Which HIPAA requirements most commonly catch sponsors out?
Understanding when and how HIPAA applies is only part of the picture. Below, we explore three areas most likely to create operational and compliance challenges during a clinical trial:
1. HIPAA authorisation is not informed consent
Clinical trial sponsors often assume that once a participant has signed an Informed ConsentAn unambiguous, informed and freely given indication by an individual agreeing to their personal data being processed. Form (ICF), the necessary privacy requirements have also been addressed. In reality, informed consent and HIPAA authorisation serve different legal purposes.
- Informed consent explains the purpose of the study, the procedures involved, any potential risks, and the participant’s rights
- HIPAA authorisation permits the specified uses and disclosures of the participant’s PHI for research purposes
Whilst both instruments are often combined into a single document, each must independently satisfy its own legal requirements.
Sponsors should therefore ensure that participant documentation has been prepared appropriately and that the legal basis for collecting, using, and disclosing PHI has been clearly established before data begins to flow.
2. Coded data may still be PHI
A common misconception is that replacing a participant’s name with a study subject identification number automatically removes the data from HIPAA’s scope. In reality, whether coded data remains PHI depends on how it has been coded and who can re-identify the participant.
Where the recipient can link the data back to an individual, or has access to the re-identification key, the information will generally continue to be treated as PHI. Simply pseudonymising data does not, on its own, remove HIPAA obligations.
Data ceases to be PHI only when HIPAA’s de-identification standard has been met through one of two recognised methods:
- HIPAA Safe Harbor method: The 18 specified identifiers are removed, and the Covered Entity has no actual knowledge that the remaining information could be used, alone or with other information, to re-identify the individual
- Expert Determination method: A qualified expert determines and documents that the risk of re-identifying an individual is very small
Importantly, HIPAA also recognises that key-coded data may be considered de-identified in the hands of a recipient, such as a sponsor, even where the Covered Entity retains the re-identification key. This applies only where the code is not derived from the individual’s identifiers and the key is not disclosed to the recipient.
It’s also important to distinguish Limited Data Sets from de-identified data. Whilst Limited Data Sets have certain direct identifiers removed, they may still contain information such as dates and limited geographic data. They can be disclosed for research purposes without participant authorisation, provided the recipient enters into a Data Use Agreement (DUA).
In practice, sponsors should not assume that ‘coded’ always means ‘out of scope’. Understanding whether a dataset remains PHI, qualifies as a Limited Data Set, or has been properly de-identified is essential for determining which HIPAA requirements continue to apply.
3. PHI rarely flows directly from site to sponsor
Modern clinical trials rarely involve information moving directly between the investigator site and the sponsor. Instead, PHI may pass through Clinical Research Organisations (CROs), laboratories, central imaging providers, cloud platforms, electronic trial systems, safety vendors, and other third parties before reaching its final destination.
Without a clear understanding of these data flows, organisations can struggle to determine who is responsible for protecting PHI at each stage of the processA series of actions or steps taken in order to achieve a particular end..
Mapping PHI throughout the trial helps sponsors identify which organisations receive identifiable information, the legal basis for each disclosure, and whether contracts appropriately allocate responsibilities for security, retentionIn data protection terms, a defined period of time for which information assets are to be kept., breach reporting, and participant rights.
This exercise can also help identify where identifiable data could be minimised or replaced with coded or de-identified information, reducing unnecessary privacy risk.