Federated learning in a regulator-audited secure processing environment: a multi-hospital deployment study

Wait 5 sec.

Background. Federated learning enables collaborative model development without transferring patient level data between institutions. However, translation into routine healthcare practice remains limited because deployment requires more than distributed model training. Federated infrastructures must operate within secure processing environments, satisfy governance and security requirements, support auditability, and integrate with existing regulatory workflows for secondary use of health data. Although federated learning has been demonstrated in multiple clinical applications, evidence for its deployment, assessment, and operation within regulated health-data infrastructures remains limited. Methods. We implemented a decentralised swarm learning system for federated learning and integrated it into Acamedic, a certified secure processing environment (SPE) operated by Helsinki University Hospital (HUS). Introduction of the swarm learning coordination layer constituted a material modification to the previously certified HUS SPE and triggered a differential regulatory security assessment under Finland's Act on the Secondary Use of Health and Social Data and associated Findata requirements. The assessment evaluated controls relating to data isolation and locality, identity and access management, logging and monitoring, network security, and environment protection, while establishing a governance model that separates certification of infrastructure-level controls from study specific assessment of data, models, parameter exchanges, and outputs. The swarm learning architecture was developed and deployed across the university hospitals of Helsinki, Turku, and Tampere, with HUS serving as the regulator-assessed implementation within a certified SPE and partner sites operating under local institutional governance frameworks. As an operational exemplar, we trained federated DeepSurv survival models for acute myeloid leukaemia (AML) using harmonised longitudinal laboratory data. Findings. The differential security assessment identified one high-severity, two medium-severity, and two low-severity findings. All high- and medium-severity findings were remediated and verified, after which an independent certification report was issued for the assessed extension. The resulting federated-learning capability was authorised for secondary use of health data and operationalised as a reusable extension to the HUS secure processing environment. Swarm learning was successfully executed across three university hospitals without transferring patient-level data, achieving 100% parameter merge success. Training operations were traceable through infrastructure logs, container logs, and a distributed ledger coordination layer recording participant registration, parameter exchanges, and model-training lineage. On independent test sets from all three hospitals, the swarm-trained AML model demonstrated stronger risk stratification than locally trained reference models, with consistently stronger risk separation, higher log-hazard ratios (swarm vs local: 4.32 vs 1.79 at HUS, 7.20 vs 3.19 at TAYS, and 5.90 vs 2.91 at TYKS), and improved discrimination metrics. The resulting federated-learning capability was authorised for secondary use of health data, operationalised as a reusable extension to the HUS secure processing environment, and made available for future permit approved analyses. Interpretation. This study demonstrates that federated learning can be integrated into a certified secure processing environment, subjected to regulatory assessment, and operated across independent hospitals without centralising patient level data. The principal contribution is a reusable governance and infrastructure model that separates assessment of system-level controls from study specific evaluation of data, models, parameter exchanges, and outputs. By enabling federated learning to function as an assessed infrastructure capability rather than a project-specific exception, the approach provides a practical pathway for operationalising decentralised federated learning within regulated health-data environments. The findings are directly relevant to emerging European frameworks for secondary use of health data, including secure processing environments envisioned under the European Health Data Space, whose implementation builds on many of the same governance principles evaluated in this study.