Snowflake healthcare data platform integrating EMR, claims and laboratory data with PHI security

Zero HIPAA Audit Findings After 11-Week Snowflake Implementation

Healthcare Data Integration | HL7/FHIR Pipelines | PHI Security & Governance

At a Glance

IndustryHealthcare
OrganizationRegional healthcare system with 7 hospitals
ServicesSnowflake Implementation, Healthcare Data Integration, Data Engineering, Data Security & Governance
ChallengeHealthcare data was distributed across three EMRs, a claims system, and a laboratory provider, requiring a unified platform with appropriate PHI controls.
SolutionBuilt a Snowflake platform using Data Vault modeling, HL7/FHIR Snowpipe ingestion pipelines, PHI tagging, and data masking.
Key ResultPlatform deployed in 11 weeks with zero compliance findings in its first HIPAA audit.

About the Client

The client is a regional healthcare system operating seven hospitals and managing clinical and operational data across multiple healthcare applications.

Data sources included three electronic health record (EHR/EMR) systems as well as a claims system and a laboratory vendor.

The Challenge

They were looking to load these into the same data platform, which was Snowflake, and ensure that private patients' info wasn't compromised at any stage of the project.

At the start of our journey, we learned healthcare information was fragmented and residing in many clinical and administrative systems.

The major problems we came across were:

  • Several Electronic Medical Records Systems: Clinical details were kept on three different EMR products.
  • Decoupled Healthcare Data: Billing and lab data only came outside of the core EMR environments.
  • Healthcare Interoperability: Clinical data was being ingested from the pipelines supporting HL7 and FHIR data formats.
  • PHI of high sensitivity: It's necessary to be vigilant, identify, and protect Protected Health Information within the data platform in appropriate ways.
  • Compliance Requirements: In order for the organization to comply with HIPAA requirements, secure and governance controls are a must.
  • Healthcare Environment with More than one Hospital: The common underlying data for the platform must be there among the seven hospitals.

For the first time, the solution required a single healthcare data platform to address integration and protection of PHI, rather than adding governance at the end of deployment.

The Solution

At the request of the customer, Aegis Softtech provided Snowflake consulting and implementation expertise, designing and building a single Snowflake healthcare data platform that included clinical, billing, and lab data. Their solution consisted of a Data Vault model, HL7/fhir ingestion via Snowpipe, and PHI-security controls, which all combined into a governed Snowflake platform for the customer hospital.

Unified Healthcare Data Platform

The data collected from the three EMR systems, the claims system, laboratory provider was all unified onto the Snowflake centralized environment.

The initiative created the ability to work on healthcare data coming from seven different hospitals in the system in a single place.

Data Vault Modeling

The team decided to go with a Data Vault model to organize and present the unified healthcare data on Snowflake.

This method laid out a framework that could handle data from various healthcare source systems while also capturing and keeping all the relationships required throughout the data environment.

HL7/FHIR Snowpipe Ingestion

The Snowpipe ingestion pipelines were developed to receive healthcare data in HL7 and FHIR formats and store them in Snowflake.

Brought-in of clinical data through structured ingestion pipelines from the healthcare organization's source system has been enabled by this feature.

PHI Tagging

Within the platform, from the beginning, they recognized and put a label on PHI (Protected Health Information).

The identification of PHI in this way laid a solid base that would enable the application of suitable control measures for the sensitive healthcare data later on.

PHI Data Masking

To secure PHI within Snowflake, the masks have been created using masking policies.

Instead of seeing that the data protection measures have to be done after the development, the masking activities were part of the platform's initial security and governance planning.

Security and Governance from Day One

PHI tagging and masking are part of the first step of the solution.

Using the security-by-design approach that they were implementing, they could be sure that with every step of the development of the healthcare platform, sensitive healthcare information governance was done and not that the controls had to be fitted into production before the launch.

Production Deployment in 11 Weeks

All components of the unified Snowflake platform, including healthcare data integration, ingestion pipelines, PHI tagging, masking, Data Vault modeling, and production readiness, were rolled out in 11 weeks.

Summary of Outcomes

The healthcare system had its needs secured while receiving an innovative Snowflake platform that united all data under one banner.

The Technology Behind the Implementation

  • Snowflake
  • Snowpipe
  • Data Vault Modeling
  • HL7
  • FHIR
  • Tagging of PHI
  • Dynamic Data Masking
  • Healthcare data integration into the platform.
  • Data Governance
  • HIPAA-Aligned Security Controls

Interested in a Healthcare Data Platform on Snowflake that Ensures Privacy?

Aegis Softtech is committed to delivering the very latest in medical Snowflake data platforms that include and combine all kinds of patient data ( clinical, claims, laboratory, and even more) and at the same time guarantee all the security regulations are in place from day one.

From the ingestion and conversion of clinical data in formats like HL7/FHIR and the building of medical data models to the protection of PHI and the deployment of the production system, the Aegis Softtech team will help you build and implement a safe and scalable medical data framework.

Talk to the Aegis Softtech Snowflake Expert

*Client identity is confidential.*