Patient-generated health data (PGHD) and the trust threshold for clinical use
Photo by Codioful (Formerly Gradienta) on Unsplash
insight

Patient-generated health data (PGHD) and the trust threshold for clinical use

By Jason Alan Snyder·July 19, 2026

Roughly 98% of patient-generated health data never enters a clinical workflow. The gap is not technology. It is trust. Without a measurable threshold for provenance, recency, and validation, consumer health data remains invisible to the systems that need it most.

A patient with atrial fibrillation generates 288 heart rate readings per day from a smartwatch. A person with type 2 diabetes logs blood glucose values four times daily through a phone app. A caregiver for someone with Parkinson's disease records tremor severity on a five-point scale every evening. None of this data, by default, is clinically actionable. Not because it lacks signal. Because it lacks trust.

The clinical system has no standardized way to assess whether patient-generated health data meets the threshold required for care decisions. That absence is not a minor gap. It is the structural reason why billions of data points collected outside hospitals remain outside hospitals.

What is patient-generated health data?

Patient-generated health data (PGHD) is any health-related data created, recorded, or gathered by patients or their caregivers outside a clinical setting, without direct clinician oversight at the time of capture. The Office of the National Coordinator for Health IT (ONC) defines it broadly: health history, symptom reporting, biometric data, treatment history, and lifestyle choices that patients record on their own.

Examples include:

  • Continuous glucose monitor (CGM) readings from a Dexcomer or Libre device
  • Blood pressure logs from an at-home cuff synced to a mobile app
  • Step counts and sleep data from a Fitbit, Apple Watch, or Oura Ring
  • Patient-reported outcome (PRO) questionnaires completed between visits
  • Mood tracking entries from a mental health app
  • Food and medication diaries
  • Photos of skin lesions or wound healing submitted through a patient portal
  • Which of the following is an example of patient-generated health data? Any of the above. The distinguishing characteristic is not the type of data. It is the source: the patient, not the provider.

    This distinction matters because clinical AI systems treat data differently depending on where it originates. A blood pressure reading taken by a nurse during a clinic visit enters the EHR with an implicit chain of custody: calibrated device, trained operator, timestamped encounter, signed note. A blood pressure reading from a home cuff arrives with none of those guarantees.

    How much can we trust electronic health record data?

    Before asking whether PGHD is trustworthy enough for clinical use, we need to confront the uncomfortable baseline: EHR data itself has significant trust problems.

    A 2023 JAMIA study found that up to 30% of medication lists in EHRs contain discrepancies when compared against pharmacy fill data. Diagnosis codes are frequently selected for billing optimization rather than clinical accuracy, a problem we covered in depth in our analysis of ICD-10 coding accuracy. And structured lab results lose context when LOINC codes are mapped inconsistently across systems, a challenge documented in the LOINC code standardization trust problem.

    Is EHR data considered secondary data? In research contexts, yes. When EHR data is used for purposes beyond the original clinical encounter, such as AI training, population health analytics, or payer reporting, it becomes secondary use data. This means it was never collected with those downstream applications in mind, and its quality may not support them.

    The point is not that EHR data is untrustworthy. It is that trust should not be assumed for any data source. It should be measured. That measurement is exactly what the clinical system lacks for PGHD.

    Key statistics

    DTI scoring dimensions and their weight for PGHD trust assessment
    DTI scoring dimensions and their weight for PGHD trust assessment

  • 98% exclusion rate: An estimated 98% of patient-generated health data is never integrated into clinical EHR workflows, according to a 2022 Deloitte analysis of digital health data flows.
  • 350+ million: The number of consumer wearable devices shipped globally in 2023 (IDC), each producing continuous health-adjacent data with no clinical trust framework.
  • 30% medication list error rate: Up to 30% of EHR medication records contain discrepancies versus pharmacy fill data (JAMIA 2023), establishing that even institutional data has measurable trust deficits.
  • 3 weeks to 2 hours: SuperTruth reduced data standardization time for 105,000 diagnostic records from imaware by 95%, demonstrating that trust scoring at scale is operationally viable.
  • 72% of patients report willingness to share wearable data with their clinician (Rock Health 2023 Consumer Survey), but fewer than 10% of health systems have a structured intake pathway for it.
  • The five trust failures that keep PGHD out of clinical workflows

    When a clinician ignores a patient's home blood pressure log, the decision is rarely arbitrary. There are specific, identifiable reasons why PGHD fails to cross the trust threshold. Each one maps to a scorable data dimension.

