Federated learning enables collaborative model development while keeping patient‑level data within each institution. Despite multiple demonstrations in clinical settings, routine healthcare deployment is limited because practical translation requires more than distributed model training. Operationalisation must satisfy governance and security requirements, support auditability, integrate with regulatory workflows for secondary use of health data, and run within certified secure environments.
This study implemented a decentralised swarm learning coordination layer and integrated it into an existing certified secure processing environment (SPE) run by Helsinki University Hospital (HUS). The work aimed to demonstrate that federated learning can be assessed under regulatory frameworks, deployed across independent hospitals without centralising patient data, and made available as a reusable infrastructure capability for future permit‑approved analyses.
A decentralised swarm learning system was developed and integrated into Acamedic, the certified SPE operated by HUS. Introducing the swarm coordination layer was treated as a material modification to the certified environment and therefore triggered a differential regulatory security assessment under Finland's Act on the Secondary Use of Health and Social Data and the associated Findata requirements.
The differential assessment evaluated infrastructure controls including data isolation and locality, identity and access management, logging and monitoring, network security, and environment protection. The process established a governance model that intentionally separates certification of infrastructure‑level controls from study‑specific evaluation of data, models, parameter exchanges, and outputs.
Deployment spanned three university hospitals: Helsinki (HUS), Turku (TYKS), and Tampere (TAYS). HUS served as the regulator‑assessed implementation within its certified SPE, while partner sites operated under their local institutional governance frameworks. As an operational exemplar, the authors trained federated DeepSurv survival models for acute myeloid leukaemia (AML) using harmonised longitudinal laboratory data held locally at each site.
Operational traces were captured at multiple levels: infrastructure logs, container logs, and a distributed ledger coordination layer that recorded participant registration, parameter exchanges, and model‑training lineage. These traces supported auditability and monitoring of the federated training process.
The differential security assessment identified one high‑severity, two medium‑severity, and two low‑severity findings related to the introduced extension. The authors report that all high‑ and medium‑severity findings were remediated and subsequently verified. After remediation and verification, an independent certification report was issued for the assessed extension, and the federated‑learning capability was authorised for secondary use of health data and operationalised as a reusable extension to the HUS SPE.
Technically, swarm learning was successfully executed across the three hospitals without transferring patient‑level data. The study achieved 100% parameter merge success during federated training. Traceability was provided through the combination of infrastructure and container logs plus the distributed ledger layer that documented registration events, parameter exchanges, and model lineage.
On independent test sets drawn from each hospital, the swarm‑trained AML survival model demonstrated stronger risk stratification than locally trained reference models. The abstract reports consistently stronger risk separation and higher log‑hazard ratios for the swarm model versus the locally trained models at each site: HUS 4.32 versus 1.79, TAYS 7.20 versus 3.19, and TYKS 5.90 versus 2.91. The swarm models also showed improved discrimination metrics relative to local models (details of specific discrimination statistics beyond the reported log‑hazard ratios were not provided in the source abstract).
The study demonstrates that federated learning can be integrated into a certified secure processing environment, subjected to regulatory assessment, and operated across independent hospitals without centralising patient‑level records. The principal contribution described is a reusable governance and infrastructure model that separates assessment of system‑level controls from study‑specific evaluation of datasets, models, parameter exchanges, and outputs.
By reframing federated learning as an assessed infrastructure capability rather than a project‑level exception, the approach provides a practical pathway for operationalising decentralised federated learning within regulated health‑data environments. The authors note the relevance of this model to emerging European frameworks for secondary use of health data, including secure processing environments envisioned under the European Health Data Space, which rest on comparable governance principles.
Institutional approvals were obtained: the IRBs of Helsinki University Hospital, Tampere University Hospital, and Turku University Hospital provided ethical approval for the work. The authors state that all necessary patient/participant consent procedures and institutional forms were followed and archived according to reporting requirements.
Patient‑level data used in the study cannot be made publicly available because they contain sensitive health information and are subject to Finnish legislation and institutional data‑permit conditions. The source states that access may be requested from relevant data controllers and authorities, subject to applicable approvals and secure processing requirements.
Note: This report is a preprint that has not been peer reviewed and should not be used to guide clinical practice. The abstract and article information presented here are the sole source of facts used in this rewrite; further methodological or result details beyond those reported in the source were not provided.