Closing the missing lineage gap in healthcare analytics with a governance-backed certification model is crucial to connect business decisions to outcomes.
Aug 25 26
7 min read
Uzma Jilani
Healthcare organizations spend enormous effort defining performance measures, such as member months, medical cost per member per month (PMPM), utilization per 1,000, network leakage, risk scores, readmission rates, quality measures and financial ratios.
These definitions are debated by finance, clinical, operations, analytics and technical teams because the choices matter.
Yet after the meeting ends, the decision often fragments. A note lands in a spreadsheet. A developer changes SQL. A dashboard is updated. Months later, someone asks why the number changed, and the organization can trace the rows back to a made those rows meaningful
Closing the gap
Traditional data lineage is good at answering where data came from and how it moved. Governance is intended to answer who decided, what was approved and under which policy or business rule a decision was made. For a reportable healthcare KPI, those two questions should not live in separate systems of memory.
Governance explains WHY the metric is defined this way. Lineage explains WHERE the reported value came from.
This proposed model treats an approved governance decision as the start of an executable chain rather than the end of a meeting. The sequence is straightforward: governance conversation → governance decision ID → governed business rule → KPI registry → gold semantic dependencies → certified table → reportable KPI.
Each stage creates evidence. The governance decision ID records the approved rationale, owner, effective date and status. The KPI registry gives the metric a canonical identity, business definition, reporting grain, numerator, denominator, exclusions, timing basis and refresh cadence. A dependency bridge explicitly records which gold-layer objects implement the KPI and the role each object plays.
The missing link
For example, a medical cost PMPM measure might use a medical claims fact as the numerator, a member-month fact as the denominator, line of business and date as dimensions, and a governed exclusion rule for denied or otherwise excluded claims. Recording those roles creates a query-able dependency map rather than leaving the relationship hidden in SQL.
That map enables practical questions that healthcare data teams routinely struggle to answer. These include which KPIs use member months as a denominator? Which certified tables are affected if a provider-network definition changes? Which reports must be reviewed if a classification methodology is re-versioned? Which governance approvals must be reopened before a change is promoted?
More than a metadata exercise
Healthcare data are unusually sensitive to timing, restatement and context. Eligibility can be corrected retroactively. Claims mature after service. Provider affiliations change over time. Financial periods may be frozen while incurred reporting remains restatable. A claim line is not always a clinical encounter. Classification logic and risk models are versioned.
Those realities mean a governance decision can directly change architecture and ETL behavior. The most useful example is member months.
Suppose leadership asks for five years of incurred medical cost PMPM. The analytical requirement is five years of membership denominators aligned to incurred service periods. It does not automatically follow that the ETL process should rebuild all 60 months of membership every month.
A governed implementation may instead require an initial 60-plus-month historical build, incremental processing for the new month, a defined retroactive eligibility window, targeted historical backfills for exceptional corrections and separate frozen membership behavior when a financial no-retro use case requires it.
That is not merely an optimization decision. Reprocessing too little can leave retroactive eligibility changes stale, which can overstate member months and understate PMPM or utilization per 1,000. Reprocessing everything unnecessarily increases compute, runtime and operational risk. Mixing restatable incurred membership with frozen financial membership can break reconciliation.
The larger lesson is that healthcare domain knowledge changes engineering design, and engineering design changes reported performance.
What certified should really mean
In this model, certification is a publication boundary. Reusable gold facts and dimensions can support many analyses, but a KPI becomes a trusted reporting product only when its governed definition has been implemented, validated and published through a controlled certified table.
A certified KPI should have an approved definition; documented numerator, denominator, exclusions and timing basis; assigned business and technical ownership; completeiliation evidence; a defined refresh and restatement policy; and certification metadata such as version
This also reduces one of the most persistent analytics risks, which is recreating business logic in the visualization layer. Tableau, Power BI or another reporting tool should consume the certified output rather than become the place where the KPI is redefined.
Standardizing the governance method
A multi-client healthcare organization should not assume that every client, market or contract has the same legitimate business rules. Line-of-business definitions, contractual denominators, paid-vs.-incurred basis, provider-network rules, benchmark methods and exclusions can differ.
The enterprise opportunity is to standardize how those differences are governed. The shared standard can include KPI naming, governance workflow, Gold modeling conventions, data-quality controls, lineage structure, certification criteria and common healthcare definitions. Client or market configuration can then record approved sources of truth, contract-specific denominators, timing rules, benchmarks and overrides.
The goal is not to eliminate variation. It is to make variation explicit, versioned and auditable.
Supporting change, retirement and compliance
After a KPI is connected to its governance decision, gold dependencies, sources and certified outputs, the organization gains a forward-looking control surface as well as a backward-looking audit trail.
Before a rule changes, teams can identify affected metrics, tables, clients, historical periods and dashboards. When an asset is retired, the same relationships can identify dependent reports, access entitlements, retention rules and purge candidates. Governance records can preserve the owner, policy basis, approval, timestamp, change history and disposition evidence.
This does not make a data architecture a legal authority. Legal hold, retention, HIPAA, contractual and security requirements still come from the appropriate legal, privacy, compliance and security functions. What the architecture provides is the traceability needed to execute those policies consistently and demonstrate what was decided and what was done.
What we learned
The framework was developed through a health-plan gold semantic-layer design effort covering 54 documented KPIs across executive, financial, utilization, care management, utilization management, risk adjustment, plan operations, growth, quality and experience domains.
The portfolio made the dependency problem visible. Some measures share the same denominator but differ in numerator and timing. Some are sourced from claims, others from finance, care management, utilization management, surveys or risk systems. Some require client-specific rules while others can use common enterprise definitions. Treating each KPI as a registered, governed object provides a common control model across those differences.
More importantly, the approach shifts the governance conversation from ‘Where is the definition documented?’ to ‘Can we prove the path from approved decision to published value, and can we predict what will be affected if that decision changes?’
A practical starting point
Organizations do not need to govern every metric on day one. A pragmatic implementation starts with high-risk KPIs: board-level measures, financial and regulatory metrics, contract-sensitive measures, and metrics with known cross-team definition drift.
For each, establish a canonical KPI ID, assign decision ownership, record the approved business rule, map semantic dependencies andlt through a controlled table. Then expand the pattern to additional domains and use the metadata graph for change-impact analysis and lifecycle management
Healthcare analytics cannot be trusted solely because data lineage is technically complete, and it cannot be trusted solely because a governance committee approved a definition. A trustworthy KPI needs both: provenance of the data and provenance of the decision.
Connecting those forms of provenance turns governance from documentary overhead into an architectural control. It gives engineers a clear implementation contract, gives business owners a durable record of intent, and gives data consumers a certified output that can be traced backward and assessed forward.
A reportable KPI should be able to answer two questions at any time: Where did this number come from? And why is this the number we agreed to report?
Uzma Jilani, FACHDM, is a senior director of data management and operations for Navvis.
More for you
Loading data for hdm_tax_topic #reducing-cost…
