Frequently Asked Questions

Data Governance & Third-Party Risk

Why is data governance important for organizations handling sensitive information?

Data governance is essential for organizations managing sensitive data because it mitigates the risk of exposing personally identifying information (PII), ensures compliance with regulations, and helps avoid additional costs and reputational damage. Effective governance maintains vigilance over data throughout its lifecycle, adapts to evolving ethical concerns, and forms the foundation of workforce trust in data sharing and usage. Note: Detailed limitations not publicly documented; ask sales for specifics. Source

What are the financial risks of a data breach in healthcare and life sciences?

According to a Ponemon Institute study, the average cost per record exposed in a healthcare data breach is 0, while in the life sciences industry it is 4 per record. These high costs highlight the importance of robust data governance and security protocols. Note: Costs may vary by organization and incident. Ponemon Institute, 2020

How common are third-party data breaches in the United States?

In a 2018 Ponemon Institute study, 61% of participating US companies reported experiencing data breaches connected to vendors or third-party business associates, a 12% increase from 2016. This underscores the growing risk associated with third-party relationships. Note: The study reflects trends up to 2018; current rates may differ. Ponemon Institute, 2018

What impact did the COVID-19 pandemic have on healthcare data breaches?

According to the US Department of Health and Human Services, there was a 36% increase in healthcare data breaches in the second half of 2020 compared to the first half. Nearly three-quarters of all breaches during this period were tied to third parties, with 21.3 million healthcare records breached in the second half of 2020 alone. Note: These figures are specific to the 2020 pandemic period. HHS Analysis, 2021

What best practices are recommended for managing third-party data risk?

Recommended best practices for managing third-party data risk include: routinely auditing third-party security practices, maintaining an inventory of all third parties with data access, conducting frequent reviews of third-party technologies, requiring notification of any data sharing with other entities, and enlisting senior leadership support for data security efforts. Note: Implementation effectiveness may vary by organization. Source

meldR Platform & Data Society Solutions

What is meldR and how does it support data compliance in healthcare and life sciences?

meldR is a Learning Experience Communication Platform (LXCP) introduced by Data Society to address the unique needs of healthcare and life sciences organizations. It provides a unified point of contact with built-in data compliance features specific to these industries, enabling instructors to deliver training, learners to build communities of practice, and L&D departments to track development and achievements. Note: meldR is best suited for organizations requiring healthcare and life sciences data compliance; detailed limitations not publicly documented. meldR Product Page

How does Data Society help organizations upskill their workforce while maintaining data security?

Data Society offers hands-on, instructor-led training programs and platforms like meldR that enable organizations to upskill their workforce using real-world data sets. These solutions are designed to foster collaboration and professional development while incorporating data compliance features to protect sensitive information. Note: Organizations must still ensure their own internal compliance policies are followed. Source

Security & Compliance

What security and compliance certifications does Data Society hold?

Data Society holds the ISO 9001:2015 certification, an internationally recognized standard for quality management and secure operations. This certification is particularly important for industries such as government contracting and healthcare, where robust data security is required. Note: SOC 2 or other certifications are not listed; ask sales for specifics. Source

How does Data Society ensure secure operations for its clients?

Data Society designs and implements its solutions with a focus on secure operations, adhering to ISO 9001:2015 standards. This approach is intended to safeguard sensitive data and maintain client trust, especially in regulated industries. Note: Detailed security protocols are not publicly documented; contact Data Society for specifics. Source

Integrations & Technical Requirements

What integrations does Data Society support for data governance and compliance?

Data Society supports integrations with communication tools (email, social media, calendar platforms), learning management systems, and data platforms. meldR, for example, integrates with these tools to streamline collaboration and training. Additionally, Data Society solutions can integrate with data visualization and analytics tools like Power BI, Tableau, and ChatGPT. Note: Integration capabilities may vary by product; confirm with Data Society for your use case. Source

Use Cases & Industry Applications

Which industries benefit most from Data Society's data governance and compliance solutions?

Industries that benefit most include healthcare, life sciences, government, financial services, aerospace and defense, energy and utilities, and professional services. Data Society's solutions are tailored to address the unique data governance and compliance challenges in these sectors. Note: Suitability for other industries may vary; contact Data Society for industry-specific details. Case Studies

Where can I find resources about data governance and third-party business associates?

You can access Data Society's resource on data governance and third-party business associates at https://datasociety.com/data-governance-and-third-party-bas/. Note: Additional resources may be available on the Data Society website.

While the value of data rises in pace with data science tools and technologies, so also does the risk of data exposure.

Data Governance and Third-Party BAs

Data Governance and Third-Party Business Associates

With progress inevitably come challenges. Such is the reality organizations confront as they increasingly harness the transformational potential of data. While the value of data rises in pace with data science tools and technologies, so also does the risk of data exposure. 

