UBC — AI Solutions

Audit — Dynamic Documentation Platform

Living documentation that stays in sync with engineering, cloud, AI, and compliance activity. Documents update themselves as the organization changes.

Back to library
SOP
Fresh

SOP-AIDLC-02 — Data Sourcing, Lineage & PHI Handling

Governs how data is sourced, minimized, tracked, and protected — including PHI — for AI development.

Owner: Data Governance LeadApprover: GRC LeadVersion: 3.0Updated: 12/10/1969

1. Purpose

Ensure data used in AI systems is lawful, minimized, traceable, and safe.

2. Scope

All datasets used for training, fine-tuning, evaluation, or retrieval.

3. Definitions

  • PHI — Protected Health Information under HIPAA.
  • Lineage — The traceable path from data source to model output.
  • De-identification — Removal or transformation of identifiers per HIPAA Safe Harbor or Expert Determination.

4. Roles & Responsibilities (RACI)

ActivityRACICadence
Approve data sourceData Governance LeadGRC LeadLegalTeamPer source
Register lineageData EngineerData Governance LeadAI PlatformTeamContinuous
Approve PHI useGRC LeadCISOLegal, ClinicalTeamPer dataset

5. Procedure

  1. Complete a data source registration record (owner, legal basis, license, consent, PHI classification).
  2. Prefer de-identified data; require Expert Determination or Safe Harbor for PHI use.
  3. Register lineage in the Data Catalog: source → transformation → dataset → model → output.
  4. Store PHI datasets in HIPAA-compliant enclaves with audit logging.
  5. Enforce data minimization: retain only fields required for the stated purpose.

6. Inputs & Outputs

Inputs

  • Data source proposal
  • Consent records
  • BAA / DPA

Outputs

  • Data source registration
  • Lineage record
  • Approval memo

7. Controls & Metrics

MetricTarget
PHI datasets with approved basis100%
Datasets with complete lineage≥ 98%

8. Exceptions & Escalation

  • Emergency incident-response data access requires CISO approval and time-boxed retention.

9. Records & Retention

RecordRetention
Data source records10 years
LineageLife of dataset + 5 years
  • SOP-AIDLC-03
  • Access Control Policy
  • SOP-PM-08

11. References

  • HIPAA Privacy Rule
  • GDPR Art. 5, 25
  • NIST AI RMF Map

12. Revision History

See the Versions tab for the full change history maintained by the Auto-Doc Engine.


Document code: SOP-AIDLC-02 · Aligned to HIPAA §164.502(b) / GDPR Art. 5, 25 / NIST AI RMF Map. Controlled document — reproduction outside the UBC QMS requires the Quality Manager's approval.

Suggested by AI
No suggestions right now.
Frameworks
HIPAA
GDPR
AI Governance
ISO 27001