The purpose of this guidance is to provide general considerations for managing data security in human subjects research reviewed and approved by the Charles River Campus IRB.

Data Security Requirements

University Data is information generated by, owned by, or otherwise in the possession of Boston University that is related to the University’s activities, including research data. University Research data are subject to BU’s Data Classification Policy. As part of the University’s Data Classification Policy, data are categorized as Public, Internal, Confidential Use or Restricted Use with varying standards for protection that must be applied.

Researcher Responsibilities

  • Researchers who collect or utilize research data are responsible for accessing, storing, transferring and processing data on systems that have appropriate security controls for the class of data being used.
  • Researchers should itemize the kinds of data being collected and/or utilized as part of their research and determine what level of security is needed for their data.
  • Researchers should consult with IS&T and/or their local IT support groups to determine the best way to access, store, and use their data, particularly for data categorized as confidential or restricted use.

Examples of Research Data and Corresponding BU Data Classification

  • While most research data at BU are not subject to the HIPAA Privacy Rule, the HIPAA de-identification standard (removal of 18 data elements – e.g. email addresses, phone numbers, birth dates, zip codes, etc.) is still the gold standard. When data are deidentified in in the manner of the HIPAA Privacy Rule, there are no specific requirements for platform-use at BU, as the data are categorized as Public.
  • Similarly under the HIPAA Privacy Rule are data that are considered Limited Data Sets, meaning, they contain protected health information that excludes direct identifiers, effectively anonymizing data by limiting the elements to dates, cities and zip codes. When BU data are anonymized in the manner of the HIPAA Limited Data Set standard, the BU Shared Computing Cluster, BU Office 365 applications, BU REDCap or Qualtrics, BU Network Drives (NAS1), BU Google apps and others may be used, as these data are categorized as Confidential. NOTE: BU Google apps cannot be used for Limited Data Sets under HIPAA, as the data are typically provided by HIPAA Covered Entities, such as hospitals, health clinics, health insurers, the MA Department of Public Health, etc. Limited Data Sets from HIPAA Covered Entities require the execution of data use agreements (DUAs). For more information on DUAs, please contact BU’s Office of Industry Engagement.
  • The research data includes some personally identifiable information such as email addresses, phone numbers, facial images in pictures/videos (even if there is no name associated with the image), etc. In this case, BU Restricted Use network drive (nas-RU1 or BUMC Y Drive); BU Office365 apps, such as SharePoint, OneDrive, Teams; BU REDCap or Qualtrics and others may be used, as this data is categorized as Restricted Use.

Considerations for IRB Applications

As part of the IRB’s role in protecting the rights and welfare of human subjects, researchers must identify which electronic platforms, data transfer methods, data/document storage plans etc. are being proposed in the research. This information can be documented in the Confidentiality of Data section of the IRB application. BU’s InfoSec has provided sample language that can be used in the Confidentiality of Data section of the IRB application.

Researchers are encouraged to consult with IS&T on the use of third-party data collection, storage or analysis applications proposed for their research. Providing the IRB with correspondence with BU IS&T verifying the appropriateness of novel or third-party applications can facilitate the IRB’s review of the Confidentiality of Data plan.

FAQs answered by BU’s Information Security

Data Storage & Security Questions

  1. I have completed my research study and need to save the data for 7 years. How do I do this?

The purpose of the 7-year retention requirement for research data is both to (1) comply with a federal requirement and (2) enable the University to respond to litigation/legal/subpoena requests. As such, the data should be maintained at BU.  BU’s IS&T offers storage for archiving Confidential and Restricted Use data. Please refer to their website here, for more information.

  1. I want to store my data on a password protected computer that will be stored in a locked office, but someone mentioned BU requires encryption as well. Is that true?

Yes, the BU Data Protection Standards require encryption for all non-Public data, including Confidential and Restricted Use data, even when a computer or device is stored in a locked office.

Data Transfer & Communications Questions

  1. As part of my field research, I am recording interviews using my cell phone and uploading to the BU networked shared drive. However, my collaborators do not have access to the BU networked shared drive and wish to text me audio recordings of interviews they have collected. Is there a better way to handle this?

Consult with IS&T for the latest recommendations, however, most recently they have recommended researchers use BU Office365 OneDrive folders for data transfer. The OneDrive folder can then be shared with collaborators using their professional email account (personal addresses should not be used). Collaborators can download the OneDrive app to their phones.

  1. Can I use Whatsapp, Gmail Chat, or iMessage to send ongoing communications with study participants?

WhatsApp is a Facebook product and while the messages are sent with encryption, Facebook has access to information on phones that use their products. Companies such as Google and Apple use and share information about their users. We recommend the following BU options that provide more adequate confidentiality for research data:

    • BU Microsoft Teams can be used for chatting/texting or calling (email address) via the Teams app. Teams is similar to Zoom but has HIPAA compliant recording of video and/or audio that can be stored and shared on Microsoft Stream.
    • BU REDCap can be used for sending participant information (such as videos) as well as typical research needs (e.g., consent forms, surveys, reminders, etc.) via email or secure text (Twilio).
    • BU Qualtrics has similar functionality to BU REDCap but does not have as many features.
    • BU Cisco phones or Cisco Jabber – an application that connects to BU Cisco phone when out of the office – are great options for traditional phone communications

While apps such as Whatsapp may still be necessary for a research project (e.g., working in remote or limited resource settings) the consent form should contain clear information about the company’s access to and potential use of information on the participant’s phone, regardless of how secure the researcher may store those data once collected.

Consent Participants Remotely

I would like to use Google Forms to consent participants, is that ok?

If you are not conducting health-related research, Google Forms may be OK to use. However, if you are conducting health-related research we suggest using a BU Microsoft app, such as Forms.  Forms can be hosted on a BU website and only the administrators can see the responses. Other Restricted Use/HIPAA compliant options include collecting participant consent using BU Qualtrics or BU REDCap.  Please note, BU’s REDCap can be used for FDA (21 C.F.R. Part 11) compliance, but additional requirements need to be implemented. Send an email to rchelp@bu.edu to start the process.

Additional Resources

  • BU IS&T offers a wide range of services to ensure the security of Boston University’s information and technology resources. Researchers are encouraged to consult with IS&T
  • BUMC Data Guidance Page provides a list of BU-reviewed and cleared services based on Data Classification
  • Data Storage Options offered by IS&T
  • BU HIPAA Policy outlines how covered components must protect HIPAA data
  • Email best practices security reminder