    1. Provenance is unverifiable

    Where did this reading come from? Was the device FDA-cleared or a $15 Amazon knockoff? Was the patient wearing the sensor correctly? Was the app that transmitted the data validated? For most PGHD, nobody can answer these questions.

    Provenance is the single most heavily weighted dimension in the SuperTruth Data Trust Index, accounting for 25% of the total score. For PGHD, provenance is almost always incomplete.

    2. Recency is ambiguous

    A patient uploads three months of glucose data before an endocrinology visit. Which readings are clinically relevant? The ones from last week? Last month? The system has no standard for recency windows in PGHD, so the clinician either reviews everything (impractical) or ignores everything (common).

    Recency accounts for 15% of the DTI score, and it is the dimension most frequently degraded in PGHD because batch uploads destroy temporal context. We have written about this pattern in why recency is the most underrated dimension in health AI data scoring.

    3. Validation has no pathway

    Clinical lab results go through certified reference ranges, quality control processes, and CLIA-certified laboratories. PGHD goes through nothing. A patient's self-reported pain score of 7 out of 10 cannot be validated against an external standard. A step count from a wrist-worn accelerometer has a known error margin of 15-20% depending on gait speed, but that error margin is never attached to the data point.

    4. Concordance breaks immediately

    Does the patient's home blood pressure data agree with their clinic readings? If a patient's Apple Watch shows a resting heart rate of 58 bpm and the clinic ECG shows 72 bpm, which one reflects reality? Without concordance checking across sources, PGHD creates contradictions rather than clarity.

    Concordance is 10% of the DTI score, and for PGHD, it is the dimension that determines whether patient data supplements or undermines the clinical record.

    5. Consent is assumed, not governed

    When a patient shares their Fitbit data through a health system's patient portal, what consent was actually granted? Can that data be used for AI model training? Can it be shared with a research partner? Most health systems treat PGHD consent as a binary: the patient uploaded it, so we can use it. That assumption fails under scrutiny, especially as regulations tighten around consent governance and consumer data rights.

    The integration problem is a trust problem disguised as a technical one

    Most published literature on PGHD and EHR integration treats the challenge as primarily technical: FHIR APIs need to support PGHD resources, EHR vendors need to build intake pathways, and data formats need standardization. These are real issues. But they are not the binding constraint.

    The binding constraint is that no one has defined what "good enough" looks like for PGHD in clinical contexts. There is no threshold. There is no score. There is no equivalent of a lab result's reference range or a radiology report's structured findings.

    Without a defined trust threshold, integration is meaningless. You can pipe wearable data into Epic through a FHIR R4 API, and the data will sit in a tab that no clinician opens. The infrastructure works. The trust does not.

    This mirrors the broader pattern we see across healthcare data. As we documented in digital health app data: the gap between consumer trust and clinical trust, consumers trust their health apps far more than clinicians do. The gap is not irrational on either side. Consumers trust what they experience daily. Clinicians distrust what they cannot verify.

    What a trust threshold for PGHD clinical use actually requires

    A clinical trust threshold for PGHD needs to be quantitative, not qualitative. Saying "clinicians should consider patient-generated data when appropriate" is a policy statement, not a standard. Here is what a real threshold requires.

    Device provenance scoring. Every PGHD data point should carry metadata about the device that captured it: manufacturer, model, FDA clearance status, calibration date, and firmware version. A reading from an FDA-cleared blood pressure cuff scores differently than a reading from an unvalidated app.

    Temporal context preservation. Batch uploads should be decomposed into individual timestamped readings, each scored for recency relative to the clinical question. A glucose reading from 72 hours ago has different clinical utility than one from 72 days ago.

    Cross-source concordance checking. PGHD should be automatically compared against available clinical data. If a patient's home readings systematically diverge from clinic readings, that divergence should be flagged, quantified, and scored rather than ignored.

    Consent tier assignment. Every PGHD record should carry a consent classification: clinical use only, research permitted, AI training permitted, or restricted. This is what ConsentOS was built to handle.

    Composite trust scoring. All of these dimensions should roll up into a single score that a clinician, researcher, or AI system can use as a filter. Below the threshold: do not use for clinical decisions. Above the threshold: include with documented provenance. This is the logic of the Data Trust Index applied to patient-generated data.

    Why clinical AI cannot afford to ignore PGHD

    The argument for defining a trust threshold is not academic. It is operational.

