Data Security in Human Subjects Research

Last updated on February 24, 2022 7 min read Working with Human Subjects - Data Security in Human Subjects Research

General guidance for managing data security in human subjects research reviewed and approved by the Charles River Campus IRB.

Data Security Requirements

University Data is information generated by, owned by, or otherwise in the possession of Boston University that is related to the University’s activities, including research data. University Research data are subject to BU’s Data Protection Standards. Under the University’s Data Classification Policy, data are categorized as Public, Internal, Confidential or Restricted Use with varying standards for protection that must be applied.

Researcher Responsibilities

  • Researchers who collect or utilize research data are responsible for accessing, storing, transferring and processing data on systems that have appropriate security controls for the class of data being used.
  • Researchers should itemize the kinds of data being collected and/or utilized as part of their research and determine what level of security is needed for their data.
  • Researchers should consult with IS&T and/or their local IT support groups to determine the best way to access, store, and use their data, particularly for data categorized as confidential or restricted use.

Examples of Research Data and Corresponding BU Data Classification

  • While most research data at BU are not subject to the HIPAA Privacy Rule, the HIPAA de-identification standard (removal of 18 data elements – e.g. email addresses, phone numbers, birth dates, zip codes, etc.) is still the gold standard. When data are de-identified in in the manner of the HIPAA Privacy Rule, there are no specific requirements for platform-use at BU, as the data are categorized as Public.
  • Similarly under the HIPAA Privacy Rule are data that are considered Limited Data Sets, meaning, they contain protected health information* that excludes direct identifiers, effectively anonymizing data by limiting the elements to dates, cities and zip codes. When BU data are anonymized in the manner of the HIPAA Limited Data Set standard, the BU Shared Computing Cluster, BU Office 365 applications, BU REDCap or Qualtrics, BU Network Drives (NAS1), BU Google apps and others may be used, as these data are categorized as Confidential. NOTE: BU Google apps cannot be used for Limited Data Sets under HIPAA, as the data are typically provided by HIPAA Covered Entities, such as hospitals, health clinics, health insurers, the MA Department of Public Health, etc. Limited Data Sets from HIPAA Covered Entities require the execution of data use agreements (DUAs). For more information on DUAs, please contact BU’s Office of Industry Engagement.
  • The research is health* related and includes some personally identifiable information such as email addresses, phone numbers, facial images in pictures/videos (even if there is no name associated with the image), etc. In this case, BU Restricted Use network drive (nas-RU1 or BUMC Y Drive); BU Office365 apps, such as SharePoint, OneDrive, Teams; BU REDCap or Qualtrics and others may be used, as this data is categorized as Restricted Use. Note, however, that if the research is not health related (e.g., amount of texts sent/day) it is classified as Confidential even when identifiable information is included.

Considerations for IRB Applications

As part of the IRB’s role in protecting the rights and welfare of human subjects, researchers must identify which electronic platforms, data transfer methods, data/document storage plans etc. are being proposed in the research. This information can be documented in the Confidentiality of Data section of the IRB application. BU’s InfoSec has provided sample language that can be used in the Confidentiality of Data section of the IRB application.

Researchers are encouraged to consult with IS&T on the use of third-party data collection, storage or analysis applications proposed for their research. Providing the IRB with correspondence with BU IS&T verifying the appropriateness of novel or third-party applications can facilitate the IRB’s review of the Confidentiality of Data plan.


Answered by BU’s Information Security

Data Storage & Security Questions

I have completed my research study and need to save the data for 7 years. How do I do this?

The purpose of the 7-year retention requirement for research data is both to (1) comply with a federal requirement and (2) enable the University to respond to litigation/legal/subpoena requests. As such, the data should be maintained at BU.  BU’s IS&T offers storage for archiving Confidential and Restricted Use data. Please refer to their website here, for more information.

I want to store my data on a password protected computer that will be stored in a locked office, but someone mentioned BU requires encryption as well. Is that true?

Yes, the BU Data Protection Standards require encryption for all non-Public data, including Confidential and Restricted Use data, even when a computer or device is stored in a locked office.

Data Transfer & Communications Questions

As part of my field research, I am recording interviews using my cell phone and uploading to the BU networked shared drive. However, my collaborators do not have access to the BU networked shared drive and wish to text me audio recordings of interviews they have collected. Is there a better way to handle this?

  • Consult with IS&T for the latest recommendations, however, most recently they have recommended researchers use BU Office365 OneDrive folders for data transfer. The OneDrive folder can then be shared with collaborators using their professional email account (personal addresses should not be used).  Collaborators can download the OneDrive app to their phones.

What platforms can I use to share health-related* information?

  • To avoid study staff using their personal cell phones with research participants, BU has a number of recommended options: Study staff can use a BU desk phone, a BU cell phone, or extend a desk phone to a personal device using BU Cisco Webex:
  • BU Microsoft Teams can be used for chatting/texting or calling (email address) via the Teams app. Teams is similar to Zoom but has HIPAA compliant recording of video and/or audio that can be stored and shared on Microsoft Stream.
  • BU REDCap can be used for sending participant information (such as videos) as well as typical research needs (e.g., consent forms, surveys, reminders, etc.) via email or secure text (Twilio).
  • BU Qualtrics has similar functionality to BU REDCap but does not have as many features.

What platforms can I use to send appointment updates with no disclosure of health-related information?

  • Google Voice can be used in this instance since you are not planning to disclose health information over Google Voice. While BU HIPAA Components can never use Google Voice, non-HIPAA components may do so as long as they are not sharing or discussing health information. Communications around appointments would be subject to BU’s policies on Confidential data:
  • Whatsapp, Gmail Chat, or iMessage can be used for appointment setting or updating, but cannot be used to request or send health-related information. WhatsApp is a Meta product and while the messages are sent with encryption, Meta has access to information on phones that use their products. Companies such as Meta, Google, and Apple use and share information about their users. For this reason, a study should not require use of these apps unless the Consent outlines how data is collected and shared by the company with third party companies

I would like to use Google Forms to consent participants, is that ok?

  • If you are not conducting health-related* research, Google Forms may be OK to use. However, if you are conducting health-related research we suggest using a BU Microsoft app, such as Forms. Forms can be hosted on a BU website and only the administrators can see the responses. Other Restricted Use/HIPAA compliant options include collecting participant consent using BU Qualtrics or BU REDCap.  Please note, BU’s REDCap can be used for FDA (21 C.F.R. Part 11) compliance, but additional requirements need to be implemented. Send an email to to start the process.

Additional Resources

*Health-related information is very broad, including stress or anxiety related to school, but does not typically include social engagement, decision making, number of texts sent per day, or educational practices, strategies, or effectiveness.

Information For...

Back to Top