HIPAA impact on clinical research featured image showing a clinical research coordinator pointing at a whiteboard with an IRB and consent flowchart, with a horizontal bar chart comparing HIPAA risk levels across different research data types in a split diagonal overlay panel.

HIPAA: The Impact on Clinical Research

TIPS: HIPAA and Clinical Research
HIPAA in Clinical Research: 10 Practical Tips for Research Professionals
Clinical research involves collecting and disclosing PHI in ways that fall outside standard treatment and payment activities. HIPAA’s Privacy Rule creates a distinct framework for research use of PHI, with authorisation requirements, waiver conditions, and minimum necessary standards that research teams navigate daily. These ten tips address the specific points where compliance problems most commonly occur.
Quick Tip Summary
1. Know which HIPAA pathway applies to your study
2. Get authorisation right the first time
3. Understand when a waiver is appropriate
4. Apply the minimum necessary standard to every disclosure
5. Handle limited data sets with a data use agreement
6. Treat de-identification as a formal process, not a judgment call
7. Coordinate HIPAA and informed consent into one conversation
8. Plan data retention before the study begins
9. Know your breach reporting obligations
10. Document every HIPAA decision in the research file
What You Will Learn
Which HIPAA pathway applies to each study type. How to structure a valid research authorisation. When waivers apply. How the minimum necessary standard works in research. How limited data sets and data use agreements function. What de-identification requires. And what breach notification obligations look like.

10 HIPAA Tips for Clinical Research Professionals

1
Know Which HIPAA Pathway Applies to Your Study Before You Access Any PHI
Why It Matters
The Privacy Rule offers several pathways for research access to PHI: individual authorisation, waiver of authorisation granted by an IRB or Privacy Board, preparatory-to-research access, decedent research access, and use of de-identified data or limited data sets. Each has different requirements and limitations. Starting a study without confirming which pathway applies is one of the most common sources of HIPAA problems in research settings.
What To Do
Before accessing any PHI, confirm with your IRB and privacy officer which pathway applies. Document the decision in the protocol and regulatory binder. Pathway changes during a study require review and documentation before taking effect.
Common Mistake
Assuming IRB approval covers HIPAA compliance. IRB approval addresses human subjects protection under the Common Rule. HIPAA compliance is a separate determination made by the covered entity through its privacy officer, in coordination with the IRB but not replaced by it.
Pro Tip
Create a HIPAA pathway checklist for every study start-up package. It takes minutes and creates the record an OCR audit will look for first.
2
Structure the Research Authorisation to Include All Eight Required Elements
Why It Matters
A defective authorisation is not a minor paperwork problem. Under the Privacy Rule, using PHI under a defective authorisation is a violation of the same weight as having no authorisation at all. Research teams that collect authorisations without verifying they contain all required elements are building their study on a compliance risk that may not surface until an audit or a subject complaint.
What To Do
Every research authorisation must include: a description of PHI to be used or disclosed, names or classes of persons authorised to disclose and receive, the purpose of each use or disclosure, an expiration date or event, the right to revoke, a conditioning statement, and the potential for re-disclosure. Review your template against this list annually.
Common Mistake
Using a generic institutional consent form that was designed for treatment purposes and adding a research section to the bottom. Treatment-purpose authorisations and research-purpose authorisations have different required elements. A combined form must satisfy all requirements for both, which is a drafting task that should involve your privacy officer, not just the research team.
3
Understand the Three Criteria an IRB Must Find Before Granting a Waiver

A waiver of authorisation allows a covered entity to use or disclose PHI for research without obtaining individual authorisation, but only when an IRB or Privacy Board finds that all three required criteria are met. Research teams often request waivers without fully understanding what the IRB is being asked to determine, which leads to incomplete waiver applications and delayed approvals.

