Solutions / Healthcare & Life Sciences

“Who saw this record?” Answer it in seconds.

HIPAA and GDPR ask one question about patient data. Most systems cannot answer it.

HIPAAGDPR Art. 9Minimum necessaryClinical AIDeployable today
$4.75M
OCR penalty for missing audit controls
Montefiore, 2024. Insider theft, found by police two years later
+17.4%
Rise in unauthorized-access breaches
2025 — while total healthcare breaches fell 4.3%
$6.64M
Average healthcare breach cost
Highest of any industry (IBM, 2026)
292 days
To resolve a stolen-credential breach
Nearly ten months of unanswered questions

Easy to use. Hard to prove.

ClinicianResearcherDiagnostic modelThird-party vendor1 patient recordWho could see it?Who did?Reconstructed by hand, weeks later
HIPAA Security RuleEnforced

§164.312(b) requires mechanisms that record and examine activity in systems containing ePHI — and that you actually review them.

GDPR Art. 9In force

Health data is special category. Accountability means showing who could reach it, and who did.

Clinical AIGrowing fast

Diagnostic and decision-support models read the same records. Their training and input data has to be traceable.

What changes with Lakekeeper.

Access control and the audit record become properties of the data itself.

Today
With Lakekeeper
Audit evidence
Stitched together from logs and spreadsheets, weeks after the access.
Supports HIPAA §164.312(b)
Returned from the catalog. Every read, write and transformation is a system event.
Access
Standing database logins, shared service accounts, credentials nobody revoked.
Supports Minimum necessary
Deny by default at table and view level. Nothing reaches PHI without an explicit grant.
Clinical AI
Models read patient data with no record of which records fed which output.
Supports Data integrity · DSAR response
Every dataset carries its provenance, including what trains and feeds a model.
Coverage
Controls re-implemented per warehouse, per tool, per cloud.
Supports Portability · no lock-in
One open Iceberg catalog. Governance travels with the data.

Lakekeeper helps you meet HIPAA's access-control and audit obligations and supports GDPR accountability for special-category health data. It is not a compliance certification and does not by itself guarantee HIPAA or GDPR compliance.

Turn access to patient data from something you hope is controlled
into something you can prove.

Book a 30-minute walkthrough

Bring your CISO or privacy lead, plus whoever owns your data platform.

Sources: HHS OCR settlement with Montefiore Medical Center (Feb 2024); HHS OCR breach portal, 2025 reporting year; IBM Cost of a Data Breach Report 2026 (healthcare sector); IBM Cost of a Data Breach, healthcare industry analysis (stolen-credential resolution time).

← Back to all solutions