Storage
REDCap
UT Health San Antonio Storage Options (Server/Cloud)
Data Sharing / Data Use Agreement
Data Acquisition, Management, Sharing, & Ownership
What is a DUA? When do I need a DUA? Where is the DUA template form?
Accessing existing data (medical records, etc.)
[Not sure if this is needed]
HIPAA (waivers, authorizations, disclosures)
The HIPAA Privacy Rule, at 45 CFR parts 160 and 164, defines certain health information as protected health information (PHI) which a covered entity may only use or disclose (sharing) to others in certain circumstances and under certain conditions.
The Rule requires individuals to provide written authorization before the covered entity may use or disclose the individual’s health information for research purposes.
A covered entity may also use and disclose PHI if a waiver or alteration of the HIPAA authorization of is granted by the Institutional Review Board as long as the criteria for waiver or alteration is satisfied:
- The PHI use or disclosure involves no more than minimal risk to the privacy of individuals provided that there is an adequate plan to protect PHI from improper use and disclosure, there is an adequate plan to destroy identifiers at the earliest opportunity, and there are adequate written assurances in place that the PHI will not be reused or disclosed to any person or entity.
- The research could not practicably be carried out with the waiver or alteration.
- The research could not be practicably be conducted without access to and use of the PHI.
Submit the Form J - HIPAA Waiver of Authorization with your IRB submission to request access to identifiable health information without prior written permission from the subject. A Data Use Agreement may need to be considered.