Health data evaluation, identity, and interoperability

Consent, Permission, and Fitness for Use Are Not the Same Thing

A three-gate model for health data in pharma marketing that separates legal permission, contractual permission, and whether a use fits the brand's standards.

Christian Guerrero Published 3 min read Part 6 of 10

The short answer

A common question in pharma media is "are we allowed to use this data?" The question sounds like it has one answer. It has at least three. Data can be legally permissible, contractually permitted, and still inappropriate for the brand. Treating any single signal as universal approval leads to problems.

The three gates

Gate 1: Legal permission

Is the use allowed under applicable law? This depends on the type of data, who holds it, where the individual lives, and what they were told. Federal rules include HIPAA for covered entities and the FTC's authority over unfair or deceptive practices, including the Health Breach Notification Rule. Several states have consumer health data laws with their own consent requirements. This gate belongs to counsel.

Gate 2: Contractual permission

Does the contract with the data provider allow this specific use? Contracts often limit data to certain purposes, such as targeting but not measurement, or prohibit combining it with other data. Upstream contracts can also restrict what the provider can license. This gate belongs to procurement and counsel together.

Gate 3: Fitness for use

Even when the first two gates pass, would the brand be comfortable if patients, clinicians, or regulators saw exactly how the data was used? Is the data accurate enough for the purpose? Could the use cause harm, such as revealing a condition to others on a shared device? This gate belongs to the brand, privacy, and media teams.

How the gates interact

Legal Contract Fitness Decision
Yes Yes Yes Proceed
Yes Yes No Do not proceed or change the use
Yes No Any Renegotiate or do not proceed
No Any Any Do not proceed

The third row is common. A use can be legal and still prohibited by contract. The second row is the one teams skip, because once legal and contract say yes, it feels like the question is answered.

Questions for the fitness gate

  • Would a reasonable patient expect their data to be used this way?
  • Is the data accurate enough that errors will not cause harm or embarrassment?
  • Could the ad reveal sensitive information to someone other than the intended person?
  • Does the use match the brand's published privacy commitments?

The NIST Privacy Framework offers a structured way to think about privacy risk beyond legal compliance.

Document the decision

Record each gate's answer, who made it, and when. If the data or use changes, revisit all three. This record is also useful in data contract reviews and provenance checks.

Practical takeaway

Replace "are we allowed?" with three separate questions in your approval process, each with a named owner. Do not proceed until all three have a documented yes.

Sources

External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.

Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.

Working through this decision on a real plan?

I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.