New Recruitment Template in HawkIRB 

Common Workflow for Data Confidentiality 

Herky Hint: Section X. Privacy and Confidentiality 

Privacy and Confidentiality: Criteria for Approval 


New Recruitment Template in HawkIRB 

A new template for use in recruitment emails and letters has been added to HawkIRB and is also available on the HSO website. This updated template includes required and recommended informational elements.  

The main revision to the template is to inform the recipient that their contact information was obtained from the University of Iowa Health Care (UIHC) medical record database. This section is now required for studies utilizing the UIHC electronic medical record information for recruitment purposes. 

As with the prior template, bold and bracketed fields are instructions for adding study-specific information.  Modify the format to fit your recruitment method (letter, email, flyer, information sheet, etc.). The bold font should be removed prior to attaching it to the Attachments page of the HawkIRB application. 


Common Workflow for Data Confidentiality

In an effort to help researchers complete the HawkIRB application accurately and avoid unnecessary workflow, the processes as described in Section X in the application for confidentiality protections should be consistent with each other, and with what is described in the consent document.

For data confidentiality, researchers are encouraged to clearly describe: 

  • Who has access to data.
  • Whether the data is identifiable.
  • Where data are stored.
  • How long the data will be kept.
  • How data are protected.
  • Whether data are shared.

Examples of common workflow requests sent to researchers are included in the following:

Including procedures/electronic records in all pertinent areas 

If a researcher indicates in HawkIRB section VII.E.4 that they will be utilizing audiotapes, videotapes, or photographs, the appropriate information needs to be indicated in section X.4 and  VII.E.6 and addressed in the consent document. 

Screenshot of HawkIRB section seven - E - four

 

Screen shot of HawkIRB section seven - E - six.

 

Screen shot of HawkIRB section ten point four.
Data sharing

For data collected as indicated in section X.4 the response to X.5 and X.6 about data sharing must also be consistent in the consent document and section XII.1 as applicable.

Screen shot of HawkIRB sections ten point five and ten point six.

 

Screenshot of HawkIRB section twelve point one.

The description in Section X.6 should indicate whether the data that will be shared with collaborators will be identifiable, coded, or de-identified, and this information should be included in the consent document.

Additional Guidance
  • When preparing to submit a modification, it is helpful to review and create a printer friendly version of the currently approved form, and use the answers to answer the new versions of the questions in Sections VII, X and XII.
  • For multisite research where Iowa is the lead IRB with relying sites, the privacy/confidentiality sections must describe the privacy protections for the participants and the confidentiality protections for the data at all sites, not just at the UI. 

Herky Hint: Section X. Privacy and Confidentiality  

By Emily Shultz, CIP 

In the HawkIRB application, items X.1-9 address privacy and confidentiality. When completing the responses in section X., it is important to note the difference between privacy and confidentiality. Privacy protections refer to the methods researchers use to make sure participants cannot be seen or heard during the recruitment, enrollment, and consent processes, or while participating in study procedures. Confidentiality refers to the protections that researchers will use to ensure participant data is captured and maintained securely when it is collected and stored.  

Note: Recent updates to HawkIRB have resulted in alterations to questions and the types of responses indicated. Reviewing each question thoroughly prior to answering it will result in better consistency in the application and will reduce the need for revisions during IRB review. 

Privacy 

Section X.1 asks if the research team will implement measures to protect the privacy of the subjects during the recruitment, enrollment, and consent process to ensure subject privacy. 

Screenshot of HawkIRB ten point one.

If you will be collecting Social Security numbers (SSN) of subjects, indicate ‘yes’ on item X.2. 

Screenshot of HawkIRB section ten point two.

Why you may need to collect SSNs:

If you will be compensating subjects with a payment at or above $100 (or over $2,000 in a year) you would need to collect their SSN. (Note: For VA subjects, SSNs must be collected for any amount of payment.) In addition to selecting ‘yes’ for X.2, indicate the compensation plans in section VII.E 9-10 of the HawkIRB application. 

Reimbursing a subject for travel or per diem costs does not require the collection of SSNs. However, the research team would need to receive documentation of the mileage and/or per diem amounts to support the reimbursement. Information about reimbursement is provided in section VII.E.11 in HawkIRB. More information on reimbursement is available on the HSO website.

Screenshot of HawkIRB section ten point three.

If you select ‘yes’ in X.2, section X.3 will ask the intended use of the SSN. In item X.3, describe the intended uses for the SSN. The subject must consent to the collection of their SSN for any purpose other than compensation. The description in section X.3 should be consistent with section VII.D.6 and the consent document. Indicate the plan for how and when the SSN will be destroyed in accordance with UI policy. (Note: For VA research subjects the SSN is retained indefinitely). For additional information on the UI Research Subject Compensation Policy. 