    Clinical AI models trained exclusively on EHR data miss the 99% of a patient's life that happens outside a clinic. For chronic disease management, oncology symptom monitoring, post-surgical recovery tracking, and rare disease surveillance, the signal is in the patient-generated layer.

    Consider the behavioral intelligence that VIOLET maps across oncology populations. Patients search for symptoms, side effects, and treatment options weeks or months before those concerns appear in a clinical record. That behavioral data is a form of patient-generated signal. Without a trust framework, it remains invisible to clinical systems.

    Or consider the pattern documented in type 1 diabetes behavioral data: CGM adoption signals appear in search behavior before they appear in clinical outcomes data. The patient is generating data long before the system captures it.

    The clinical AI models that will outperform in the next five years are the ones that can ingest, score, and use patient-generated data alongside institutional data. The ones that cannot will be training on an increasingly incomplete picture of patient health.

    The PGHD trust threshold in practice

    DTI score thresholds by PGHD clinical use case
    DTI score thresholds by PGHD clinical use case

    What does this look like operationally? A health system deploying a remote patient monitoring program for heart failure patients collects daily weight, blood pressure, and symptom data from 5,000 patients. Today, a nurse reviews flagged values manually. Tomorrow, an AI model triages the data.

    But which data? All of it? Only readings from FDA-cleared devices? Only readings that concordance-check against the last clinic visit? Only readings with complete device metadata?

    The answer depends on the use case. A population health dashboard might accept PGHD with a DTI score of 40 or above. A clinical decision support alert might require 70 or above. An AI model being submitted to the FDA for clearance might require 85 or above, consistent with what Platinum-grade data guarantees.

    The threshold is not fixed. It is contextual. But it must exist. Without it, every system either accepts all PGHD uncritically or rejects all PGHD reflexively. Neither serves patients.

    What the wearable explosion means for trust infrastructure

    With 350 million consumer wearable devices shipped in 2023 alone, the volume of patient-generated health data is growing faster than any other category of health information. Apple, Google, Samsung, Garmin, Oura, Dexcom, Abbott, Withings, and dozens of other manufacturers are creating continuous streams of biometric data.

    Most of this data lives in consumer platforms with no clinical trust framework applied. The wearable data trust problem is not a future concern. It is a present reality that compounds daily.

    Every month that passes without a trust scoring standard for PGHD is another month of unscored, unvalidated data accumulating in consumer apps that patients assume their doctors can see and use. The longer the gap persists, the harder the eventual integration becomes.

    The role of the patient as data steward

    One underappreciated dimension of the PGHD trust problem is that patients are being asked to serve as data stewards without any of the tools or training that role requires. They are expected to maintain device calibration, ensure consistent measurement conditions, report accurately, and manage data sharing permissions across multiple platforms.

    This is why patient-controlled data platforms matter. MyBio.Health was designed around the principle that patients should own their data and control its flow, but with trust infrastructure underneath. When a patient shares data from MyBio.Health, it arrives with provenance metadata, consent classification, and a trust score. The patient remains the steward. The data arrives ready for clinical evaluation.

    Building the bridge between consumer health data and clinical AI

    The path from PGHD to clinical utility runs through trust scoring. Not through more FHIR APIs. Not through more EHR vendor integrations. Not through more patient portal features. Those are necessary but insufficient.

    The sufficient condition is a measurable, auditable trust threshold that can be applied at the point of data ingestion, adjusted by use case, and enforced before any AI model trains on patient-generated data.

    SuperTruth's DTI Engine scores every health data record across 8 dimensions: Provenance (25%), Consent (20%), Recency (15%), Quality (10%), Concordance (10%), Validation (10%), Breadth (5%), and Stability (5%). That scoring framework applies to EHR data, claims data, lab data, imaging data, and patient-generated data alike. The standard does not change based on the source. The threshold changes based on the use case.

    This is what closes the gap between the 350 million devices generating data and the clinical systems that need it.

    The DTI Engine scores every health data record 0-100 across 8 trust dimensions before your AI model sees it. If your team is building clinical AI that needs to incorporate patient-generated data, or if you are defining trust thresholds for remote monitoring programs, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140.

    Further reading:

  • DTI™ Engine
  • Health systems solution
  • The wearable data trust problem: from consumer device to clinical intelligence
  • Digital health app data: the gap between consumer trust and clinical trust
  • Why recency is the most underrated dimension in health AI data scoring
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    The FICO score for health data.

    8 dimensions. 0–100. Travels with every record permanently.

    See the DTI Engine
    Share