Test data obfuscation for
five million transactions a day.
A state healthcare provider needed to validate production-level volumes of integrated doctor-patient records without exposing patient information. HealthTest's test data obfuscation protected production records, created full test condition variations and tested more than 5 million transactions a day.
Real volumes.
Protected patients.
Integrated doctor-patient record systems must work at the volumes hospitals generate every day. Testing with small samples misses the defects that appear only at scale, but using real patient records in test environments would breach privacy obligations and expose patients.
The provider needed test data that behaved exactly like production, with records connected across systems, while ensuring no real patient could be identified from it. Simple masking would break the links between doctors, patients and records, so a more careful approach was essential.
It also needed every meaningful variation of test conditions covered, which is impossible to prepare and execute by hand at production volumes. Manual testing would only ever sample a fraction of the records, leaving scale-related defects undiscovered until the platform went live.
What made it hard
- Production volumes
- Validation had to reflect the real daily volume of patient transactions, not a small sample that would hide scale defects.
- Patient privacy
- Personal health information could not be exposed in test environments, to testers, developers or any partner teams.
- Connected records
- Obfuscated data had to keep relationships between records intact, so doctors, patients and appointments still linked correctly.
Obfuscated production data,
tested at scale.
PinnacleQM applied HealthTest, its healthcare automation platform, to obfuscate production records and generate the full set of test condition variations. It then executed them automatically at production volume, comparing results against expected outcomes without exposing any patient.
Smart obfuscation replaced identifying patient details while preserving referential integrity, so records stayed connected across systems and tests behaved as they would in production. The resulting data could be used safely at full volume, without any real patient being identifiable.
HealthTest created test scripts and expected results automatically, and ran more than 5 million transactions per day, validating the integrated records at genuine scale. Automated comparison against expected results meant defects were found quickly, with clear evidence for the teams responsible.
From production data
to automated validation.
Three stages turned sensitive production data into safe, scalable test coverage.
-
01
Design
-
Records obfuscated
Production doctor-patient records were obfuscated with referential integrity preserved, so linked records still behaved as they would in production.
-
Conditions generated
Full test condition variations were created from the obfuscated data, covering far more scenarios than manual test design allows.
-
Records obfuscated
-
02
Execution
-
Automated execution
HealthTest executed more than 5 million transactions per day, validating the platform at the volumes hospitals really generate.
-
Automated execution
-
03
Verification
-
Results compared
Automated comparison validated every outcome against expected results, so defects were identified quickly and with clear evidence.
-
Results compared
Production scale,
zero exposure.
The provider validated at real volumes without privacy risk.
What the
provider gained.
Scale and privacy, together.
- Validation at genuine production volumes.
- Patient information protected throughout testing.
- Connected records preserved across integrated systems.
- Full test condition coverage generated automatically.
- Defects found that small samples would miss.
- Reusable data and scripts for future changes.
Need realistic data
without the risk?
Tell us about your systems, data sensitivity and testing volumes. We will show how obfuscated, production-scale data could strengthen your testing.
- Share your systems, data types and privacy obligations.
- We assess obfuscation and data generation needs.
- You receive a test data approach and plan.