Cures vs. Privacy: Why We Shouldn't Have to Choose
You shouldn’t have to choose between advancing treatments and protecting privacy — modern data systems can and must do both.
Every treatment you have ever received exists because someone, somewhere, was the first to try it, and their outcome was recorded so it could help you.
You are already a beneficiary of other people's data. The question isn't whether to participate in that economy. You already do. The question is whether you can participate in it as someone whose data is treated as valuable, not extracted.
Last week at AACR 2026 in San Diego, three separate teams showed what becomes possible when clinical data is actually integrated at scale:
Amit Moran
MD Anderson
Compared spatial multiomics from patients whose tumors responded to cemiplimab against patients whose tumors did not. The work surfaced perineural invasion as a factor influencing checkpoint inhibitor response, mapping mechanism to outcome across cohorts. His framing: integrating spatial transcriptomic and proteomic data with clinical outcomes and population-level datasets can turn mechanistic observations into clinically actionable insights.
Katherine Janeway
Dana-Farber
Focused on pediatric sarcomas, where progress has stalled because there are no established biologic subtypes to target. AI-driven digital pathology is starting to do what manual classification could not, while her team combines tumor and patient data to build osteosarcoma subtypes for pediatric and AYA populations.
Sarah Tasian
CHOP
Made the parallel case from leukemia: risk-adapted chemotherapy has improved average outcomes in childhood ALL, but genetic heterogeneity across B- and T-cell pediatric ALL populations means one-size-fits-all treatment does not hold.
Three rooms, three cancers, three teams. Same requirement: data at population scale, integrated across modalities and institutions. One patient's spatial transcriptomics profile doesn't tell you which tumors respond to checkpoint inhibitors. One child's genetic subtype doesn't reveal how to treat pediatric ALL. The patterns only emerge across thousands of cases, cohorts, and time.
So why isn't this happening faster?
Because the people whose data this depends on have every reason to say no.
Look at 23andMe. In 2018, the company entered an exclusive $300M data partnership with GSK. Over five years, that deal produced roughly 50 therapeutic programs built on insights derived from customer DNA. In 2023, hackers accessed the genetic data of millions of customers; a 2024 lawsuit alleged that information on Ashkenazi Jewish and Chinese-heritage customers had been curated into lists and sold online. In 2025, 23andMe filed for bankruptcy, and the genetic data of 15 million people became an asset in a Chapter 11 proceeding. About 1.9 million customers requested deletion. HIPAA didn't apply, because direct-to-consumer genetics companies aren't covered by it.
The data ultimately ended up at a nonprofit run by the co-founder, but the precedent stands. Consent given for "research" in 2015 looks very different than what the average customer pictured.
The field's instinct when this comes up is to say we're "data hungry" and to ask for more. That framing is the problem. It makes the patient the supplier and the company the consumer.
The right pitch isn't "we need your data." It's "your data is valuable, here is exactly why, here is who it will help, and here is what we will never do with it."
This is the work at LooporaData. Validation pathways where the model goes to the data instead of the other way around. Custody stays at the health system. Phased rollouts that start with a hello-world test on the buyer's own data before any patient record is touched. Built so that the patient whose data is in the system can be told, in plain language, what their data did and didn't do.
It's also why I'm starting a podcast.
The conversations about clinical data and AI that matter most aren't happening on stages. They're happening on calls and in clinics and at kitchen tables, and most of them never reach the person whose data is being talked about. Closing that gap.
So a real question, not a rhetorical one:
What would make you trust sharing your health data?