Health data evaluation, identity, and interoperability

Health Data Provenance: Questions Every Audience Vendor Should Answer

A source-to-segment lineage template and the provenance questions every health audience vendor should answer before a pharma brand buys.

Christian Guerrero Published 3 min read Part 4 of 10

The short answer

Provenance is the history of a data set: where it came from, how it was collected, who touched it, and how it changed on the way to becoming an audience segment. For health audience data, provenance determines whether the data is lawful to use, whether it is accurate, and whether the brand would be comfortable explaining its use in public.

Many vendors describe their data in general terms. A buyer should ask for specifics.

The lineage template

Ask the vendor to fill in one row per source feeding the segment.

Field What to capture
Source type Transaction, survey, app, claims, clinical, modeled
Original collector Who collected the data from the individual
Collection context What the person was doing and what they were told
Permission basis Consent, notice, contract, or other basis
Date range When the data was collected
Transformations Aggregation, modeling, de-identification, joins
Refresh cadence How often the source updates
Restrictions Uses that are not permitted

A vendor that cannot fill in these fields for its own segments is relying on its suppliers' assurances without checking them.

Ten questions to ask

  1. What are the original sources for this segment, by type and share?
  2. Did individuals receive notice that their data could be used for advertising?
  3. Where consent was required, how was it collected and recorded?
  4. How do you handle opt-outs and deletion requests, and how quickly do they flow through?
  5. What modeling is involved, and how is it validated?
  6. Does the segment include data that would be considered sensitive health data under applicable state laws?
  7. Has the segment's makeup changed in the past year?
  8. Who else licenses this segment?
  9. What uses are prohibited by your upstream contracts?
  10. Will you notify us if a source changes or is removed?

Red flags

  • Vague source descriptions. "Proprietary data from trusted partners" is not provenance.
  • Unwillingness to share methodology under NDA. Legitimate vendors can usually explain their approach.
  • Claims that data is "HIPAA compliant" as a blanket statement. HIPAA applies to specific entities and data flows. Many health audience sources fall outside HIPAA and are governed by other laws, including the FTC's Health Breach Notification Rule and state laws.
  • Segments that seem too precise to be true. Very narrow condition segments at large scale deserve extra scrutiny.

What to do with incomplete answers

Not every question will get a perfect answer. Decide in advance what gaps are acceptable. A gap in refresh cadence may be tolerable for a broad awareness segment. A gap in permission basis is usually not. Escalate permission and sensitive-data gaps to privacy counsel.

Tie provenance to contracts

Answers only protect you if they are enforceable. Turn the key answers into contract terms, including notice of source changes and audit rights.

Practical takeaway

Send the lineage template and ten questions before any health data purchase. File the answers with the plan. Revisit them annually or when the vendor changes sources.

Sources

External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.

Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.

Working through this decision on a real plan?

I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.