Every longitudinal dataset rests on one quiet engineering decision: how a patient is followed over time without being exposed.
For years buyers treated that decision as the vendor's problem. A token appeared, records joined, the license was signed. In late September a European regulator made it the buyer's problem too.
A €7 million reminder
On September 23, 2026, Italy's data protection authority, the Garante, fined a major RWD vendor €7 million over a database built from the records of about one million patients of roughly 800 general practitioners. The company described the data as anonymous. The Garante disagreed. According to the authority, the code assigned to each patient made it possible to follow that patient over time, and combined with detailed clinical and location data, it allowed individuals to be singled out and, with reasonable means, reidentified. The authority also treated the company as controller from the point of collection, because it directed how pseudonymization happened at the source.
The decision can be appealed, it concerns one dataset, and European law is not HIPAA. None of that makes it irrelevant to a US buyer. It names the central tension in real world evidence plainly: the feature that makes data valuable for research, a persistent link across time, is the same feature regulators examine first.
The tension buyers cannot outsource
Research needs continuity. A protocol that measures exposure, endpoint, and confounders across years needs to know that the record in year one and the record in year four belong to the same person. Without that, there is no cohort, only a pile of events.
Privacy needs distance. The more detail that rides alongside a persistent identifier, the shorter the path back to a real person. Diagnoses, prescriptions, visit dates, geography: each one makes a study more useful and a dataset more identifiable.
Most vendors resolve this tension in a deck. Few resolve it in architecture. When the architecture fails, the consequences land on everyone in the chain: the source who contributed, the vendor who assembled, and the sponsor whose study now depends on a dataset under scrutiny.
Why dental makes this sharper
Dental data adds a layer most RWD diligence has never had to examine.
Dental records are rich, longitudinal, and highly specific. Tooth level charting, periodontal measurements, imaging, recall intervals, and procedure histories are exactly the depth that makes oral systemic research possible. They are also distinctive. A full chart history is not a generic claims row.
Dental records also live in a different place. They sit in practice management systems that were never connected to hospital networks, never routed through medical clearinghouses, and rarely touched by the tokenization pipelines medical data runs through. Linking them to medical records is not a matter of flipping a switch on an existing token. It requires deliberate design of where identity lives, who holds it, and what crosses into the research environment.
Shortcuts are tempting. Move identifiers to a central location, match them, strip them later. That approach produces a join quickly. It also produces a central point that knows who everyone is, which is precisely what a careful buyer should not want sitting underneath a study.
Five diligence questions about the identity boundary
Before licensing any linked dataset, dental or otherwise, ask the vendor to answer these in writing:
- Where does identity live, and who holds it? Name the system and the party. "Encrypted" is not an answer.
- What crosses into the research environment? List the fields. If a persistent code travels with dense clinical and location detail, ask how reidentification risk was assessed and by whom.
- Who directs the de identification process at the source? The Italian decision turned partly on this. Control at the source carries responsibility for the chain.
- Can the linkage be explained to a contributing provider in one paragraph? If sources do not understand how their patients are protected, their continued participation is a risk to your longitudinal series.
- What happens to your study if a source withdraws? Datasets assembled without provider governance can lose contributors overnight. That breaks the very continuity you paid for.
A vendor that answers crisply is selling an asset. A vendor that answers with adjectives is selling exposure.
What Bridge Health Syndicate built
Bridge Health Syndicate built the member governed dental data layer for healthcare with the identity boundary as the starting design constraint, not a compliance patch.
De identified dental records link to medical records at the patient level through the HELIX Protocol (patent pending). Identity never crosses the boundary. The research environment receives what research needs, the longitudinal oral systemic signal, without becoming a place that knows who patients are.
Governance follows the same logic. Contributing dental organizations are members, not silent upstream sources. They set research use policy and partner categories, and they keep control of how their data is used. That matters to buyers for a commercial reason as much as an ethical one: providers who understand and govern the linkage stay in the network, and longitudinal series stay intact.
The result is linked dental medical evidence designed to survive diligence, not just pass a demo.
The question behind the question
The Garante decision will be read closely across Europe, and US privacy teams will read it too. The lesson for buyers is not that linked data is dangerous. It is that linkage design is now part of what you are buying.
The mouth has been missing from real world evidence for a long time. Adding it back the wrong way would trade one gap for another. Adding it back with identity on the right side of the boundary is how oral systemic research becomes a durable asset.
For the data brief on the Bridge Health Syndicate linked dental medical layer, visit https://bhsyndicate.com or email dra@bhsyndicate.com.
—
Rabiel Amirian, DDS
Founder, Bridge Health Syndicate
https://bhsyndicate.com
dra@bhsyndicate.com
Top comments (0)