Longevity Next

The Health-Data Moat: Rights, Retention and the Cost of Useful Evidence

A framework for evaluating health-data rights, retention, collection costs and external performance without mistaking dataset size for defensibility.

Published
Last updated
Last reviewed

A commercial-diligence framework; public examples do not establish private contracts, margins or company valuation.

A longitudinal dataset becomes a commercial asset only when an organisation can lawfully use it, keep collecting information that matters, and turn that information into something a customer cannot easily obtain elsewhere. A large record count answers none of those questions on its own. The useful diligence unit is not a stored data point. It is a reusable, sufficiently complete patient trajectory connected to a defined application.

Evidence reviewed through 19 September 2026. This is a commercial-diligence framework, not a valuation of any named company or legal advice. Public examples establish particular access rules or disclosures. They do not reveal a platform's private contracts, acquisition costs or profit margins.

Start with the right to use, not the ability to collect

In the United States, the HHS research guidance distinguishes several routes for covered entities to use health information: individual authorisation, specified waiver arrangements, limited datasets under data-use agreements, and information meeting the rule's de-identification standard. These are not interchangeable permissions. The guidance concerns the HIPAA framework; it does not establish every obligation of a consumer-health platform. HHS research-use guidance.

For diligence, a rights inventory should connect each dataset to its collection context, permitted purposes, counterparties and restrictions. A company may possess laboratory results for service delivery without having demonstrated permission for every proposed research, advertising or onward-licensing use. An acquisition should not silently turn a narrow permission into a broader one. The operative question is whether the intended use survives scrutiny, not whether an interface contains an accept button.

The FTC's February 2023 GoodRx enforcement announcement provides a concrete warning against equating possession with unrestricted use. The agency alleged unauthorised disclosure of sensitive health information and announced a proposed order restricting advertising-related sharing, alongside a civil penalty. This is an enforcement example with its own facts, not a ruling that every health-data business is identical. FTC GoodRx announcement.

Access can be valuable without being exclusive

UK Biobank makes data available to eligible academic, government, charitable and commercial researchers for health-related research in the public interest. Its access page describes controlled access, including the Research Analysis Platform. Commercial participation therefore does not, by itself, identify an exclusive source of data. UK Biobank access framework.

That creates a useful counterfactual: what could a capable competitor build using accessible research resources, licensed records or a new collection programme? A platform's defensibility might instead reside in difficult-to-reproduce follow-up, outcome adjudication, consented linkage or a validated workflow. Those possibilities need proof. Calling the whole database proprietary obscures which part is scarce and which part is replaceable.

US information-blocking rules also make unrestricted data lock-in a poor default assumption. The official framework addresses specified actors and interference with access, exchange or use of electronic health information, subject to its legal scope and exceptions. It is not a universal right to every company's analytical model or research dataset. ONC information-blocking resources.

Count the cost of a usable trajectory

A diligence model should start with an explicit denominator: people eligible for the intended analysis who have the required baseline, follow-up, permissions and outcome linkage. Divide the attributable costs of recruitment, sample processing, retention, quality control and linkage by that number. This proposed measure is not an accounting standard. It exposes how an apparently inexpensive acquisition funnel can produce an expensive analytical asset.

Consider an illustrative platform with strong sign-ups but weak repeat attendance. The first visit may generate revenue and a detailed profile, while producing little information about change. Buying more first visits does not necessarily fix the missing second and third visits. A useful operating dashboard would separate sign-ups, completed baselines, eligible follow-ups, linked outcomes and withdrawals, with both elapsed time and cost for each stage.

Retention should also be examined by health status and service pathway, not only as a headline percentage. If people with worsening health leave the service, the remaining cohort may look reassuring while becoming less useful for the intended decision. Spending on retention can be commercially sensible, but its value depends on which missing information it recovers. Retention that merely keeps the easiest participants is not equivalent to representative follow-up.

Interoperability is an operating test

Moving a file between systems is not the same as combining comparable measurements. Commercial diligence should ask whether units, assay versions, sampling conditions, timestamps and outcome definitions remain interpretable after linkage. It should also distinguish the cost of the initial integration from the recurring cost of maintaining it. A platform that requires repeated manual reconciliation may still be useful, but its scaling argument needs to include that labour.

The strongest test is a held-out use case: can the same pipeline support a new site, population or customer without quietly changing the definition of success? A model that performs well only in its original service population may provide local utility, not a transferable advantage. The scientific requirements are developed separately in the companion article on repeated measurement; they should not be replaced by a sales claim about dataset size.

A diligence matrix that can fail

Evidence and interpretation comparison
Claimed advantageEvidence to requestCompeting explanation
Exclusive informationContracts, consent scope and comparator accessSimilar data can be licensed elsewhere
Low collection costCost per eligible complete trajectoryCheap first visits hide costly follow-up
Durable retentionCohort-level follow-up and withdrawal reasonsSelective retention improves the headline
Transferable predictionLocked-model external evaluationPerformance depends on original population
Integrated workflowError rates and reconciliation workloadIntegration is sustained by manual effort
Difficult replicationTime, rights and operational barriers itemisedA rival can reproduce the useful subset
Customer valueDefined decision and independently assessed utilityMore measurements create more reports, not better decisions

Revenue does not answer the evidence question

A service can be commercially attractive because it saves time, improves access or organises information. None of those propositions requires a claim that it slows aging. Conversely, a scientifically valuable cohort can be shared widely and support many organisations without producing exclusivity for its original collector. Keeping these two axes separate makes both the commercial and scientific assessment more precise.

The sources reviewed here do not establish company-specific acquisition cost, lifetime value, marginal data-licensing revenue or the cost a competitor would face to replicate a particular platform. Those quantities remain diligence questions. They should not be reverse-engineered from fundraising announcements, membership prices or the number of biomarkers offered.

What would change the assessment

The commercial case would strengthen with auditable rights, sustained follow-up, external performance and a demonstrated application that customers value. It would weaken if permissions narrow, linkage proves unreliable, retention becomes selective or competitors reproduce the relevant performance at lower cost. A new data release should therefore trigger a question about incremental utility, not an automatic increase in the claimed moat.

The conclusion is conditional: longitudinal data can support defensibility, but only through specific rights, economics and execution. It is not a recommendation to buy a platform, a forecast of winners or an assessment of any organisation's legal compliance.

Sources and related reading

The contextual sources above control the named US regulatory and UK research-access examples. For the separate scientific question, see when repeated measurement improves aging-biomarker validation. For practical follow-up design, see what clinic registries need to disclose.

Opens in a new tab