top of page
Vaccine Production Line

Connect+ Health 

Trusted Research Environment

Secure Analytics Enclaves Advancing Health Equity

Product Specification and Technical Overview

Executive Summary

Healthcare research today faces a critical challenge regarding population diversity and data accessibility. Approximately 88% of large-scale genomic studies derive from individuals of European ancestry, yet this population represents only 16% of the global population. This fundamental imbalance compromises our ability to develop effective treatments and understand disease patterns across diverse communities. The underlying issue is not a scarcity of valuable health data from underrepresented populations. Rather, this data remains inaccessible within institutional silos because many organizations serving diverse communities lack the secure infrastructure required to share sensitive health information while meeting regulatory requirements and respecting community concerns about privacy and data sovereignty.

 

Connect+ Health Trusted Research Environment (TRE) addresses this challenge by providing turnkey analytics enclaves and data clean rooms for organizations that need to share health data securely but lack internal capabilities to build and manage these environments themselves. Our platform enables rapid implementation of data trusts that advance diversity, equity, and inclusion in health research while data custodians maintain complete control over their information assets.

2

Connect+ Health TRE is an AWS-based secure research environment enabling collaborative health data analysis across multiple jurisdictions while maintaining data sovereignty and privacy. The platform provides researchers with pre-configured workspaces containing standard analytical tools (R, Python, Atlas/OHDSI) and specialized health data libraries, accessible only through authenticated sessions without download capabilities. A metadata catalog enables dataset discovery without exposing patient information, while data custodians control access through customizable approval workflows, multi-level permissions, comprehensive audit logging, and resource monitoring dashboards that ensure compliance with organizational governance requirements.

  • Infrastructure Foundation

  • Core Platform Components

  • Administrative Control Center

3

Connect+ Health TRE implements comprehensive security based on ISO27001 and SOC2 standards, featuring end-to-end encryption, network isolation, automated threat detection, multi-factor authentication, and complete audit trails to support compliance with FIPPA, GDPR, HIPAA, and other regulations. The platform employs the internationally recognized Five Safes framework across five dimensions: Safe People (credential verification and role-based access), Safe Projects (ethics review and privacy assessments), Safe Settings (isolated workspaces with real-time monitoring), Safe Data (de-identification protocols and privacy-preserving linkage), and Safe Outputs (statistical disclosure controls and manual review). A multi-stage airlock system ensures that only aggregate, non-identifiable research results leave the environment through automated checks, qualified personnel review, and comprehensive documentation, with configurable thresholds aligned to organizational governance policies and risk tolerance.

  • Security Standards and Architecture

  • Five Safes Framework Implementation

  • Airlock System

4

Connect+ Health TRE is designed to advance health equity by enabling data trusts where communities and organizations serving underrepresented populations maintain control over their data while participating in collaborative research. The platform supports community data sovereignty through flexible governance frameworks that accommodate indigenous principles and culturally specific requirements, allowing data providers to negotiate fair value exchange and benefit-sharing arrangements while retaining full authority over usage terms. By eliminating traditional infrastructure barriers, the platform enables organizations of any size to participate in large-scale research without capital investments or specialized technical staff, democratizing access to secure analytics capabilities and ensuring that historically underserved communities can contribute their data and benefit from research outcomes that serve their populations.

  • Purpose and Design Philosophy

  • Data Sovereignty and Cultural Respect

  • Removing Access Barriers

5

Connect+ Health TRE supports flexible governance models that accommodate diverse organizational structures and community requirements, including single-organization review committees, multi-stakeholder boards with community representatives, or federated models where multiple organizations maintain independent authority while coordinating on shared initiatives. The platform enables community-driven data trusts by integrating community advisory boards and patient representatives into governance structures, with configurable workflows that require community approval alongside scientific and ethics review, while maintaining transparency through comprehensive documentation of governance decisions and research outcomes that demonstrate how community data contributions advance scientific knowledge and health improvements.