Confidentiality

Section X.4 asks how the research team will manage subject data and biospecimens. (Note: Managing the risk of loss of confidentiality should be addressed in section VIII.2.)  The methods by which data will be collected (paper/hard copy records, electronic records, and biologic samples) must be selected. Check as many boxes as you need for each of the types of data storage (paper/electronic/biospecimens) that will be included in your study. From these selections, additional responses will be required.

Screenshot of HawkIRB section ten point four.

 

Screenshot of HawkIRB section ten point four.

If paper/hard copy records are selected, please indicate if only research members will have access, and/or whether the records will be stored in a locked location with only authorized access, and whether the data is identifiable, coded, or deidentified/anonymous.

Note: For all responses in Section X.4, it is important to use correct terminology to describe the data:

  • Identified Data – Subject identifiers are stored in the data set
  • Coded Data – There is a link between the ID code and the identifiable information
  • De-identified Data – Subject identifiers were initially collected and have been removed. This could include breaking the link between the code and the identifiers so they can’t be re-identified.
  • Anonymous Data – No identifying information was ever collected from or about subjects

If electronic records are indicated, the options described above will need to be similarly  completed. Additionally, the method/location of electronic storage will also need to be provided.

Screenshot of HawkIRB section ten point four.

If collecting biologic samples, please indicate if only research members will have access, and/or whether the records will be stored in a locked location with only authorized access. Then also describe the location for the storage of the specimens. 

Screenshote of HawkIRB section ten point four.

Note: For VA research subjects, the consent form must describe if data is stored anywhere outside VA premises. Any biological samples stored outside the VA must have approval from the VA Associate Chief of Staff (ACOS). 

In section X.5 Indicate ‘no’ if the data will not be shared outside the UI.

Indicate ‘yes’ if the data/specimens will be shared and describe the details in section X.6. This information should also be included in the consent document. 

Screenshot of HawkIRB sections ten point five and ten point six.
Certificate of Confidentiality

If your study meets the NIH criteria for a Certificate of Confidentiality (CoC) or if you will be applying for one, indicate ‘yes’ in section X.8. If your study meets the NIH criteria for a Certificate of Confidentiality (CoC) or if you will be applying for one, indicate yes in section X.8. If the UI is the coordinating center and IRB of record for some or all sites, describe in section X.9. All relying sites will be required to sign and complete the CoC assurance to acknowledge the requirements associated with the CoC.  Attach these assurance document(s) from the relying site(s) in the attachment category immediately following X.9. (The  template CoC assurance letter is available as a drop down option with this attachment category.)

A Certificate of Confidentiality is only allowed for research projects that are:

  • Collecting personally identifiable, sensitive information
  • Approved by an Institutional Review Board (IRB) operating under a Federalwide assurance (FWA) issued by the DHHS Office of Human Research Protections (OHRP) or with the approval of the FDA
  • On a topic that is within the HHS health related research mission
  • Federal funding is not required but issuance is at the discretion of the issuing agency
  • Storing research data in the United States
  • Allowable under federal regulations
Screenshot of HawkIRB sections ten point eight and ten point nine.

The CoC should also be indicated in section VIII.2 as a method of minimizing risk to subjects. 

Questions about this topic? Email the HSO Education and Outreach team or come to Office Hours to speak directly to a member of the HSO team.   

Have an idea for a future Herky Hint for HawkIRB? Let us know!  


Privacy and Confidentiality: Criteria for Approval

By Emily Shultz, CIP

Privacy and confidentiality are two unique concepts that are required for human research participant protection. While privacy is specific to the research participant, confidentiality is specific to the participant’s identifiable data and/or specimens. 

Privacy is the ability of an individual to function without intrusion and includes the ability to control what personal information is shared with others. Privacy protections in research refer to the methods used to protect subject privacy during the conduct of the study and the collection of data.

Confidentiality is the right of the individual to have their information, once it is shared with others, held securely, and kept secret unless the individual consents to disclosure. Confidentiality protections in research include measures taken to protect data during and after collection.

The exercise of privacy and confidentiality falls within the ethical concept of beneficence from the Belmont Report which focuses on ‘maximizing possible benefits and minimizing potential harms.’ 

Criteria for Approval

Federal regulations overseeing the criteria for approval of human subjects research 45 CFR 46.111(a)(7) and 21 CFR 56.111(a)(7) require that the research plan has “…adequate provisions to protect the privacy of subjects and to maintain the confidentiality of data.” 

