A recurring design failure in public-health programs is that the funder ends up with a view built for a clinician, because that view already existed and building a second one is work. The result is an agency holding individual clinical detail it has no decision to make with.
What an agency needs
- Whether the program is reaching the population it was supposed to reach, and who it is missing.
- Whether components are actually being delivered — screening completed, naloxone in homes, deliveries on schedule.
- Whether the outcomes agreed in advance are moving, including the safety measures that would show it failing.
- Whether outcomes differ by race, insurance status or geography within the enrolled population — which has to be looked for deliberately.
- Population-level drug supply warnings and overdose patterns, at a resolution a response can act on.
Every one of those is aggregate. None requires a name.
What an agency does not need
- Individual behavioral health screening results.
- Individual social determinants assessments.
- Individual monitoring data.
- Individual toxicology results.
- A list of participants and their clinical status.
An agency that receives these acquires risk without acquiring capability: it now holds sensitive information, is exposed to records requests and breach obligations over it, and has no decision that the information improves. And the population learns what the agency holds, which starts the process described in why trust is load-bearing.
The two edge cases worth naming
Evaluation. A real evaluation may need individual-level data. The answer is not to route it to the agency’s operational functions but to an evaluator under an appropriate agreement, with the analysis plan agreed in advance — see pilot design.
Safety. A specific, immediate risk to a specific person is a clinical event with a clinical response, and it goes to a clinician. It is not a reporting flow.
More: data governance.