Patient Safety & Data Research

Every data point is a patient. Build like it.

What a safe, research-grade patient data system should look like — the experience, the architecture and the assurance behind it — for biopharma, clinical research and healthcare teams across APAC.

KY & Company Insights  |  7 minute read

Patient support programmes, registries, electronic patient-reported outcomes and real-world evidence studies all rest on the same thing: data that patients trust you with. When that data is wrong, late or exposed, the cost is not just a failed study. It is a missed safety signal, a delayed intervention or a patient who stops engaging.

Our view is simple: patient safety is designed into a system, not audited into it afterwards. It starts with the experience, is enforced by the architecture and is proven through validation.

What the research says

The stakes are clinical, financial and regulatory.

1 in 10

patients is harmed in health care. More than half of that harm is preventable, and half of the preventable harm involves medication.

World Health Organization1
US$7.42M

is the average cost of a healthcare data breach, the highest of any industry. Healthcare breaches took 279 days on average to identify and contain.

IBM, Cost of a Data Breach 20252
2025

ICH adopted E6(R3), the rewritten Good Clinical Practice guideline that makes data governance and computerised systems a core part of trial quality.

International Council for Harmonisation3
The WHO defines patient safety as “the absence of preventable harm to a patient.” World Health Organization, Patient Safety fact sheet1
Why it matters

Your data system is part of your safety system.

Whoever you are, the platform that collects patient data carries obligations far beyond storing it.

Biopharma & Patient Support

Under EU pharmacovigilance guidance, adverse reactions surfaced through a patient support programme count as solicited reports, handled with the same rigour as study reports.4 A PSP platform that can’t capture and route them is a compliance gap.

Clinical & Academic Research

ICH E6(R3) expects computerised systems to be fit for purpose and validated in proportion to risk, with traceable audit trails and controlled access across the data lifecycle.3

Hospitals, NGOs & Public Health

Health data is among the most sensitive personal data an organisation holds. In Hong Kong, its collection and use is governed by the PDPO and the Privacy Commissioner’s guidance.5

Our approach

Three layers of a safe patient data system.

The same principles run through our Pati™ platform, our patient support programmes and the bespoke research systems we build.

Experience

We design it for people.

Patients, clinicians and safety teams each get an experience built for their job, so good data is the easy path.

Architecture

We build it for integrity.

Identity separated from clinical data, consent enforced in code and every change recorded.

Assurance

We validate it for inspection.

Risk-based validation, security monitoring and safety reporting that can stand up to an audit.

Experience

We design it for people.

Bad data usually starts with a bad screen.

Most data quality problems are experience problems. A questionnaire that is too long gets abandoned. A dashboard that buries exceptions gets ignored. A safety form that takes ten minutes gets filled in later, from memory. Each audience needs its own design.

For patients and caregivers

  • Short, validated instruments, one question per screen, with save-and-resume.
  • Bilingual Traditional Chinese and English, large tap targets and plain language for older and low-literacy users.
  • Layered consent that explains what is collected and why, with a simple way to change their mind.
  • Reminders that respect time zones, preferred channels and quiet hours.

For clinicians and nurse educators

  • Exceptions first: missed doses, worsening scores and overdue follow-ups at the top, not in a report.
  • One-tap escalation when a patient mentions a possible side effect.

For research, safety and quality teams

  • Query management and source traceability without spreadsheets.
  • A safety case queue with reporting clocks visible from the moment an event is captured.

Pati™ — Our patient support platform brings care coordination, adherence tracking and HCP visibility into one place, built on these experience principles.

Patient Support Programmes — When we run a programme end to end, the same platform and team capture, triage and forward safety information to your pharmacovigilance function.

Architecture

We build it for integrity.

A reference architecture for patient data research.

Every system we build differs in detail, but a safe patient data platform has a recognisable shape: four layers, with security and traceability running through all of them.

Highlighted components are the ones most often missing from systems we are asked to review.

  • Separate who from whatNames and contact details live in an identity vault; clinical data carries a pseudonymous key. Researchers never need to see who a patient is.
  • Consent is dataConsent is stored, versioned and checked by the system before any record is used, not held in a PDF.
  • Nothing is silently overwrittenCorrections create new versions with who, when and why, so any record can be reconstructed.
  • Safety has a clockA possible adverse event becomes a tracked case the moment it is captured, with its reporting deadline visible.
  • Standards over customOpen standards such as HL7 FHIR make it easier to exchange data with hospital and partner systems.6
  • Residency by designData is hosted in the region the client selects — EU, US or Singapore — and stays there.
Assurance

We validate it for inspection.

Other considerations that decide whether a system survives contact with reality.

A well-designed system still has to prove itself to sponsors, ethics committees, auditors and inspectors. We follow a delivery lifecycle that builds the evidence as we go, rather than assembling it at the end.

  1. MapTrace every data flow and safety obligation: what is collected, who sees it, where it is hosted and which reporting rules apply.
  2. DesignTest flows with real patients and clinicians, and complete a privacy impact assessment before a line of code is written.
  3. BuildVersion every instrument, rule and release so any result can be traced back to exactly what the patient saw.
  4. ValidateApply risk-based computer system validation, focusing effort on the functions that affect patient safety and data integrity.
  5. OperateMonitor continuously, reconcile safety cases with the pharmacovigilance database, and rehearse backup and recovery.

Security deserves particular attention. Healthcare breaches take longer to detect than those in any other industry,2 so continuous monitoring and alerting matter as much as encryption. Where AI is used — summarising patient messages or flagging possible adverse events, for example — it assists human reviewers and never closes a safety case on its own. Our Responsible AI approach explains how we govern and measure it.

Before you build or buy

Six questions to ask about any patient data platform.

If a vendor can’t answer these clearly, the platform isn’t ready for patients.

  • Is identifiable data stored separately from clinical and research data?
  • How is consent recorded, versioned and enforced before data is used?
  • How does a possible adverse event reach our safety team, and how fast?
  • Can every change to a record be traced to who made it, when and why?
  • Where is data hosted, and who can access it from where?
  • What validation evidence exists, and how is it maintained after each release?

Built for regulated environments

  • RBAC & Audit Trails
  • AES-256 Encryption
  • Selectable Data Residency — EU / US / SG
  • GDPR & CCPA Aligned
  • No customer data used for AI training
  • ISO 27001 Programme Underway

References

  1. World Health Organization (2023). Patient Safety, fact sheet, 11 September 2023.
  2. IBM Security (2025). Cost of a Data Breach Report 2025. Healthcare findings summarised by The HIPAA Journal.
  3. International Council for Harmonisation (2025). E6(R3) Guideline for Good Clinical Practice, adopted 6 January 2025.
  4. European Medicines Agency. Guideline on Good Pharmacovigilance Practices (GVP), Module VI, section VI.C.2.2.11; see also MHRA Inspectorate, Patient support programmes (2020).
  5. Office of the Privacy Commissioner for Personal Data, Hong Kong. The Personal Data (Privacy) Ordinance and related guidance.
  6. HL7 International. HL7 FHIR standard.

Engineering patient safety where it matters most.

Whether you are launching a patient support programme, collecting patient-reported outcomes or building a research registry, the system should protect patients as carefully as your clinicians do. Partner with KY & Company to design, build and validate it.

Get In Touch →
Scroll to Top

Discover more from KY & Company | Empowering Healthcare & Social Good

Subscribe now to keep reading and get access to the full archive.

Continue reading