Client: A technology company building a secure data platform for the healthcare research sector
Engagement: Human-centered discovery, product strategy, and end-to-end build
OUTCOMES AT A GLANCE
35%
More analytical utility preserved vs. traditional anonymization
3 wks → 5 days
To prepare data for ethics review
2
Healthcare research organizations now in paid pilots
The starting point
The organization set out to help healthcare researchers share sensitive patient data securely and ethically. The initial concept centered on data anonymization — a genuine need in a field where regulations like HIPAA, GDPR, and PIPEDA make data sharing legally complex and high-risk, and where a single compliance misstep can halt a study.
But anonymization is a crowded space, with established tools competing on the same technical features. So before building anything, we started where we always do: not with the technology, but with the work. We set out to understand how healthcare researchers actually handle sensitive data day to day — where their time, their confidence, and their compliance really break down.
Client: A technology company building a secure data platform for the healthcare research sector
Engagement: Human-centered discovery, product strategy, and end-to-end build
OUTCOMES AT A GLANCE
35%
More analytical utility preserved vs. traditional anonymization
3 wks → 5 days
To prepare data for ethics review
2
Healthcare research organizations now in paid pilots
The starting point
The organization set out to help healthcare researchers share sensitive patient data securely and ethically. The initial concept centered on data anonymization — a genuine need in a field where regulations like HIPAA, GDPR, and PIPEDA make data sharing legally complex and high-risk, and where a single compliance misstep can halt a study.
But anonymization is a crowded space, with established tools competing on the same technical features. So before building anything, we started where we always do: not with the technology, but with the work. We set out to understand how healthcare researchers actually handle sensitive data day to day — where their time, their confidence, and their compliance really break down.
Mapping how the work really happens
We spoke with healthcare researchers to understand their real concerns — and the most important one wasn’t whether data could be anonymized. It was whether the data stayed useful afterward. A recurring frustration surfaced: traditional anonymization often strips so much value from a dataset that the findings become unreliable. For a researcher, privacy that destroys analytical integrity isn’t a solution — it’s a dead end.
We paired that with the institutional view, working directly with PIPEDA experts and compliance consultants to understand what regulators actually demand, where institutions get exposed, and what an ethics review genuinely requires. Two truths emerged from listening to how the work really happened: researchers needed data that was still usable, and institutions needed decisions that were defensible
The problem behind the problem
That discovery reframed everything. The company knew data had to be anonymized — but the real problem sat one layer deeper. Researchers didn’t trust that anonymized data would still support valid findings, and institutions couldn’t easily prove their compliance decisions to ethics boards and auditors. Ethics-review prep, audit trails, documentation, and representation gaps were where projects actually stalled — sometimes for weeks.
The right problem wasn’t “anonymize the data.” It was “make sensitive healthcare data ready — private, still analytically useful, compliant, and defensible.” Finding that problem — by watching how people really worked — is what made the rest of the engagement worth doing.
Mapping how the work really happens
We spoke with healthcare researchers to understand their real concerns — and the most important one wasn’t whether data could be anonymized. It was whether the data stayed useful afterward. A recurring frustration surfaced: traditional anonymization often strips so much value from a dataset that the findings become unreliable. For a researcher, privacy that destroys analytical integrity isn’t a solution — it’s a dead end.
We paired that with the institutional view, working directly with PIPEDA experts and compliance consultants to understand what regulators actually demand, where institutions get exposed, and what an ethics review genuinely requires. Two truths emerged from listening to how the work really happened: researchers needed data that was still usable, and institutions needed decisions that were defensible
The problem behind the problem
That discovery reframed everything. The company knew data had to be anonymized — but the real problem sat one layer deeper. Researchers didn’t trust that anonymized data would still support valid findings, and institutions couldn’t easily prove their compliance decisions to ethics boards and auditors. Ethics-review prep, audit trails, documentation, and representation gaps were where projects actually stalled — sometimes for weeks.
The right problem wasn’t “anonymize the data.” It was “make sensitive healthcare data ready — private, still analytically useful, compliant, and defensible.” Finding that problem — by watching how people really worked — is what made the rest of the engagement worth doing.
