Human Subjects Research and the HIPAA Privacy Rule
HIPAA applies to research uses of PHI as well as clinical uses. However, the application of HIPAA to research is more nuanced. The forms and guidance below will help researchers understand how to apply HIPAA regulations to their work.
Guidance
- Guidance for Study Teams with Members Inside and Outside the Health Care Component (HCC)
- Guidance for Researchers Outside the Health Care Component (HCC) Using Protected Health Information (PHI) (coming soon)
- Research Proposal Requirements
- Researcher FAQs
Forms
This is an accordion element with a series of buttons that open and close related content panels.
Accounting for Disclosures
Accounting for Disclosures Guidance: This document provides guidance on when and how researchers are required to account for disclosures of research participants’ PHI. The document includes a link to the REDCap Accounting Log researchers should use when accounting for disclosures.
Authorizations for Use or Disclosure of PHI in Research
Authorizations for Use or Disclosure of PHI in Research
Please note, these are templates only. As with your research consent form, your HIPAA authorization form will need to be tailored to fit the particular uses and disclosures of PHI in your study.
Certifications
- Certification for Activities Preparatory to Research: This certification must be signed prior to using PHI in the preparation of a research protocol.
- Certification for Research on the Protected Health Information of Decedents: This certification must be signed when the research, or a distinct part of the research, uses only the protected health information of decedents.
Database Forms and Tools
- Database Decision Tool: This tool is used to determine if a database that is used for research purposes must be registered with the UW-Madison HIPAA Privacy Officer.
- Database Registration and Preparatory to Research Certification for Database Custodian: This form is used to register a database with the UW-Madison Privacy Officer and, when applicable, for the database custodian to certify use of the database in preparation of a research protocol.
Data Use Agreement and Related Forms
Data Use Agreement: This agreement must be completed before receiving or disclosing a Limited Data Set (“LDS”).
- Data Transfer and Use Agreements: Use these forms to disclose or receive an LDS from an external entity.
- Internal Data Use Agreement for Use or Disclosure of a Limited Data Set: This internal data use agreement must be signed when a UW-Madison employee receives a limited data set from within the UW HCC or UW ACE.