Security & Responsible Data Use

Use data responsibly, and help your team do the same.

Operational excellence rarely depends on patient identifiers — it depends on counts, rates, and timing. This guide explains how to use Adaptive Flow Studio responsibly and what to set up before your team starts. It is practical guidance, not legal terms.

Why this matters to leaders

The leaders who roll this out well do one thing first: they tell their team what data is approved for the work, what must be de-identified, and who to ask when unsure. A few minutes of framing prevents the most common data mistakes.

What Adaptive Flow Studio is designed for

Adaptive Flow Studio is built for operational learning. It works well with synthetic data, de-identified or aggregate data, and operational measures your organization has authorized you to use — volumes, rates, timing, staffing, capacity, and throughput.

Good operational measurement almost never needs a patient's name. When you find yourself about to upload identifiers, pause: most of the time the count or the rate is all the chart needs.

Protected Health Information (PHI)

Do not upload Protected Health Information unless your organization has a signed Business Associate Agreement (BAA) in place with Adaptive Flow Health and the use is authorized. If you are unsure whether your data contains PHI, treat it as PHI and do not upload it.

When in doubt, do not upload it.

If you are not certain a dataset is appropriate, leave it out and ask first. It is far easier to add data later than to walk back a mistake.

What to tell your team before they start

Before anyone on your team uploads data, make three things clear:

  • What is approved.Which datasets and data types are cleared for this work under your organization's governance policies.
  • What must be de-identified. What has to be aggregated or stripped of identifiers before it goes in.
  • Who to ask. The person to check with when someone is unsure — and the instruction to ask before uploading, not after.

Access and boundaries

Roles and access control who can do what. Team Studio lets Team Admins assign roles — building, reviewing, or view-only — and manage who can see each workspace. My Studio keeps personal work separate from shared team work. Use these boundaries deliberately: start narrow and grant more access as the need is clear.

The Team Studio Leadership Guide covers roles, invitations, and safe sharing in depth.

The official terms

This page is guidance to help you work responsibly. For the binding terms on data use, PHI, BAAs, and our security posture, see:

If anything here appears to conflict with those pages, the Data Use and Security pages govern.

Where to next