Subsalt Adds Secure Runtime for Analyzing Protected Health Data
Subsalt, a provider of privacy-preserving health data infrastructure, has launched Secure Runtime, a computing environment designed to let health systems analyze protected health information without exposing patient-level data to users.
Authorized users can run Python inside the environment to calculate metrics, test hypotheses, and create charts, heatmaps, and other visualizations. Health systems control who can access data, permitted uses, and which analytical outputs can be exported.
Datavant evaluated Secure Runtime under HIPAA's Expert Determination standard, examining aggregate outputs and automated privacy tests that determine what information can leave the environment. Datavant had previously evaluated Subsalt's technology for generating de-identified digital twin patient populations.
Subsalt is also making Subsalt MCP generally available. The Model Context Protocol implementation lets AI chat applications connect to an organization's custom de-identified datasets while retaining existing access and governance controls.
For health care IT teams, the architecture addresses a central problem in analytics and AI: providing researchers and applications with useful access to sensitive information without broadly distributing the underlying patient records. Keeping computation close to protected data and controlling exported results can reduce exposure compared with workflows that move raw datasets among analytics environments.
The addition of MCP extends that model to AI agents and natural-language interfaces, but it also makes authorization and output controls increasingly important as users gain easier ways to query clinical datasets.
Secure Runtime and Subsalt MCP are generally available to new and existing Subsalt customers.
Posted by MedCloudInsider Editors on 09/16/2026