10 HIPAA Tips for Clinical Research Professionals
Know Which HIPAA Pathway Applies to Your Study Before You Access Any PHI
Structure the Research Authorisation to Include All Eight Required Elements
Understand the Three Criteria an IRB Must Find Before Granting a Waiver
A waiver of authorisation allows a covered entity to use or disclose PHI for research without obtaining individual authorisation, but only when an IRB or Privacy Board finds that all three required criteria are met. Research teams often request waivers without fully understanding what the IRB is being asked to determine, which leads to incomplete waiver applications and delayed approvals.
Retrospective chart reviews, large historical database studies, and feasibility studies where contacting subjects is not possible are the most common waiver-eligible research types.
Apply the Minimum Necessary Standard to Every PHI Request and Disclosure
Use a Limited Data Set with a Data Use Agreement When Full Anonymisation Is Not Feasible
A limited data set retains certain geographic and date elements but strips the 16 direct identifiers required under Safe Harbor. It can be used for research with a data use agreement (DUA) rather than individual authorisation or a waiver.
The DUA must require the recipient to limit use to specified purposes, apply appropriate safeguards, and report any unprovided disclosures. Review the obligations it places on the recipient before it is signed.
Treat De-Identification as a Formal Process with Documented Verification
Coordinate HIPAA Authorisation and Informed Consent Into a Single Coherent Conversation
Define Your Data Retention and Destruction Schedule Before the Study Opens
HIPAA does not specify a research records retention period, but FDA regulations require records for regulated clinical investigations to be retained for at least two years after an NDA or BLA is approved or closed. State laws and sponsor agreements often extend that further. Research PHI without a destruction schedule is an ongoing liability.
Know the Breach Notification Timeline and Who Is Responsible for Reporting
Document Every HIPAA Compliance Decision in the Research Regulatory Binder
Frequently Asked Questions
Sources
- HHS: HIPAA Privacy Rule and Research
- HHS: Research and the HIPAA Privacy Rule Guidance
- HHS: HIPAA Breach Notification Rule
- HHS OHRP: 45 CFR 46 Common Rule