Confidentiality protections include the researcher’s data security plan and their data sharing plan (if applicable) to protect collected data. The researcher will need to indicate in the HawkIRB application, and in the consent document (if applicable) whether data/specimens will be identifiable, coded, or de-identified. 

Confidentiality Requirement for Informed Consent

Federal regulations overseeing the general requirements for informed consent at 45 CFR 116(b)(5)  and 21 CFR 50.25 state that informed consent must include “a statement describing the extent, if any, to which confidentiality of records identifying the subject will be maintained.” The consent document will need to describe the methods that will be used to ensure the confidentiality of the participant’s data.

Types of Risk

In considering what harms could be involved with the loss of participant privacy and/or confidentiality, we can look elsewhere in the regulations where types of risks are discussed, including placing subjects “… at risk of criminal or civil liability or be damaging to the subjects' financial standing, employability, educational advancement, or reputation …” 45 CFR 46.104(d)(2)(ii)

Risks from Loss of Privacy

When considering how these types of risk could apply to a participant’s privacy, we can imagine a scenario in an interventional study of people who inject illegal drugs. For these individuals, it is important to conduct the consent process in a place where no one could see or overhear the consent being discussed. If it were possible for someone to overhear them confirming that they meet the study criteria it might be that the person overhearing could tell the participant’s employer, and it could result the person losing their job which could: 

  • Affect financial standing
  • Damage their reputation
  • Put them at risk for criminal liability
Risks Due to Loss of Confidentiality

Risks from loss of confidentiality can occur at almost any point during or after data collection. For example, loss of confidentiality could occur if a laptop containing participant data for the same drug use intervention was stolen. Or if data were transferred electronically to a colleague on a system that did not use encryption, or if paper consent documents were left in an unlocked office, the information about participants could put them at risk of harm due to 

  • criminal liability, and loss of
    • financial standing,
    • employability,
    • educational advancement, and/or
    • reputation.
Managing Risks in Research Procedures

Efforts to protect the subject’s rights to privacy could include protections such as the following:

• Providing a private space for discussing study procedures and obtaining consent 

• Telling participants at the beginning of surveys or interviews that they can choose not to answer any questions that make them feel uncomfortable

• Collecting only the amount and type of information necessary to answer the research question 

• Not allowing tagging on social media recruitment posts 

• Sending non-specific emails and/or leaving only general messages on voicemail (not saying anything specific about the participant or the research) 

• Using blind copy (BCC) for group emails

Plans to protect the confidentiality of participant data and/or specimens might include:

• Limiting who has access to identifiable data and specimens

• Retaining identifiable data or specimens on a secured server or in a locked lab

• Not linking identifiers with data or specimens, or removing identifiers from data or specimens as soon as possible, or 

• Using encrypted email for sending data to a colleague

• Certificates of Confidentiality

Confidentiality protections begin at data collection and are ongoing as long as the identifiable data and/or specimens exist.

Certificate of Confidentiality

Certificate of Confidentiality (CoC) is an additional layer of protection for information, documents, and/or biospecimens that contain identifiable, sensitive information related to a participant’s involvement in research. The National Institutes of Health (NIH) and other federal agencies issue certificates to provide additional confidentiality protections beyond the standard protections for human subjects research.

The National Institutes of Health (NIH) automatically issues a CoC for studies that the agency funds to provide additional protections for participants who are participating in a research project that collects identifiable, sensitive data. However, the IRB is tasked with ensuring the CoC criteria are appropriately applied to the research. Once a CoC is applied, the protections for the research data last in perpetuity.

The study team and the institution have specific obligations outlined in the Institutional Assurance Statement for ensuring research subject’s sensitive data is only released under limited scenarios.  The responsibilities associated with the CoC must be applied by all collaborators affiliated with the project if the research is a cooperative research project. In a multisite collaborative project utilizing a single IRB of record, the primary PI and lead IRB are responsible for ensuring all collaborating sites are aware of, and apply, the terms of the CoC. 

Even if the NIH (or other HHS agency) does not fund the study, when reviewing research, the IRB may advise the researcher to apply to the NIH for a Certificate of Confidentiality based on the sensitivity of the data being collected.  For more information on CoCs, see the Certificates of Confidentiality FAQs. 

For more information on protecting confidentiality through data security see the Data Security Guidance educational tool.

Questions about this topic? You can email the HSO Education and Outreach team or come to Office Hours to speak directly to a member of the HSO team.