  • Flexible Governance Architecture

  • Community Participation Mechanisms

6

Connect+ Health TRE serves diverse stakeholders by enabling community health organizations serving underrepresented populations to participate in large-scale research while maintaining data control and governance authority; regional health authorities to provide secure research access while meeting regulatory requirements through comprehensive audit capabilities; Indigenous health programs to implement data sovereignty principles and OCAP frameworks (Ownership, Control, Access, Possession) with cultural protocols integrated into approval workflows; academic researchers to access diverse health data through standardized secure environments without technical barriers; and data trusts or cooperatives to implement governance frameworks where member organizations collectively control data assets while enabling approved public-good research. The platform removes infrastructure barriers and standardizes processes across all use cases while respecting community governance, cultural protocols, and organizational decision-making requirements.

  • Community Health Organizations

  • Regional Health Authorities

  • Indigenous Health Programs

  • Academic Researchers

  • Data Trusts and Cooperatives

7

Organizations begin implementation with a collaborative assessment phase where Connect+ Health TRE teams work with technical staff, governance committees, and community representatives to understand data assets, infrastructure, compliance requirements, and specific configuration needs. The configuration and deployment phase establishes jurisdiction-appropriate environments with customized access controls, approval workflows, authentication integration, and monitoring capabilities through phased implementation that minimizes operational disruption. Comprehensive role-specific training ensures administrators, governance committee members, and researchers understand their respective responsibilities through hands-on sessions, documentation, and video tutorials, followed by ongoing support that includes technical assistance, governance consultation, platform optimization, regular security updates, and collaborative evolution of the platform as organizational needs and research programs expand.

  • Assessment and Planning Phase

  • Configuration and Deployment Phase

  • Training and Enablement Phase

  • Support and Evolution

Technical Architecture

Connect+ Health Trusted Research Environment (TRE)

Computer security_edited.jpg

Infrastructure Foundation

Connect+ Health TRE operates on Amazon Web Services (AWS) cloud infrastructure with initial deployment in Canada. The platform architecture supports establishment of additional localized instances in other jurisdictions as required to meet data sovereignty and residency requirements (e.g., South America, the Middle East and Africa). This deployment model ensures that sensitive health information remains within appropriate geographic and regulatory boundaries while enabling secure collaborative research across organizational boundaries. Each jurisdictional deployment maintains independent operation while adhering to consistent security and governance standards.

data scientist_edited.jpg

Core Platform Components

The environment provides pre-configured research workspaces that include standard analytical tools such as R, Python, and Atlas/OHDSI, along with specialized libraries optimized for health data analysis including genomic, clinical, and multi-modal datasets. Researchers access these secure workspaces through authenticated sessions with no out any capability to download or transfer underlying patient data. All analytical work occurs within the controlled environment where data custodians maintain complete oversight and monitoring capabilities.

OurThe metadata catalog system enables researchers to discover available datasets and understand their characteristics without accessing privacy restrictedunderlying patient information. This metadata-driven discovery approach allows appropriate matching of research questions with available data resources while protecting privacy. Access requests flow through customizable approval workflows that can be configured to respect each organization's specific governance requirements and decision-making processes.

data science general.jpg

Administrative Control Center

Data custodians are provided with receive comprehensive administrative capabilities for managing their secure environments. Access controls can be configured at multiple organizational levels, from organization-wide policies down to project-specific permissions. The platform provides detailed resource usage monitoring and cost reporting through comprehensive dashboards, enabling effective budget management and resource allocation decisions. Complete audit logging captures all system activities, supporting both compliance monitoring and security oversight responsibilities. The export approval system includes configurable workflows that can be tailored to match specific organizational governance requirements.

