Health data monetization where contributing sites earn royalties
A hospital running Kymolog can add its device readings to pooled datasets. It consents first, and the install de-identifies the readings before any leave, so only de-identified data reaches us. We license the datasets and pay royalties back to the contributing sites.
Add-on service · consent first · de-identified by allowlist · royalties
How the data network works
The data network is a separate add-on service we run on top of Kymolog™. A contributing hospital opts in and chooses what it contributes. Its readings are de-identified inside the install, wherever it runs, and only then do they cross to the network (Fig. 2).
On our side, readings from many sites are pooled by code and device type. We license the pooled device datasets, and royalties go back to the sites whose readings they hold.
Figure 2 as a table
| Step | Where | What happens |
|---|---|---|
| 1. Consent | contributing site | the site opts in and chooses what it contributes |
| 2. De-identify | the site’s install | an allowlist keeps coded readings; identifiers stay behind |
| 3. Aggregate | Saga data network | readings from many sites pool by code and device type |
| 4. License | Saga data network | licensees take device datasets with provenance |
| 5. Royalties | back to the site | paid to each contributing site |
What a contributing hospital decides, and what it earns
Consent comes first
Nothing is pooled until a hospital opts in. Research data consent is set at the site: the hospital chooses which device classes, units and date ranges it contributes, and under what consent terms. Readings outside that choice never reach the network.
De-identification by allowlist
De-identification runs inside the install before any reading leaves, and it works from a list of fields allowed out instead of a search for identifiers. Take one oxygen saturation (SpO₂) reading of 94 % (Fig. 3). Its LOINC code, value and unit leave as they are, and the patient and the visit leave as tokens. The time shifts by that patient's own date offset, and the device leaves as its type, a pulse oximeter.
The bed, the patient's name, record number, birth date and address, and any free text all stay behind. That makes patient data sharing for research a list of fields the hospital can read before it agrees. Identified data stays where the install runs: see who holds patient data in each deployment.
Figure 3 as a table
| Field | In the install | What leaves |
|---|---|---|
| subject | Patient/p-041 | person t-6c1e (token) |
| encounter | Encounter/e-2207 | visit v-81d0 (token) |
| code | LOINC 59408-5 | LOINC 59408-5 (as is) |
| value | 94 | 94 (as is) |
| unit | % (UCUM) | % (UCUM) (as is) |
| taken | 2026-10-03 10:20 | 2027-01-14 10:20 (date shifted) |
| device | Device/ox-12 | pulse oximeter (type only) |
| bed | bed 7, ICU | stays in the install |
| patient | name, MRN, birth date, address | stays in the install |
| note | free text | stays in the install |
Royalties
Data royalties go back to the hospitals whose readings a licensed dataset contains, and we report them to each site by period and by dataset. For a hospital working out how to monetize healthcare data, nothing is licensed until the site has consented and the install has de-identified the readings.
A real world data platform for device datasets
Licensees take device datasets with provenance. Each row is one coded reading: a LOINC code, a value in a UCUM unit, the device type, a shifted time and tokens for the patient and the visit. Rows from different hospitals line up because each site's edge agent coded its readings the same way at capture.
Device makers, trial sponsors and research groups license these datasets from us, so real world data licensing runs through one party for readings from many sites. Each hospital that joins adds its readings to the same real world data network, with the same fields as every other site.
Learn how a hospital joins the data network
Name a unit and the devices it runs. We show which fields would leave the install and how royalties are reported. We reply within one business day with times to talk.