The Three Criteria for a Full Waiver of Authorisation (45 CFR 164.512(i))
1. The research involves no more than minimal risk to privacy of the individuals whose PHI will be used or disclosed.
2. The research could not practicably be conducted without the waiver, meaning it would be impractical or impossible to obtain individual authorisation from the subjects whose records will be accessed.
3. The research could not practicably be conducted without access to and use of the PHI. This is a separate finding from criterion 2: the research questions must genuinely require the identifiable data.

Retrospective chart reviews, large historical database studies, and feasibility studies where contacting subjects is not possible are the most common waiver-eligible research types.

4
Apply the Minimum Necessary Standard to Every PHI Request and Disclosure
Why It Matters
The minimum necessary standard requires limiting PHI to what is reasonably necessary to accomplish the purpose. In research, this means data fields in extracts, records accessed in chart reviews, and information shared with sponsors should be limited to what the study protocol actually requires.
What To Do
Before requesting a data pull, review the protocol and specify exactly which data elements are needed. Request only those. Fields that might be useful but are not required by the protocol should not be in the extraction. Document the determination in the study file.
Common Mistake
Requesting full electronic health records when the protocol only needs specific data elements. Pulling entire charts when targeted data satisfies the protocol violates the minimum necessary standard even with a valid waiver. The access pathway does not override the minimum necessary obligation.
Pro Tip
Write a one-paragraph data minimisation rationale at study start-up listing which elements were requested, why each is necessary, and which were excluded. This document supports IRB submissions and OCR audit readiness.
5
Use a Limited Data Set with a Data Use Agreement When Full Anonymisation Is Not Feasible

A limited data set retains certain geographic and date elements but strips the 16 direct identifiers required under Safe Harbor. It can be used for research with a data use agreement (DUA) rather than individual authorisation or a waiver.

Limited Data Set: What Stays
Must Be Removed
Dates (admission, discharge, service, birth, death)
Names, postal address (except state and 3-digit zip)
Geographic subdivisions smaller than a state
Phone and fax numbers, email, SSN, MRN, plan numbers
Ages and other demographic data not listed as direct identifiers
Certificate/license numbers, device identifiers, URLs, IP addresses, biometrics, full-face photos

The DUA must require the recipient to limit use to specified purposes, apply appropriate safeguards, and report any unprovided disclosures. Review the obligations it places on the recipient before it is signed.

6
Treat De-Identification as a Formal Process with Documented Verification
Why It Matters
De-identified data falls outside HIPAA’s scope, making it useful for data sharing and publications. But de-identification has a specific legal meaning. Removing a name and replacing it with a study ID does not satisfy either the Safe Harbor or Expert Determination method. A data set that does not meet the requirements is still PHI regardless of how it has been labelled.
What To Do
Use the Safe Harbor method (remove all 18 specified identifiers and have no actual knowledge that the remaining information could be used to identify an individual) or the Expert Determination method (a qualified statistician applies generally accepted principles to determine and document that the risk of identification is very small). Keep the de-identification verification document with the study records.
Common Mistake
Calling a data set de-identified after removing names and social security numbers while retaining dates of service, geographic detail, and rare diagnosis codes. In small populations, rare conditions combined with date and location information can be re-identifying even without direct identifiers. The Safe Harbor method requires removal of all 18 specified categories, not just the most obvious ones.
7
Coordinate HIPAA Authorisation and Informed Consent Into a Single Coherent Conversation
Why It Matters
Subjects typically sign both an informed consent form and a HIPAA research authorisation. These are often presented separately, creating confusion. The Privacy Rule permits combining them into a single document, but the combined form must satisfy all requirements for both.
What To Do
If your institution uses a combined form, train coordinators to walk subjects through both the consent and authorisation sections distinctly. If using separate documents, present the authorisation alongside the consent, not mailed separately after the visit.
Common Mistake
Having subjects sign the HIPAA authorisation at a different time or location from the informed consent, without the benefit of being able to ask questions in context. Authorisations signed remotely without an explanation session produce lower-quality consent and create a record that looks like the HIPAA component was treated as a checkbox rather than a genuine disclosure to the subject.
Pro Tip
Script a brief plain-language explanation of the HIPAA authorisation section for coordinators to use during consent discussions. Something as simple as two sentences explaining what PHI will be shared and with whom reduces subject confusion and supports informed decision-making in a way that a form signature alone does not.
8
Define Your Data Retention and Destruction Schedule Before the Study Opens

HIPAA does not specify a research records retention period, but FDA regulations require records for regulated clinical investigations to be retained for at least two years after an NDA or BLA is approved or closed. State laws and sponsor agreements often extend that further. Research PHI without a destruction schedule is an ongoing liability.

