HEALICS

Secure research environments for sensitive data

HEALICS provides secure, research environments for projects involving sensitive data. It is designed for researchers at the University of Bern, the Insel Gruppe, the Universitäres Psychiatrisches Zentrum Bern (UPZ) and collaborating institutions to jointly access and analyze data within a controlled and compliant setting, restricted to authorised project members and the defined project duration.

Developed within the Digital Medicine program, HEALICS is the service resulting from the project Development of Research Platform Bern and is intended to become the standard infrastructure for sensitive data research in Bern.

HEALICS stands for Healthcare, Education, Analysis, Life Science, Innovation, Collaboration, and Security.

HEALICS is hosted on the sovereign and ISO 27001-certified Switch Cloud.

HEALICS supports the phase of the research lifecycle in which approved data is analyzed and processed within a secure environment.

Before a project can use HEALICS, the Principal Investigator (PI) or project lead must ensure that:

  • the research project is clearly defined, including funding and project governance
  • all required approvals and authorizations are in place (e.g. ethics approval, data protection assessments and other applicable permissions)
  • all necessary permissions for the intended use of the data have been obtained from the responsible data owner or data provider.

Once all project-specific requirements have been fulfilled (e.g. ethics approval, data protection clearance, funding confirmation, and data access permissions), the project lead submits a request for a project room to the HEALICS Support team.

The HEALICS Support team reviews the request to ensure that all required information, declarations and project details have been provided. The review is limited to the completeness of the request and does not include an assessment of scientific, ethical, legal or governance aspects of the project.

Once the request has been approved, the project room is provided according to the requested project configuration. The designated room administrator is granted access and receives onboarding from the HEALICS Support team to manage the project room.

As soon as the project room is ready, the room administrator can:

  • invite and manage project members
  • import and export data through controlled processes
  • install and use project-specific software and computing resources
  • analyze and process approved data within the project environment
  • collaborate with authorized project members

Responsibility for the project, including the lawful use of data, remains with the project lead and the responsible institution.

Different projects require different levels of security, collaboration and flexibility.

HEALICS offers different policy levels:

  • TEST: For exploration, prototyping and training with non-sensitive data.
  • COLLABORATION: For individual projects working with sensitive data under controlled access conditions, including secure collaboration with internal and external partners.
  • CLUSTER HUB: For coordinated multi-project environments with structured collaboration and controlled data sharing across related projects or programs.

Each project room is isolated from other projects and configured according to policies defined when requesting room opening.

Researchers access their project environment through a web browser using Switch edu-ID with multi-factor authentication. Access to HEALICS is project-based and managed through defined roles and access rights.

Each project room includes a “room administrator” role responsible for managing project membership and user access within the room.

Responsibility for ensuring that only authorized project members are granted access remains with the project lead and the responsible institution.

Approved data can be transferred into the project room from institutional sources, collaborating partners or project-owned datasets, either through manual uploads or via dedicated interfaces (currently to Inselspital).

All data transfers follow controlled processes and require self-declaration specifying the origin and type of data being transferred.

Data remains within the project environment and is accessible to authorized users only.

HEALICS is data-format agnostic. Any data format can be used, provided it can be stored and processed within a standard file system environment.

For projects involving data from the Insel Gruppe, HEALICS is aligned with existing governance and data delivery processes.

Project rooms and all data contained within them are deleted after project completion. Project teams are responsible for exporting and retaining any data required beyond the project duration before the environment is decommissioned. Long-term data retention is outside the scope of HEALICS.

Work in a virtual Linux environment and use common research tools such as R, Python or MATLAB etc.

A range of commonly used research software is already whitelisted and available within HEALICS. The project team can submit a request to HEALICS Support for additional software to be reviewed and whitelisted.

Software licenses are not included and must be provided by the project where required.

The initial resources are provisioned according to the requirements defined when opening the project room. This includes block storage of different performances, S3-compatible object storage and compute, whether CPU based or high-performance NVIDIA GPU based.

If project requirements change during the project lifecycle, resource adjustments can be requested through the HEALICS portal and will be reviewed according to the applicable procedures.

Your responsibility

HEALICS provides the infrastructure and the operational framework. Responsibility for the lawful use of data remains with the respective project and institution.

For research projects, this means in particular:

  1. The Principal Investigator (PI) is responsible for the lawful use of data in the project.
  2. Governance responsibilities remain clearly assigned.
  3. Platform operation and project responsibility are deliberately separated.

This is an important principle: HEALICS reduces the burden of setting up secure research environments, but it does not remove project-level responsibility for lawful and appropriate research conduct.

The HEALICS Platform

Support

Designed for active research projects involving sensitive data and a defined project duration

However, it is NOT intended as:

- a long-term archive

- a generic file exchange platform

- general-purpose cloud storage

- a primary computing environment for non-sensitive data