Health data monetization where contributing sites earn royalties

A hospital running Kymolog can add its device readings to pooled datasets. It consents first, and the install de-identifies the readings before any leave, so only de-identified data reaches us. We license the datasets and pay royalties back to the contributing sites.

Add-on service · consent first · de-identified by allowlist · royalties

Fig. 1. Three hospital installs, each sending a thin de-identified trace to one aggregator, with royalties returning.

How the data network works

The data network is a separate add-on service we run on top of Kymolog™. A contributing hospital opts in and chooses what it contributes. Its readings are de-identified inside the install, wherever it runs, and only then do they cross to the network (Fig. 2).

On our side, readings from many sites are pooled by code and device type. We license the pooled device datasets, and royalties go back to the sites whose readings they hold.

From consent to royaltiesFive steps across two dashed regions. Inside the contributing site’s install: 1, consent: the site opts in and chooses what it contributes; 2, de-identify: an allowlist keeps the coded readings and leaves identifiers behind. A red arrow carries the de-identified readings out of the install into the Saga data network, an optional add-on: 3, aggregate: readings from many sites are pooled by code and device type; 4, license: licensees take device datasets with provenance, shown as an arrow to a licensee box. 5, royalties: an arrow runs back under both regions from the data network to the contributing site.CONTRIBUTING SITE’S INSTALLSAGA DATA NETWORK1CONSENTThe site opts inand chooses whatit contributes.2DE-IDENTIFYAn allowlist keepsthe codedreadings;identifiers staybehind.3AGGREGATEReadings frommany sites pool bycode and devicetype.4LICENSELicensees takedevice datasetswith provenance.licenseedevicedatasets5ROYALTIESPaid back to each contributing site.
From consent to royaltiesFive steps across two dashed regions. Inside the contributing site’s install: 1, consent: the site opts in and chooses what it contributes; 2, de-identify: an allowlist keeps the coded readings and leaves identifiers behind. A red arrow carries the de-identified readings out of the install into the Saga data network, an optional add-on: 3, aggregate: readings from many sites are pooled by code and device type; 4, license: licensees take device datasets with provenance, shown as an arrow to a licensee box. 5, royalties: an arrow runs back under both regions from the data network to the contributing site.CONTRIBUTING SITE’S INSTALL1CONSENTThe site opts in and chooses what itcontributes.2DE-IDENTIFYAn allowlist keeps the coded readings;identifiers stay behind.SAGA DATA NETWORK3AGGREGATEReadings from many sites pool by code anddevice type.4LICENSELicensees take device datasets withprovenance.licenseedevice datasets5ROYALTIESPaid back to eachcontributing site.
Figure 2 as a table
StepWhereWhat happens
1. Consentcontributing sitethe site opts in and chooses what it contributes
2. De-identifythe site’s installan allowlist keeps coded readings; identifiers stay behind
3. AggregateSaga data networkreadings from many sites pool by code and device type
4. LicenseSaga data networklicensees take device datasets with provenance
5. Royaltiesback to the sitepaid to each contributing site
Fig. 2. The data network, an optional Saga service on top of Kymolog. A site consents, its readings are de-identified inside its install, only de-identified readings leave, Saga pools and licenses them as device datasets, and royalties go back to the sites that contributed.

What a contributing hospital decides, and what it earns

Consent comes first

Nothing is pooled until a hospital opts in. Research data consent is set at the site: the hospital chooses which device classes, units and date ranges it contributes, and under what consent terms. Readings outside that choice never reach the network.

De-identification by allowlist

De-identification runs inside the install before any reading leaves, and it works from a list of fields allowed out instead of a search for identifiers. Take one oxygen saturation (SpO₂) reading of 94 % (Fig. 3). Its LOINC code, value and unit leave as they are, and the patient and the visit leave as tokens. The time shifts by that patient's own date offset, and the device leaves as its type, a pulse oximeter.

The bed, the patient's name, record number, birth date and address, and any free text all stay behind. That makes patient data sharing for research a list of fields the hospital can read before it agrees. Identified data stays where the install runs: see who holds patient data in each deployment.

