Case study
How we identified clinical trial risks before they became costly problems
Auditing a live clinical research platform to strengthen data protection, workflow integrity, and delivery decisions before further investment.
- Healthcare
- Clinical research
- Technology & Delivery Assessment
- Independent advisory
- Technology & Delivery Assessment
- Clinical systems risk diagnosis
- Security and data integrity review
- Delivery oversight
- Client
- University of Birmingham
- Initiative
- Ongoing clinical trial project
- Industry / Domain
- Healthcare, clinical research
- LLI role
- Independent technology and clinical systems advisor
- Scope
- Audit, risk diagnosis, advisory support, ongoing project oversight
Overview
Ensuring a high-risk clinical trial met regulatory, security, and real-world research needs before further investment.
The problem
The University of Birmingham was already running a clinical research project supported by an external software vendor. While development was progressing, the research team lacked confidence that the application truly reflected clinical workflows, adequately protected participant data, and complied with clinical research standards.
Key issues included limited visibility into the system architecture, insufficient documentation, unclear data-handling practices, and a growing risk that design shortcuts could lead to participant deanonymisation or data contamination. These were not abstract technical concerns. They directly affected patient safety, regulatory compliance, and the credibility of the research itself.
Researchers, clinicians, and project stakeholders faced operational risks, reputational damage, and the possibility of having to invalidate or repeat parts of the study if flaws were discovered too late.
What was at stake
Clinical trials operate under strict ethical and regulatory constraints. Any failure in data protection or process integrity could have led to breaches of confidentiality, non-compliance with HIPAA requirements, or unusable study results.
If the project had continued without intervention, the university risked escalating costs, delayed timelines, and irreversible damage to participant trust. A poorly designed solution would not just fail technically. It would undermine the scientific validity of the trial and expose the institution to legal and reputational consequences.
Why LLI
LLInformatics was engaged to provide an independent, expert assessment rather than incremental development support. The university needed a partner capable of owning responsibility for identifying real risks, challenging existing assumptions, and translating clinical realities into technical direction.
Partial outsourcing or isolated code reviews were not sufficient. What was required was a holistic technology risk diagnosis combined with hands-on advisory support across security, architecture, user experience, and delivery planning.
This aligns directly with LLI's Technology & Delivery Assessment and interim advisory services.
Our approach
Before proposing changes, we focused on understanding the clinical context.
Decisions were guided by three principles:
Patient safety first
Data integrity over speed
Clarity over complexity
We deliberately prioritised real-world clinical scenarios rather than idealised user journeys. We avoided over-engineering and instead focused on safeguards, transparency, and maintainability.
Trade-offs were assessed openly with stakeholders, particularly where cost, scope, and compliance intersected.
The solution
LLI delivered a structured audit and ongoing advisory support that addressed both immediate risks and longer-term sustainability.
Core capabilities
- 01
Identification and mitigation of data security and deanonymisation risks
- 02
Clinical workflow aligned data models and user flows
- 03
UX simplification to support participant focus and reduce error rates
- 04
High-level system architecture diagrams and interaction visualisations
- 05
Independent verification of estimates, scope, and delivery plans
Key design choices
Introducing additional safeguards to meet HIPAA compliance requirements
Designing user journeys that explicitly covered non-happy-path scenarios
Removing non-essential interface elements that distracted from clinical tasks
Establishing shared architectural artefacts to improve cross-team communication
Each decision directly addressed an identified risk or operational gap, reducing the likelihood of compliance failures or data quality issues.
Technology stack
Specific technologies were reviewed rather than replaced wholesale.
- Secure data handling
- Role-based access control
- Scalable architecture patterns appropriate for sensitive clinical data
Choices were evaluated on their ability to support auditability, security, and long-term maintenance rather than novelty.
Dedicated team
Senior technology consultant with healthcare and clinical systems experience
Security and compliance specialist
UX advisor with experience in regulated environments
Interim technical leadership support for ongoing oversight
Engineering standards
Code quality
Emphasis on clarity, traceability, and defensive design.
Testing and reliability
Focus on data integrity checks and edge-case handling.
Documentation and collaboration
Creation of high-level diagrams and shared artefacts to support alignment.
Long-term sustainability
Decisions validated against future study extensions and regulatory scrutiny.
Results and impact
For users
Participants experienced clearer, more focused interactions with reduced cognitive load and lower risk of errors.
For the organisation
The university gained confidence that the project aligned with clinical regulations and ethical standards, reducing institutional risk.
For operations and data
- Data contamination risks were reduced
- Security posture improved
- Delivery effort was optimised through clearer scope and prioritisation
- Project costs were lowered by avoiding unnecessary or inflated implementation work
Why this case matters
This project demonstrates LLI's ability to operate at the intersection of clinical research, technology risk, and organisational decision-making.
It reflects our standards for independence, accountability, and judgement under regulatory pressure.
We are particularly suited to complex, high-stakes environments where failure is costly and where technical decisions have human and ethical consequences.
The value: the university gained an independent view of the technology, risks, and delivery plan before committing further investment, creating a clearer path towards a secure, clinically appropriate, and sustainable research platform.
More case studies
Start the conversation
Build the right technology with the right engineering partner.
Tell us what you are planning, and our senior team will help you define the strongest way forward.
Talk to our team