Governance is how data earns trust
Health data can improve operations, research, public health, benefits administration, care coordination, and policy. It can also expose people to harm when it is inaccurate, used out of context, retained without purpose, or accessed without appropriate control.
Data governance is the set of decisions, roles, standards, and evidence that determine how information is collected, described, protected, shared, used, corrected, and retired.
For AI and advanced analytics, governance is not a preliminary paperwork step. It is part of the system’s safety, validity, accountability, and legitimacy.
Start with purpose and stewardship
Every important data domain should have a named steward who understands its mission meaning, source processes, quality limitations, access expectations, and approved uses. Technical custody and mission stewardship are related but distinct responsibilities.
A request to use data should state the decision or service it will support, the minimum elements needed, the population affected, the retention period, the sharing plan, and how results will be evaluated.
- Purpose: What mission question or workflow will this use support?
- Authority: What policy, consent, agreement, or legal basis applies?
- Minimum necessary: Which fields and level of detail are actually required?
- Accountability: Who approves, monitors, and can stop the use?
- Disposition: When will data, features, copies, and derived outputs be removed?
Know what data exists and what it means
An inventory should connect systems and files to owners, classifications, sources, lineage, retention, interfaces, and known limitations. A catalog becomes useful when it helps people judge fitness for use—not merely locate a table.
Common definitions, code sets, metadata, and provenance reduce the chance that teams combine similar-looking fields with different meanings. Changes to source workflows should trigger review because they can alter the statistical behavior of downstream models without changing a column name.
Manage quality in context
Data is not simply good or bad. It may be complete enough for one operational report and unsafe for an individual eligibility or clinical decision.
Quality evaluation should examine accuracy, completeness, consistency, timeliness, uniqueness, representativeness, and stability for the intended use. Teams must also understand why data is missing and whether collection practices vary across groups, locations, or time.
- Define quality thresholds tied to the consequence of the decision.
- Publish known limitations alongside datasets and metrics.
- Monitor source changes, missingness, drift, and unexpected distributions.
- Create a correction path that reaches downstream copies and products.
- Retain provenance so users can trace a result back to its source.

Use layered privacy and security controls
HHS priorities emphasize data privacy, individual stewardship, strong access controls, and federated approaches. A mature program uses policy, architecture, and operations together rather than relying on a single de-identification or access-control technique.
Controls may include data minimization, role- and attribute-based access, encryption, segmentation, privacy-preserving analysis, managed workspaces, audit logging, output review, retention limits, and incident response.
De-identification reduces some risks but does not make every use harmless. Linkage, small populations, unusual events, and derived features can create re-identification or inference risks that require continuing assessment.
Make AI governance operational
The NIST AI Risk Management Framework organizes work around governing, mapping, measuring, and managing AI risk. For health applications, those functions should connect directly to data stewardship, model development, procurement, clinical or program review, security, privacy, and incident management.
ONC’s HTI-1 rule also advances transparency for predictive decision-support interventions in certified health IT. Transparency is valuable when it helps users evaluate whether a tool is appropriate for a particular population, setting, and decision.
- Document intended use, prohibited use, affected populations, and human oversight.
- Record training, validation, and production data lineage.
- Evaluate performance, calibration, fairness, robustness, and failure modes.
- Monitor drift, overrides, complaints, incidents, and real-world outcomes.
- Create authority to restrict, roll back, or retire a system.
Prefer governed access over uncontrolled copies
Federated architectures, secure analysis environments, and managed data products can reduce uncontrolled replication while allowing approved work. They can also make access, versioning, lineage, and monitoring more consistent.
Architecture does not replace governance. Teams still need clear agreements, shared definitions, identity assurance, purpose limitations, and processes for resolving errors and disputes across organizational boundaries.
Where copies are necessary, register them, assign an owner, inherit relevant controls, monitor their use, and enforce a disposition date.
Measure trustworthiness
Governance should produce evidence that leaders, users, auditors, and the public can understand. Useful measures include unresolved quality issues, access-review completion, unauthorized-use incidents, correction time, lineage coverage, model monitoring, and the percentage of datasets with active owners and documented purposes.
Public communication should explain what data is used, why, what protections apply, how automated tools influence decisions, and how people can ask questions or seek correction. Transparency is strongest when paired with meaningful recourse.
Conclusion
Trustworthy analytics and AI begin long before a model is trained. They begin with purpose, stewardship, data meaning, quality, privacy, security, and accountability.
HHS organizations that make those practices operational can use data more confidently, detect problems earlier, and demonstrate that innovation remains aligned with the people and missions it is intended to serve.