Before the Study Opens
Identify the applicable retention requirement and document it in the start-up checklist. Schedule the destruction date in a system that survives staff turnover.
When the Study Closes
Archive or transfer research PHI per institutional procedures. Confirm electronic files, paper records, and backups are covered by the same plan. PHI destruction must render it unreadable and unrecoverable.
9
Know the Breach Notification Timeline and Who Is Responsible for Reporting
Why It Matters
An impermissible use or disclosure of research PHI may trigger HIPAA’s Breach Notification Rule. Covered entities must notify affected individuals within 60 days of discovery. Breaches affecting 500 or more individuals in a state require notification to HHS and prominent media within the same window.
What To Do
If you discover or suspect a breach of research PHI, report it to your institution’s privacy officer immediately. Do not attempt to assess whether the incident meets the definition of a breach on your own. The privacy officer will conduct the risk assessment required under the rule to determine whether notification is required. Your job is to report promptly and preserve evidence. Delay in reporting a suspected breach compounds the compliance problem significantly.
Common Mistake
Deciding independently that an incident was not a breach. Research coordinators cannot perform the four-factor risk assessment required by the rule. Undeclared breaches discovered in audits carry significantly heavier consequences than self-reported ones.
10
Document Every HIPAA Compliance Decision in the Research Regulatory Binder
Why It Matters
An OCR investigation starts with documentation. Investigators look for the pathway determination, waiver or authorisation, minimum necessary rationale, DUA, and breach assessment. Teams that made correct decisions but kept no records cannot demonstrate compliance after the fact.
What To Do
Maintain a HIPAA section in every study’s regulatory binder. Include: the pathway determination document, copies of all executed authorisations, the waiver approval documentation from the IRB, the minimum necessary rationale, any DUAs, correspondence with the privacy officer, and any incident reports or breach assessments. These records should be retained for the same period as the rest of the study records.
Common Mistake
Relying on the IRB’s records as a substitute for study-level HIPAA documentation. The IRB retains waiver approval records; the covered entity’s research office must separately demonstrate it complied with the waiver conditions throughout the study.

Frequently Asked Questions

Does HIPAA apply to all clinical research?
HIPAA applies when a covered entity or its business associates conducts or supports research, and when covered entities use PHI from their own patient populations. Research using properly de-identified data, or conducted entirely outside covered entities, falls outside HIPAA’s scope. Common Rule and IRB requirements may still apply regardless of HIPAA applicability.

Can a subject revoke their research authorisation after enrolling?
Yes, at any time in writing. After receipt, the covered entity may not use or disclose that individual’s PHI for research, with two exceptions: prior uses or disclosures already made, and those necessary to maintain research integrity (such as accounting for a withdrawal in the analysis). Revocation does not require destruction of PHI already collected.

What is the difference between a full waiver and an alteration of authorisation?
A full waiver allows use of PHI with no authorisation from subjects. An alteration allows modification of the required authorisation content (for example, omitting certain elements) rather than eliminating it entirely. Both require IRB or Privacy Board findings. An alteration is appropriate when some authorisation is obtainable but the standard form is impracticable in the research context.

Government and Regulatory Sources

Related VelSafe Articles

Applying These Tips in Your Research Program

The ten tips above address where research teams most commonly run into HIPAA problems: pathway determination, authorisation quality, minimum necessary, de-identification, and documentation. Find more healthcare compliance resources at velsafe.com.

Tags: No tags

Add a Comment

Your email address will not be published. Required fields are marked *