Security Framework

Connect+ Health Trusted Research Environment (TRE)

complete control.jpg

Security Standards and Architecture

The platform has been designed and built according to ISO27001 and SOC2 standards for information security management. While we are progressing toward formal certification, our architecture incorporates comprehensive security controls that reflect this rigorous standard. The implementation includes end-to-end encryption for all data both at rest and in transit, network isolation and segmentation to limit lateral movement, automated threat detection and response capabilities, and multi-factor authentication requirements for all system access. The platform maintains complete audit trails of all activities, enabling organizations to demonstrate compliance with applicable privacy regulations including FIPPA, GDPR, HIPAA, and other jurisdiction-specific requirements.

investment opportunity.jpg

Five Safes Framework Implementation

Connect+ Health TRE implements the internationally recognized Five Safes framework as the foundation of our security approach. This framework provides comprehensive protection across five critical dimensions:

 

Safe People ensures that only qualified, authorized individuals access sensitive data through rigorous credential verification, professional validation, role-based access controls, and mandatory training on data handling and cultural sensitivity. Safe Projects requires every research initiative to demonstrate clear scientific merit through standardized application processes, undergo ethics review that explicitly considers cultural implications, and complete comprehensive privacy impact assessments before work begins.

 

Safe Settings provides technical security through isolated and monitored workspaces, comprehensive access logging, real-time security monitoring and alerting, and network segmentation that prevents unauthorized access or data exfiltration. Safe Data implements advanced de-identification and anonymization protocols, automated quality control measures to ensure data integrity, complete data lineage tracking for transparency and auditability, and privacy-preserving approaches to data linkage when combining information from multiple sources.

 

Safe Outputs ensures that only approved, non-identifiable results leave the environment through a multi-stage airlock system with statistical disclosure controls, manual review and approval processes, comprehensive documentation of all exports, and validation procedures to prevent re-identification risks.

Image by Jason Dent

Airlock System

The export control mechanism prevents unauthorized data release while enabling legitimate research outputs to reach the scientific community. When researchers complete analyses and wish to share results, they submit export requests that enter a review queue. Data custodians or their designated reviewers examine all requested outputs to verify they contain only aggregate, non-identifiable information before approving release. This multi-stage process includes automated statistical disclosure control checks, manual review by qualified personnel, comprehensive documentation of review decisions, and complete audit trails of all export activities. The system can be configured with organization-specific thresholds and review criteria to align with local governance policies and risk tolerance.

Connect+ Health Trusted Research Environment (TRE)

Advancing Health Equity Through Data Trusts

Brazil_edited.jpg

Purpose and Design Philosophy

Connect+ Health TRE has been specifically designed to transform how diverse health data is valued, accessed, and utilized in research. The platform enables implementation of data trusts where communities and organizations serving underrepresented populations maintain control over their data while participating in collaborative research that serves the public good. This approach directly addresses the historical exclusion of diverse populations from medical research while ensuring these communities share equitably in the benefits that result from their data contributions.

Inuit_edited.jpg

Data Sovereignty and Cultural Respect

The platform architecture supports community control over data sharing and usage terms through flexible governance frameworks that can accommodate indigenous data sovereignty principles and culturally specific requirements. Local jurisdictions and communities retain full authority over their data assets while participating in broader research collaborations when appropriate. The system supports implementation of fair value exchange models where data providers receive appropriate recognition and can negotiate benefit-sharing arrangements from research outcomes. All governance mechanisms can be configured to reflect cultural protocols and community decision-making processes.

brain scan data.jpg

Removing Access Barriers

Connect+ Health TRE eliminates traditional infrastructure barriers that prevent smaller organizations and those serving underrepresented communities from participating in large-scale research initiatives. Institutions of any size can provide their researchers with secure analytics capabilities without capital investments in specialized infrastructure or hiring of dedicated technical staff. The platform provides standardized tools and transparent processes that enable equal participation regardless of organizational resources or technical sophistication. This democratization of research infrastructure allows communities that have been historically underserved by medical research to contribute their data and participate actively in studies that will ultimately benefit their populations.

