18.1 Data Privacy and Confidentiality
Key Takeaways
- The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule establishes national standards to protect individuals' medical records and other personal health information (PHI).
- De-identification of PHI can be achieved through either the Safe Harbor method (removing 18 specific identifiers) or the Expert Determination method.
- The General Data Protection Regulation (GDPR) applies to clinical trials involving EU citizens and introduces strict requirements like the 'right to be forgotten' and explicit consent for data processing.
- Clinical Research Coordinators (CRCs) must ensure that informed consent documents clearly state who will have access to the subject's data and how it will be protected.
Understanding Data Privacy in Clinical Trials
Protecting the privacy and confidentiality of clinical trial participants is a fundamental ethical obligation and a stringent regulatory requirement. When subjects volunteer for clinical research, they entrust investigators and research staff with highly sensitive personal and medical information. The Clinical Research Coordinator (CRC) is often the primary gatekeeper of this information, responsible for implementing privacy protocols on a day-to-day basis.
HIPAA and Protected Health Information (PHI)
In the United States, the Health Insurance Portability and Accountability Act (HIPAA) of 1996, specifically the Privacy Rule, governs how covered entities handle Protected Health Information (PHI). PHI encompasses any information in a medical record that can be used to identify an individual and that was created, used, or disclosed in the course of providing a health care service, such as diagnosis or treatment.
The 18 Identifiers
Under the HIPAA Safe Harbor method, health information is considered de-identified (and thus no longer subject to HIPAA rules) if 18 specific identifiers are removed, and there is no actual knowledge that the remaining information could identify the subject. These identifiers include:
| Category | Examples of Identifiers |
|---|---|
| Names | Full name, maiden name |
| Geographic Data | Subdivisions smaller than a state (street address, city, county, zip code) |
| Dates | All elements of dates directly related to an individual (birth date, admission date, discharge date, date of death) except year |
| Contact Info | Telephone numbers, fax numbers, email addresses |
| Identifying Numbers | Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers |
| Digital/Biometric | Web Universal Resource Locators (URLs), Internet Protocol (IP) address numbers, biometric identifiers (fingerprints, voice prints), full-face photographic images |
| Other | Any other unique identifying number, characteristic, or code |
Note: The subject's study identification number or randomization code is NOT one of the 18 identifiers, provided the key to decipher the code is kept strictly secure and is not disclosed.
Expert Determination Method
While the Safe Harbor method is straightforward, the alternative is the Expert Determination method. A person with appropriate knowledge of and experience with generally accepted statistical and scientific principles for rendering information not individually identifiable applies such principles to determine that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual. The expert must document the methods and results of the analysis that justify such determination. In specialized clinical trials, particularly those researching rare diseases where removing 18 identifiers might still leave a patient easily identifiable by their unique clinical presentation, expert determination is critical.
The CRC's Role in Confidentiality
CRCs must embed privacy practices into every aspect of trial execution. This begins with the Informed Consent process. The Informed Consent Form (ICF) must contain a specific HIPAA authorization (often integrated into the ICF or provided as a separate document). The authorization must clearly explain:
- What PHI will be collected.
- Who will have access to the PHI (e.g., the sponsor, the FDA, the Institutional Review Board, Contract Research Organizations).
- How the data will be used.
- The expiration date or event for the authorization (or state "no expiration").
Practical Privacy Measures
In the clinic, CRCs should implement several practical measures to safeguard data:
- Physical Security: Locking file cabinets containing source documents, ensuring screens displaying electronic health records (EHR) are not visible to unauthorized individuals, and adopting a "clean desk" policy.
- Electronic Security: Using encrypted emails when transmitting sensitive data, never sharing passwords for Electronic Data Capture (EDC) systems, and logging off computers when walking away.
- Communication: Avoiding discussing subjects by name in public areas like elevators or cafeterias. Using only the subject's initials and screening/randomization number when communicating with the sponsor.
GDPR and Global Clinical Trials
For trials conducted globally, or those involving citizens of the European Union, the General Data Protection Regulation (GDPR) applies. GDPR is generally more stringent than HIPAA. Key concepts include:
- Data Minimization: Only data absolutely necessary for the trial should be collected.
- Explicit Consent: Subjects must actively opt-in to data processing; bundled consents are often invalid.
- Right to Erasure (Right to be Forgotten): Subjects can request their data be deleted. However, in clinical trials, this right is often limited by overriding public interest in scientific research or regulatory requirements to maintain trial integrity.
- Data Protection Officer (DPO): Organizations processing large scale sensitive health data must appoint a DPO.
If a US-based CRC is working on a trial with European subjects, they must be aware of cross-border data transfer rules and ensure sponsor-provided systems comply with GDPR mechanisms like Standard Contractual Clauses.
Secondary Use of Clinical Data
Increasingly, sponsors want to retain trial data for future, unspecified research (secondary use). Under HIPAA, future research requires either a new authorization, a waiver of authorization from an IRB/Privacy Board, or the data must be completely de-identified. CRCs must be careful during the consenting process to clearly delineate what data is being used for the primary study and what, if any, optional consent is being requested for future use. Patients have the right to refuse secondary use without affecting their participation in the primary trial.
Handling Data Breaches
A data breach occurs when unsecured PHI is accessed, acquired, used, or disclosed without authorization. Examples include losing a laptop containing unencrypted subject lists or accidentally emailing a subject's lab results to the wrong person.
When a breach is suspected, the CRC must immediately notify the Principal Investigator and the institution's Privacy Officer or compliance department. The institution must then assess the breach to determine if it compromises the security or privacy of the PHI, which dictates the timeline and method for notifying the affected subjects, the Department of Health and Human Services (HHS), and potentially the media.
Which of the following is NOT one of the 18 HIPAA identifiers that must be removed for the Safe Harbor de-identification method?
Under the General Data Protection Regulation (GDPR), which concept dictates that only the absolute minimum amount of personal data necessary for the trial should be collected?
If a CRC accidentally leaves a printed roster of trial subjects with their medical record numbers in the public cafeteria, what is the immediate first step they should take?