Skip to main content
Overview

How it works

Concept

How intracerebral EEG data travels from the hospital that recorded it into your analysis, who is accountable at each step along the way, and what the platform does to keep it protected.

In short

Recordings are de-identified at the hospital that collected them and transferred under a signed agreement. You standardize them to BIDS-iEEG yourself, then analyze them in place using tools that run inside the platform. The institution that provided the data keeps authority over it throughout.

One community on the CHORUS platform​

CHORUS.HIP is one scientific community on the shared CHORUS platform. Every community on it runs on the same architecture, the same governance model, and the same security controls.

This is why the mechanics you use every day - workspaces, sessions, applications, exports - are documented once, under the CHORUS tab, and why this section covers only what is specific to intracerebral EEG. If you have not met those concepts yet, How CHORUS works is the shortest way in.

The journey of a recording​

Data follows a controlled path from the hospital to your results, and each stage has someone accountable for it.

  • It is de-identified where it was recorded. Removing or replacing identifying information happens at the source institution, before anything leaves it. Whether the data is pseudonymised or fully anonymised depends on what the transfer agreement requires.
  • It is transferred under a signed agreement. A Data Transfer Agreement between the contributing institution and CHUV, which operates the platform, has to be in place before any data moves.
  • It arrives in a workspace. Every project has one, and the data lives inside it - isolated from every other project on the platform. See Upload iEEG data.
  • You convert it to BIDS-iEEG yourself. Standardizing recordings so they look the same across every contributing centre is a step you carry out, not something the platform does for you. See Working with BIDS-iEEG.
  • You analyze it in place. The tools run inside the workspace, streamed to your browser. Nothing is copied to your own computer while you work.
  • Results leave through a reviewed export. Taking anything out is a deliberate step that a person has to approve. See Exporting results.

Who is responsible for what​

Security on the platform depends on responsibilities being clear, and most of them sit with people rather than with software.

  • You, when you bring data in. Uploading data makes you its data controller for the platform's purposes. You are responsible for it having been properly de-identified before transfer, in line with the transfer agreement, and for it being used within the terms it was collected under.
  • The contributing institution. Participant consent, ethics approval, and the lawful basis for the research all sit with the institution that collected the data. The platform does not replace any of that - it assumes it is in place.
  • The principal investigator, for a shared project. Who is a member of the collaborative workspace, what role each person holds, and closing it when the project ends. See Manage members & roles.
  • The platform. Isolation between projects, role-based access, an audit record of consequential actions, and the export review that makes the rest enforceable.

Authority over data stays with the institution that provided it. Putting it on CHORUS.HIP does not transfer that authority to anyone else.

What belongs here​

CHORUS.HIP is dedicated to human intracerebral EEG. What belongs on it is iEEG recordings and the health- or research-related data that goes with them: the imaging used to localize electrodes, the metadata describing a recording, the results derived from it.

Data unconnected to an approved iEEG project does not belong on the platform, whatever its format.

How it is kept safe​

Protection is layered rather than resting on any single control, following the Five Safes: safe people, safe projects, safe settings, safe data, safe outputs. Even if one layer were bypassed, the others still apply. The Five Safes explains what each one means in practice.

Built to the standards your committee already asks about

ISO/IEC 27001 information-security principles, GDPR-compatible practice, Trusted Research Environment frameworks such as SATRE, and operation as a Secure Processing Environment under the European Health Data Space. Standards covers where CHORUS stands against each one.