Know exactly who touched patient data — and prove it.
Clinicians, researchers and — increasingly — AI systems all reach for the same patient and research data. HIPAA and GDPR hold you to a simple standard: control who can see it, limit access to the minimum necessary, and be able to show every access after the fact. Lakekeeper makes that control and that evidence a property of the data itself, not a set of documents describing it.
Patient data is easy to use and hard to prove.
Protected health information (PHI) and research data flow through many hands. A clinician opens a record for care, a researcher pulls a cohort for a study, and a diagnostic or clinical-decision-support model reads the same data to make a recommendation. Every one of those touches has to respect the minimum-necessary principle — and every one of them may need to be reconstructed for a HIPAA audit, a GDPR data-subject request, or a breach investigation.
The usual set-up leaves that evidence scattered: access granted through standing database logins that never get revoked, shared service accounts that no single person owns, and an audit history stitched together from logs and spreadsheets long after the access happened. When a regulator or an incident forces the question “who could see this patient's record, and who actually did?”, the honest answer is often that no one can say with certainty.
That uncertainty is the exposure. It is also entirely avoidable — if access control and the audit record live with the data instead of alongside it.
Access control and audit, built into the data catalog.
Lakekeeper is an Apache Iceberg-native catalog and governance layer. It governs your structured data today and extends toward the unstructured data and the sources your AI and agents read. Here is how its capabilities line up with what HIPAA, GDPR and clinical-AI governance ask of you.
| What Lakekeeper does | What it helps you meet |
|---|---|
Catalog-level access control Who — and which system or AI model — can reach a given patient dataset is decided at the catalog, table and view level, and enforced there. Access is deny by default: nothing sees PHI unless it has been explicitly granted. | HIPAA access control — only authorised people and systems reach PHI Supports minimum-necessary access to patient records |
Declarative data security Access rules are written down as policy and versioned like code, so you can show exactly who could see what on any past date. No standing privileges left open between projects, no shared keys or generic service accounts — every access is scoped to a single request through short-lived credentials. | Removes standing and shared access to patient records HIPAA & GDPR — demonstrable, reviewable access rules |
Audit trail at the metadata layer Every read, write and transformation of the data is captured as a system event. The audit record is produced by the platform as data is used — not reconstructed from logs and spreadsheets after an incident. | HIPAA audit obligations — a complete access history for auditors GDPR accountability & breach-investigation evidence |
Lineage & traceability You can trace where a dataset came from and what it was later used for — including the data that trains and feeds clinical AI models such as diagnostics and decision support. | Data integrity for clinical-AI models Trace PHI flow for GDPR data-subject and breach response |
Apache Iceberg-native, open standard Governance lives in the open Iceberg catalog where your data already sits, not behind a proprietary product. No vendor lock-in, and one control point as your estate grows. | Portable governance across tools and clouds Avoids re-implementing controls per system |
Lakekeeper helps you meet HIPAA's access-control and audit obligations and supports GDPR accountability for special-category health data. It is not a compliance certification and does not by itself guarantee HIPAA or GDPR compliance — it gives you the control and the evidence those frameworks require.
Turn access to patient data from something you
hope is controlled into something you can prove.
Bring your specific HIPAA access-control question, GDPR obligation for special-category data, or clinical-AI data-governance challenge — we show you how Lakekeeper addresses it against your data, not a demo dataset. Right team: your CISO or privacy lead, plus whoever owns your data platform.