Effectively managing sensitive data is particularly critical in the healthcare and life sciences universes. The collection, sharing, and transmission of Protected Health Information (PHI) and Electronic Protected Health Information (ePHI)—often replete with sensitive personal information—heightens the need for skilled data governance both to improve outcomes and to comply with standards for safeguarding Personally Identifying Information (PII).

The High Stakes of Vulnerable Data

The potential costs of data breaches are daunting, and healthcare organizations face a particularly high toll for data exposure. According to a study by the Ponemon Institute, which measured the financial impact of data breaches across 16 industries, the healthcare industry pays dearly for data security failures, incurring an estimated cost of $380 per record associated with exposure of PHI and ePHI. The cost per record for breaches in the life sciences industry was estimated to be $264.     

The troubling prospect of a ransomware attack looms particularly large as a data security concern across industries. A 2021 whitepaper published by Sophos, a security software and hardware firm, provides a current glimpse into the ransomware threat from a healthcare perspective. While 34% of healthcare employees surveyed for this study indicated that their organizations had experienced ransomware infections in the last year, 41% responded that they had not been hit by ransomware in the last year but expected to be at some point.

Data Governance and Third-Party Business Associates

For healthcare organizations, a ransomware attack carries with it not just a financial burden, but liability for violation of HIPAA regulations.  With the passage of the Health Information Technology for Economic and Clinical Health Act (HITECH), enacted to encourage health technology, this liability extends to third-party business associates (BAs) who have access to Electronic Health Records (EHR).

Third Parties and Data Security

As organizations engage more and more third-party BAs for a range of services, the opportunities for data mischief expand. In the Ponemon Institute’s 2018 study, Data Risk in the Third-Party Ecosystem, 61% of participating US companies reported that they had experienced data breaches connected to vendors or third-party BAs, representing a 12% increase from 2016.

The COVID-19 pandemic has, according to a recent analysis of breach reports by the US Department of Health and Human Services, accelerated this trend of security incidents in healthcare.  Citing a 36% increase in healthcare data breaches in the second half of 2020 over the first half of that year, the report points out that many of these breaches involve BAs, noting “According to analysts, 21.3 million healthcare records were breached in the second half of 2020 alone – with nearly three-quarters of all breaches tied to third parties.”

A Business Wire article reporting on the results of the 2018 Ponemon Institute’s study offers the following comment from Dr. Larry Ponemon:

Considering the explosive growth of outsourced technology services and the rising the (sic) volume of third parties, companies need to take control of their third-party exposure and implement safeguards and processes to reduce their vulnerability.

Data Governance and Third-Party Business Associates

The study concludes that mitigating these risks requires strong data governance protocols and security technology, recommending such measures for safeguarding ePHI files as:

  • Routinely auditing third-party security practices.
  • Maintaining an inventory of third parties that have access to their data and any associated entities that have access through them.
  • Conducting frequent reviews of technologies that third parties adopt.
  • Requiring third parties to notify them of their relationships with other entities with whom they might share data.
  • Enlisting the support of senior leadership in prioritizing data security efforts.

Balancing the Risks with the Rewards of Shared Data

With robust data governance procedures in place, organizations position themselves to reap the benefits—safely and confidently—of engaging qualified business associates that provide valuable expertise and important services.  Workforce training resources offer one example of such third-party relationships.

Many healthcare and life sciences organizations are wisely ramping up efforts to upskill their workforces in data science tools and techniques.  In the process, they are increasingly realizing that the real-world data sets their employees use in their work are highly effective as training materials.  However, the advantages of this practice, of course, are accompanied by the additional exposure of sensitive records when they are shared on learning platforms. 

Data Science Training with Data Compliance Savvy

The Data Society team recognizes that collaboration between L&D departments and workplace learners plays an important role in professional development.  The team also understands the vital importance of data security, particularly when it comes to healthcare records.  With the goal of creating a fertile learning environment that encourages communication while protecting sensitive information, Data Society has introduced meldR, a Learning Experience Communication Platform (LXCP) that caters to the unique needs of healthcare and life sciences organizations.  meldR provides a unified point of contact—with built-in data compliance specific to the healthcare and life sciences industries—through which instructors can deliver training, learners can develop a community of practice, and L&D departments can track student development and achievements. 

Data Governance and Third-Party Business Associates

Clearing obstacles to the open collaboration that promotes innovation and professional development is a key to effectively upskilling workforces.  meldR offers a space for educational engagement, where students can focus on learning rather than data security, driving the progress of healthcare and life sciences organizations toward their data maturity goals. 

Don’t wanna miss any Data Society Resources?

Stay informed with Data Society Resources—get the latest news, blogs, press releases, thought leadership, and case studies delivered straight to your inbox.

Data: Resources

Get the latest updates on AI, data science, and our industry insights. From expert press releases, Blogs, News & Thought leadership. Find everything in one place.

View All Resources
  • Fluency Over Access: What It Really Takes To Build A Data-Driven Culture In Organizations

    July 30, 2026

    Read more

  • When Training Metrics Lie: How to Actually Measure AI Upskilling Effectiveness

    July 28, 2026

    Read more