Point-of-care and EHR media for pharma

HIPAA-Safe Reporting When Point-of-Care Exposure Is Matched to Pharmacy Fills

How point-of-care exposure can be matched to pharmacy fills without exposing PHI: de-identification, aggregation, roles, and vendor questions.

Christian Guerrero Published 3 min read Part 7 of 10

The short answer

HIPAA-safe reporting means a pharma brand receives results about how exposure relates to pharmacy fills without ever receiving protected health information. Typically, patient-level matching happens inside a de-identified environment run by a measurement or data partner, using tokens rather than names, and the brand only sees aggregated results above minimum cell sizes. Brands should ask who holds what data, how de-identification is certified, and what minimum reporting thresholds apply.

Matching point-of-care exposure to pharmacy fills is one of the strongest ways to measure impact. It also involves some of the most sensitive data in marketing. The question is not whether to measure, but how to set it up so no party sees more than it should.

Who holds what

A typical setup has four parties:

Party Holds Should not receive
Point-of-care vendor Which practices or devices showed which content, when Patient prescription records
Data or measurement partner De-identified prescription data under its agreements Identified exposure data linked to names
Pharma brand Aggregated results Any patient-level data
Practice or health system Patient records Brand campaign analytics tied to patients

The design goal is that patient-level matching happens only inside a controlled, de-identified environment.

How de-identified matching works

  1. Exposure is recorded at the practice, device, or HCP level, or for patient-facing tools with appropriate consent.
  2. Records that must be matched are converted to tokens, coded identifiers that cannot be reversed by the parties receiving them.
  3. Tokens are matched to de-identified pharmacy or claims data by the measurement partner.
  4. Results are aggregated and compared with a control group.
  5. Only aggregated results above minimum thresholds go to the brand.

HHS describes two de-identification methods under HIPAA: safe harbor (removing specified identifiers) and expert determination (a qualified expert certifies very small re-identification risk). Most measurement setups use expert determination.

Practice-level designs

Many point-of-care studies avoid patient-level matching entirely. They compare new prescriptions written at exposed practices with matched unexposed practices. This is simpler for privacy and often enough for decisions.

Patient-facing tools

Exam room tablets or apps that collect patient input raise further questions. If a patient enters information, consent and data use must be clear, and state health privacy laws may apply. The article on state health privacy laws covers recent changes.

Questions to ask vendors

  1. Who performs matching, and under what agreements?
  2. Is de-identification certified by expert determination? How recently?
  3. What minimum cell sizes apply to reporting?
  4. Does any party receive patient-level data linked to exposure?
  5. How is the control group built?
  6. How long is data kept, and who can access it?

Red flags

  • A vendor offers patient-level results to the brand.
  • No written de-identification method.
  • Reports that break results into very small groups.
  • Unclear roles between vendor and measurement partner.

Common mistakes

  • Assuming HIPAA does not apply because the brand is not a covered entity. Your partners may be covered entities or business associates.
  • Asking for more granular reporting than privacy allows.
  • Ignoring state laws on consumer health data.

Practical takeaway

Ask your point-of-care vendor for a one-page data flow diagram showing every party, what each holds, and where de-identification happens. If they cannot produce it, involve your privacy team before signing.

Frequently asked questions

Can a pharma company see which patients filled a prescription after an ad?

Not in identifiable form for advertising measurement. Brands receive aggregated, de-identified results through measurement partners.

What is expert determination?

One of two HIPAA de-identification methods. A qualified expert determines that the risk of re-identification is very small and documents the method.

What is a minimum cell size?

A reporting rule that suppresses results for groups too small to protect privacy, so no one can be singled out.

Sources

External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.

Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.

Working through this decision on a real plan?

I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.