What leaves the install: an allowlistOne SpO2 reading, field by field, on either side of a dashed wall, the edge of the Kymolog install. Fields on the allowlist cross it with their rule: subject Patient/p-041 leaves as a person token; encounter Encounter/e-2207 leaves as a visit token; the code LOINC 59408-5, the value 94, highlighted in red, and the unit % leave as they are; the time taken, 2026-10-03 10:20, leaves shifted by the patient’s own date offset, here to 2027-01-14 10:20; and the device Device/ox-12 leaves as its type, pulse oximeter. Everything not on the list stops at the wall and stays in the install: the bed, the patient’s name, MRN, birth date and address, and free-text notes.IN THE INSTALLWHAT LEAVESALLOWLIST RULEsubjectPatient/p-041tokenperson t-6c1eencounterEncounter/e-2207tokenvisit v-81d0codeLOINC 59408-5as isLOINC 59408-5value94as is94unit% (UCUM)as is% (UCUM)taken2026-10-03 10:20date shifted2027-01-14 10:20deviceDevice/ox-12type onlypulse oximeterbedbed 7, ICUstayspatientname, MRN, birth date, addressstaysnotefree textstaysthe install’s edge
What leaves the install: an allowlistOne SpO2 reading, field by field, on either side of a dashed wall, the edge of the Kymolog install. Fields on the allowlist cross it with their rule: subject Patient/p-041 leaves as a person token; encounter Encounter/e-2207 leaves as a visit token; the code LOINC 59408-5, the value 94, highlighted in red, and the unit % leave as they are; the time taken, 2026-10-03 10:20, leaves shifted by the patient’s own date offset, here to 2027-01-14 10:20; and the device Device/ox-12 leaves as its type, pulse oximeter. Everything not on the list stops at the wall and stays in the install: the bed, the patient’s name, MRN, birth date and address, and free-text notes.IN THE INSTALLWHAT LEAVESsubjectPatient/p-041tokenperson t-6c1eencounterEncounter/e-2207tokenvisit v-81d0codeLOINC 59408-5as isLOINC 59408-5value94as is94unit% (UCUM)as is% (UCUM)taken2026-10-03 10:20date shifted2027-01-14 10:20deviceDevice/ox-12type onlypulse oximeterbedbed 7, ICUpatientname, MRN,birth date, addressnotefree textstays in theinstall
Figure 3 as a table
FieldIn the installWhat leaves
subjectPatient/p-041person t-6c1e (token)
encounterEncounter/e-2207visit v-81d0 (token)
codeLOINC 59408-5LOINC 59408-5 (as is)
value9494 (as is)
unit% (UCUM)% (UCUM) (as is)
taken2026-10-03 10:202027-01-14 10:20 (date shifted)
deviceDevice/ox-12pulse oximeter (type only)
bedbed 7, ICUstays in the install
patientname, MRN, birth date, addressstays in the install
notefree textstays in the install
Fig. 3. De-identification by allowlist: a field leaves only if it is on the list, and identifiers that do leave go as tokens or shifted dates. Anything not on the list, free text included, stays in the install, wherever it runs. Token values and the date offset here are illustrative.

Royalties

Data royalties go back to the hospitals whose readings a licensed dataset contains, and we report them to each site by period and by dataset. For a hospital working out how to monetize healthcare data, nothing is licensed until the site has consented and the install has de-identified the readings.

A real world data platform for device datasets

Licensees take device datasets with provenance. Each row is one coded reading: a LOINC code, a value in a UCUM unit, the device type, a shifted time and tokens for the patient and the visit. Rows from different hospitals line up because each site's edge agent coded its readings the same way at capture.

Device makers, trial sponsors and research groups license these datasets from us, so real world data licensing runs through one party for readings from many sites. Each hospital that joins adds its readings to the same real world data network, with the same fields as every other site.

Learn how a hospital joins the data network

Name a unit and the devices it runs. We show which fields would leave the install and how royalties are reported. We reply within one business day with times to talk.

Request a demo