The platform functions by isolating raw data within a controlled space, where users can execute metrics, test hypotheses, and generate heatmaps or scatterplots without accessing patient-level details. Subsalt retains governance over data exports and access rights, ensuring that only approved analytical outputs leave the environment. This release complements Subsalt’s existing digital twin technology, which creates de-identified patient populations for clinical research.
Subsalt Unveils Secure Runtime for PHI-Compliant Data Analysis
Charlotte-based Subsalt has launched Secure Runtime, a computing environment enabling health systems to analyze protected health information without exposing individual patient records. The platform allows authorized users to perform Python-based analysis and visualization while maintaining strict privacy controls validated under HIPAA’s Expert Determination standard by industry firm Datavant.

Dr. Emily Payne, a senior privacy expert at Datavant, noted that the certification process involved rigorous risk assessment for attribute and membership disclosure. The system is engineered to align with the stringent "very small" risk threshold required by HIPAA. In addition to Secure Runtime, the company introduced Subsalt MCP, a tool designed to connect AI chat interfaces with custom de-identified datasets. According to Subsalt CTO Luke Segars, these natural-language tools aim to bridge the gap between clinical inquiry and technical data navigation, allowing clinicians to query systems directly through agents.



Comments (0)
No comments yet. Be the first!