Governance Models for Data Trusts

Connect+ Health Trusted Research Environment (TRE)

Image by Christina @ wocintechchat.com

Flexible Governance Architecture

The platform supports implementation of various governance models to accommodate different organizational structures and community requirements. Data access decisions can be managed through single-organization review committees, multi-stakeholder governance boards that include community representatives, or federated models where multiple organizations maintain independent authority while coordinating on shared initiatives. Each governance model can define specific approval workflows, review criteria, and decision-making processes that reflect organizational values and community expectations.

multiculture group.jpg

Community Participation Mechanisms

For organizations implementing community-driven data trusts, the platform supports integration of community advisory boards and patient representatives into governance structures. Access request workflows can be configured to require review and approval from community representatives in addition to scientific and ethics evaluation. The system maintains transparency through comprehensive documentation of governance decisions and research outcomes, enabling communities to understand how their data contributes to scientific knowledge and health improvements.

Connect+ Health Trusted Research Environment (TRE)

Applicable Use Cases

congolese children.jpg
winter people.jpg
Quechua Indigenous Women

Community Health Organizations

Regional Health Authorities

Indigenous Health Programs

Organizations serving underrepresented populations can participate in large-scale research initiatives without investing in specialized infrastructure. Your organization's data contributes to studies that will ultimately benefit your community while you maintain complete control over access decisions and usage terms. The platform enables you to enforce community-determined governance requirements and ensures appropriate recognition of your contributions.

Health authorities can enable secure research access to sensitive health information while meeting regulatory requirements and demonstrating appropriate governance to stakeholders, ethics boards, and the public. The comprehensive audit and monitoring capabilities support accountability and transparency requirements. The platform's security architecture and controls enable compliance with privacy regulations while supporting valuable research activities.

Indigenous health programs can implement data sovereignty principles while participating in collaborative research when appropriate and beneficial. Cultural protocols and community governance integrate directly into access and approval workflows. The platform supports implementation of OCAP principles (Ownership, Control, Access, and Possession) and other indigenous data governance frameworks. Communities maintain authority over whether, how, and when their data is accessed for research purposes.

data consumers.jpg
Parliament House

Academic Researchers

Data Trusts and Cooperatives

Researchers gain access to diverse health data through standardized, secure environments that remove technical barriers to important research questions. The platform enables you to focus on scientific questions rather than navigating complex data access negotiations or managing infrastructure concerns. You can work with data from underrepresented populations while respecting community governance and contributing to health equity.

Data trusts can implement secure governance frameworks where member organizations maintain control over collective data assets while enabling approved research that serves the public good. The platform's flexible governance architecture supports various organizational structures and decision-making models.

Connect+ Health Trusted Research Environment (TRE)

Implementation Pathway

Image by Alvaro Reyes

Assessment and Planning Phase

Organizations begin implementation with a collaborative assessment of their data assets, current infrastructure, and specific compliance requirements. Our team works with your technical staff, governance committees, and community representatives to understand your objectives and requirements. This assessment phase identifies specific configuration needs, governance workflow requirements, and integration points with existing systems.

Image by Ferenc Almasi

Configuration and Deployment Phase

Based on assessment findings, we configure the environment according to your jurisdiction requirements and organizational governance policies. This includes establishing appropriate access control structures, configuring approval workflows to match your decision-making processes, integrating with your existing authentication systems where appropriate, and establishing monitoring and reporting according to your oversight requirements. Deployment proceeds through phased implementation that minimizes disruption to existing operations while progressively establishing secure research capabilities.

Image by Campaign Creators

Training and Enablement Phase

Comprehensive training programs ensure that administrators understand platform management capabilities, governance committee members understand their review and approval responsibilities, and researchers understand how to work effectively within the secure environment. Training is tailored to each role and can be delivered through various modalities including hands-on sessions, documentation, and video tutorials. Ongoing support ensures that users receive assistance with technical questions and analytical challenges throughout their use of the platform.

Call Center Employee

Support and Evolution

Following deployment, dedicated support teams remain available for technical assistance, governance consultation, and platform optimization. Regular updates ensure that your environment benefits from security enhancements and new capabilities as they become available. We work collaboratively with your team to evolve the platform configuration as your needs develop and your research programs expand.

bottom of page