18.1 Data Privacy and Confidentiality

Key Takeaways

  • The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule establishes national standards to protect individuals' medical records and other personal health information (PHI).
  • De-identification of PHI can be achieved through either the Safe Harbor method (removing 18 specific identifiers) or the Expert Determination method.
  • The General Data Protection Regulation (GDPR) applies to clinical trials involving EU citizens and introduces strict requirements like the 'right to be forgotten' and explicit consent for data processing.
  • Clinical Research Coordinators (CRCs) must ensure that informed consent documents clearly state who will have access to the subject's data and how it will be protected.
Last updated: July 2026

Understanding Data Privacy in Clinical Trials

Protecting the privacy and confidentiality of clinical trial participants is a fundamental ethical obligation and a stringent regulatory requirement. When subjects volunteer for clinical research, they entrust investigators and research staff with highly sensitive personal and medical information. The Clinical Research Coordinator (CRC) is often the primary gatekeeper of this information, responsible for implementing privacy protocols on a day-to-day basis.

HIPAA and Protected Health Information (PHI)

In the United States, the Health Insurance Portability and Accountability Act (HIPAA) of 1996, specifically the Privacy Rule, governs how covered entities handle Protected Health Information (PHI). PHI encompasses any information in a medical record that can be used to identify an individual and that was created, used, or disclosed in the course of providing a health care service, such as diagnosis or treatment.

The 18 Identifiers

Under the HIPAA Safe Harbor method, health information is considered de-identified (and thus no longer subject to HIPAA rules) if 18 specific identifiers are removed, and there is no actual knowledge that the remaining information could identify the subject. These identifiers include:

CategoryExamples of Identifiers
NamesFull name, maiden name
Geographic DataSubdivisions smaller than a state (street address, city, county, zip code)
DatesAll elements of dates directly related to an individual (birth date, admission date, discharge date, date of death) except year
Contact InfoTelephone numbers, fax numbers, email addresses
Identifying NumbersSocial Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers
Digital/BiometricWeb Universal Resource Locators (URLs), Internet Protocol (IP) address numbers, biometric identifiers (fingerprints, voice prints), full-face photographic images
OtherAny other unique identifying number, characteristic, or code

Note: The subject's study identification number or randomization code is NOT one of the 18 identifiers, provided the key to decipher the code is kept strictly secure and is not disclosed.

Expert Determination Method

While the Safe Harbor method is straightforward, the alternative is the Expert Determination method. A person with appropriate knowledge of and experience with generally accepted statistical and scientific principles for rendering information not individually identifiable applies such principles to determine that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual. The expert must document the methods and results of the analysis that justify such determination. In specialized clinical trials, particularly those researching rare diseases where removing 18 identifiers might still leave a patient easily identifiable by their unique clinical presentation, expert determination is critical.

The CRC's Role in Confidentiality

CRCs must embed privacy practices into every aspect of trial execution. This begins with the Informed Consent process. The Informed Consent Form (ICF) must contain a specific HIPAA authorization (often integrated into the ICF or provided as a separate document). The authorization must clearly explain:

  • What PHI will be collected.
  • Who will have access to the PHI (e.g., the sponsor, the FDA, the Institutional Review Board, Contract Research Organizations).
  • How the data will be used.
  • The expiration date or event for the authorization (or state "no expiration").

Practical Privacy Measures

In the clinic, CRCs should implement several practical measures to safeguard data:

  • Physical Security: Locking file cabinets containing source documents, ensuring screens displaying electronic health records (EHR) are not visible to unauthorized individuals, and adopting a "clean desk" policy.
  • Electronic Security: Using encrypted emails when transmitting sensitive data, never sharing passwords for Electronic Data Capture (EDC) systems, and logging off computers when walking away.
  • Communication: Avoiding discussing subjects by name in public areas like elevators or cafeterias. Using only the subject's initials and screening/randomization number when communicating with the sponsor.

GDPR and Global Clinical Trials

For trials conducted globally, or those involving citizens of the European Union, the General Data Protection Regulation (GDPR) applies. GDPR is generally more stringent than HIPAA. Key concepts include:

  • Data Minimization: Only data absolutely necessary for the trial should be collected.
  • Explicit Consent: Subjects must actively opt-in to data processing; bundled consents are often invalid.
  • Right to Erasure (Right to be Forgotten): Subjects can request their data be deleted. However, in clinical trials, this right is often limited by overriding public interest in scientific research or regulatory requirements to maintain trial integrity.
  • Data Protection Officer (DPO): Organizations processing large scale sensitive health data must appoint a DPO.

If a US-based CRC is working on a trial with European subjects, they must be aware of cross-border data transfer rules and ensure sponsor-provided systems comply with GDPR mechanisms like Standard Contractual Clauses.

Secondary Use of Clinical Data

Increasingly, sponsors want to retain trial data for future, unspecified research (secondary use). Under HIPAA, future research requires either a new authorization, a waiver of authorization from an IRB/Privacy Board, or the data must be completely de-identified. CRCs must be careful during the consenting process to clearly delineate what data is being used for the primary study and what, if any, optional consent is being requested for future use. Patients have the right to refuse secondary use without affecting their participation in the primary trial.

Handling Data Breaches

A data breach occurs when unsecured PHI is accessed, acquired, used, or disclosed without authorization. Examples include losing a laptop containing unencrypted subject lists or accidentally emailing a subject's lab results to the wrong person.

When a breach is suspected, the CRC must immediately notify the Principal Investigator and the institution's Privacy Officer or compliance department. The institution must then assess the breach to determine if it compromises the security or privacy of the PHI, which dictates the timeline and method for notifying the affected subjects, the Department of Health and Human Services (HHS), and potentially the media.

Test Your Knowledge

Which of the following is NOT one of the 18 HIPAA identifiers that must be removed for the Safe Harbor de-identification method?

A
B
C
D
Test Your Knowledge

Under the General Data Protection Regulation (GDPR), which concept dictates that only the absolute minimum amount of personal data necessary for the trial should be collected?

A
B
C
D
Test Your Knowledge

If a CRC accidentally leaves a printed roster of trial subjects with their medical record numbers in the public cafeteria, what is the immediate first step they should take?

A
B
C
D