inside your environment.
Patient data moves on one path: from your EHR to Clinical Extract to your study folder. Clinical Extract runs on your server or in your cloud tenant, next to the EHR it reads, and the NDJSON files, study.csv and data-dictionary.json land in storage you control. Only Clinical Extract software comes in, and we never receive patient data.
2 Scopes
Read-only scopes, one per resource type.
The token Clinical Extract presents carries one read scope per resource type the study reads and system/Group.read for the cohort. Those scopes allow read and search only. The export starts from the study cohort's Group and reaches the cohort's members only. Each study's token carries the resource types its protocol names, and a study that reads no medications carries no medication scope.
3 Minimum necessary
How the export enforces minimum necessary.
The Privacy Rule's minimum necessary standard (45 CFR 164.502(b)) asks a covered entity to limit protected health information to what the purpose needs. Clinical Extract enforces it at three levels in the export itself: the Group scopes the patients to the cohort, _type scopes the resource types, and the approved variable list scopes the columns. A variable the protocol did not approve never reaches study.csv, and the data dictionary records which variables did. The dictionary also drives the informatics team's release step.
Your privacy office reviews the deployment like any other in-house system, with the data path in Figure 1 and the scopes in Figure 2. For the agreements HIPAA asks of vendors, our checklist for business associate agreements is the reference.
A limited data set (45 CFR 164.514(e)) is one variable list: dates and geography kept, direct identifiers out. A fully identified extract under an IRB waiver is another. The dictionary is the record of which one you exported. A review preparatory to research needs only counts: the cohort builder returns the count before any record moves.
4 Your controls
What runs where in your environment.
- Your compute
- We install one container on your server or cloud tenant, built from the release source with the Dockerfile. It runs under your access controls. Health check at
/healthz, version at/api/version. - Your key store
- The RSA private key as a read-only mounted file or an injected secret; the public key at the JWKS URL Clinical Extract serves, the one path an EHR vendor fetches.
- Your storage
- The NDJSON, study.csv and data-dictionary.json in a study folder under your access controls; nothing is sent anywhere else.
- Your log
- Each run step, token request and JWKS fetch is written to the server log in your environment, size-rotated, yours to keep.
- Your front door
- The dashboard sits behind your reverse proxy's authentication or the built-in login; only the JWKS path is public. Deployment in your environment has the settings.
- Outbound only to the EHR
- Clinical Extract's outbound calls go to your EHR alone, over HTTPS on port 443: the token endpoint, the Group kickoff, the status URL, each file URL.
5 Questions
Questions about security
Is the export read-only?
The token Clinical Extract presents carries one system/<Resource>.read scope per resource type the study reads, plus system/Group.read for the cohort. Those scopes allow read and search only, so Clinical Extract cannot create or change a record.
Where is the private key?
In your key store: a file mounted read-only into the container, or a secret your platform injects. It signs the JWT for every token request and never leaves your environment; the EHR holds only the public key, at the JWKS URL Clinical Extract serves or as an uploaded certificate.
What does minimum necessary mean for a study export?
Three limits, applied in the export itself: the Group scopes the patients to the cohort, _type scopes the resource types the protocol reads, and the approved variable list scopes the columns. A variable the protocol did not approve never reaches study.csv.
Who can see the study folder?
Whoever your access controls allow. The NDJSON, study.csv and data-dictionary.json land on the server or cloud tenant you run Clinical Extract on, under your own storage, identity and audit controls.
Next
See Clinical Extract run on one of your studies.
Tell us which EHR you run and what the study or registry needs. We reply within one business day to set a meeting time.