What we built — around the workflow, not just the algorithm
Working from that insight, we designed and built the platform around the researcher’s real workflow. The result was an AI-powered engine that adapts its anonymization to each dataset’s structure, sensitivity, and intended use — and, critically, explains its decisions, generating the audit trails and compliance documentation that PIPEDA -governed ethics reviews actually require. We paired it with representation and bias analysis, so dataset gaps are flagged before they distort findings, with the researcher always in control.
Our build approach was deliberately evidence-driven. We started with a specific data structure, tested it with researchers, and compared our results against the same dataset anonymized by traditional methods and existing tools. Then we went back to the researchers who had originally used that data and asked whether their findings still held — measuring the integrity of the results, not just the privacy. We iterated that loop across progressively more complex datasets, refining the engine each cycle until it preserved analytical value across a range of real-world healthcare data.
Map the work
Find the leverage Build what fits Interviewed researchers and compliance stakeholders; mapped where time leaked, decisions stalled, and documentation became painful.
Find the leverage
Reframed the opportunity from generic anonymization to research data readiness, with clear value for users and institutions.
Build what fits
Led product strategy, AI design, prototyping, build, and workflow integration around how researchers already worked.
Validate
Tested outputs with representative datasets and researchers, measuring utility, review prep time, and pilot readiness.
What we built —around the workflow, not just the algorithm
Working from that insight, we designed and built the platform around the researcher’s real workflow. The result was an AI-powered engine that adapts its anonymization to each dataset’s structure, sensitivity, and intended use — and, critically, explains its decisions, generating the audit trails and compliance documentation that PIPEDA -governed ethics reviews actually require. We paired it with representation and bias analysis, so dataset gaps are flagged before they distort findings, with the researcher always in control.
Our build approach was deliberately evidence-driven. We started with a specific data structure, tested it with researchers, and compared our results against the same dataset anonymized by traditional methods and existing tools. Then we went back to the researchers who had originally used that data and asked whether their findings still held — measuring the integrity of the results, not just the privacy. We iterated that loop across progressively more complex datasets, refining the engine each cycle until it preserved analytical value across a range of real-world healthcare data.
Map the work
Find the leverage Build what fits Interviewed researchers and compliance stakeholders; mapped where time leaked, decisions stalled, and documentation became painful.
Find the leverage
Reframed the opportunity from generic anonymization to research data readiness, with clear value for users and institutions.
Build what fits
Led product strategy, AI design, prototyping, build, and workflow integration around how researchers already worked.
Validate
Tested outputs with representative datasets and researchers, measuring utility, review prep time, and pilot readiness.
The outcome
The organization moved from a broad concept to a differentiated, working product — positioned not as another anonymization tool, but as a healthcare research data readiness platform.
In validation testing, the engine preserved 35% more analytical utility than traditional anonymization methods on comparable datasets, while cutting the time researchers spent preparing data for ethics review from three weeks to five business days. On the strength of that validation, the platform is now moving into paid pilots with two healthcare research organizations.
“What made the difference was that the platform fit the way research actually happens. It helped us protect sensitive data, understand what changed during anonymization, and prepare the documentation we needed for review — without losing confidence in the findings.”
The PivotPath difference: the product that succeeded wasn’t the product first imagined. We found the right problem by understanding how people actually work — then built around it. That’s the order that makes the build worth doing.
The outcome
The organization moved from a broad concept to a differentiated, working product — positioned not as another anonymization tool, but as a healthcare research data readiness platform.
In validation testing, the engine preserved 35% more analytical utility than traditional anonymization methods on comparable datasets, while cutting the time researchers spent preparing data for ethics review from three weeks to five business days. On the strength of that validation, the platform is now moving into paid pilots with two healthcare research organizations.
“What made the difference was that the platform fit the way research actually happens. It helped us protect sensitive data, understand what changed during anonymization, and prepare the documentation we needed for review — without losing confidence in the findings.”
The PivotPath difference:
The product that succeeded wasn’t the product first imagined. We found the right problem by understanding how people actually work — then built around it. That’s the order that makes the build worth doing.
Read More Impact Stories
Every engagement starts with the same question — where is AI actually worth building? — and ends with a tool the team relies on.