Skip to main content
Category: Regulatory Framework

Common Rule

Also known as: Federal Policy for the Protection of Human Subjects, 45 CFR Part 46 Subpart A
Simply put

The Common Rule is the informal name for a U.S. federal policy that sets baseline ethical protections for people who participate in research studies. It is called the 'Common Rule' because a number of federal departments and agencies have adopted the same core requirements, which cover topics such as review boards, informed consent, and institutional assurances. It is separate from HIPAA, though research involving health information may be subject to both.

Formal definition

The Common Rule is the popular term for the Federal Policy for the Protection of Human Subjects, codified at 45 CFR Part 46 (Subpart A), which establishes baseline requirements for research involving human subjects across the federal departments and agencies that have adopted it. As reflected in the evidence, it outlines core provisions for Institutional Review Boards (IRBs), informed consent, and Assurances of Compliance. The Common Rule is a distinct regulatory framework from the HIPAA Privacy Rule, Security Rule, and other HIPAA rules enforced by HHS OCR; where research uses protected health information, both the Common Rule and applicable HIPAA requirements may independently apply, and practitioners should verify current regulatory text and consult the relevant subparts of 45 CFR Part 46. This entry does not address the specific criteria for IRB review, exemptions, or consent elements, which are set out in the regulation itself and may be supplemented by state law or other frameworks.

Why it matters

The Common Rule matters because it establishes the baseline ethical framework governing research involving human subjects across the federal departments and agencies that have adopted it. For healthcare organizations, academic medical centers, and research institutions, it defines core obligations around Institutional Review Board (IRB) oversight, informed consent, and Assurances of Compliance that must be satisfied before and during studies involving people. Compliance professionals working in settings where research and clinical care intersect need to understand that these protections operate independently of HIPAA.

A frequent source of confusion is the relationship between the Common Rule and HIPAA. The two are distinct regulatory frameworks: the Common Rule (codified at 45 CFR Part 46, Subpart A) governs the ethical conduct of human subjects research, while HIPAA rules govern the privacy and security of protected health information and are enforced by HHS OCR. Where research uses protected health information, both frameworks may independently apply, meaning satisfying one does not by itself satisfy the other. Practitioners should map both sets of requirements rather than assuming overlap.

Because the specific criteria for IRB review, exemptions, and the required elements of informed consent are set out in the regulation itself and may be supplemented by state law or other frameworks, organizations should verify current regulatory text against 45 CFR Part 46 and consult the relevant subparts rather than relying on general summaries. Missteps in research oversight can carry consequences separate from any HIPAA implications.

Who it's relevant to

Research Compliance and IRB Professionals
Those who administer or serve on Institutional Review Boards rely on the Common Rule as the baseline framework for reviewing research protocols, overseeing informed consent, and maintaining institutional Assurances of Compliance. They should work from the current regulatory text of 45 CFR Part 46 rather than general summaries.
Academic Medical Centers and Research Institutions
Organizations that conduct human subjects research must satisfy Common Rule obligations independently of any HIPAA requirements. Where research also involves protected health information, both frameworks may apply, and these institutions need to map each set of requirements separately.
Privacy and Compliance Officers at Healthcare Organizations
Compliance officers operating where research and clinical care intersect should understand that the Common Rule and HIPAA are distinct frameworks. Satisfying HIPAA does not establish Common Rule compliance, and vice versa; both may need to be addressed when research uses health information.
Legal Counsel Supporting Research Programs
Attorneys advising on research activities should account for the Common Rule's provisions on IRBs, informed consent, and Assurances, while recognizing that state law or other frameworks may impose additional requirements beyond the federal baseline set in 45 CFR Part 46.

Inside Common Rule

Federal Policy for the Protection of Human Subjects
The Common Rule is the informal name for the U.S. federal regulation governing the ethical conduct of research involving human subjects. It establishes baseline protections for individuals who participate in federally supported or conducted research.
Informed Consent Requirements
The Common Rule generally requires that research participants provide informed consent, meaning they are given adequate information about the research, its risks and benefits, and their rights before agreeing to participate. Specific elements of consent are defined in the regulatory text and should be confirmed against the current version.
Institutional Review Board (IRB) Oversight
The Common Rule typically requires review and approval of covered research by an IRB, which evaluates the ethical acceptability of the research, including risk minimization and protection of participants.
Scope Tied to Research
The Common Rule applies to human subjects research, particularly research that is federally funded, conducted, or otherwise subject to the policy. Its focus is the ethical treatment of research participants rather than the general handling of health information.
Relationship to HIPAA
The Common Rule and the HIPAA Privacy Rule are distinct legal frameworks with different authorities and purposes. Research involving protected health information (PHI) may be subject to both, but compliance with one does not establish compliance with the other. Readers should verify how the two frameworks interact for a given research activity against current regulatory guidance.

Common questions

Answers to the questions practitioners most commonly ask about Common Rule.

Does the Common Rule apply to the same activities as the HIPAA Privacy Rule?
No. The Common Rule and the HIPAA Privacy Rule are separate regulatory frameworks with different scopes and enforcing authorities. The Common Rule governs the protection of human subjects in federally supported research, while the HIPAA Privacy Rule governs the use and disclosure of protected health information by covered entities and, through business associate agreements, their business associates. A given research project may be subject to one, both, or neither, depending on the facts. Readers should analyze each framework independently and verify applicability against the current regulatory text.
Does complying with the Common Rule mean an organization has satisfied its HIPAA obligations?
Not necessarily. Meeting Common Rule requirements does not by itself establish HIPAA compliance, and vice versa. Where both frameworks apply to the same activity, an organization generally must satisfy each set of requirements separately. The two have distinct definitions, obligations, and oversight authorities. Where a research activity involves protected health information held by a covered entity, HIPAA Privacy Rule requirements typically apply in addition to any Common Rule requirements. Confirm the specific obligations of each framework against current guidance.
How should our organization determine whether an activity is subject to the Common Rule, HIPAA, or both?
Begin by analyzing each framework separately, since they have independent triggers. Consider whether the activity meets the applicable definition of human subjects research under the Common Rule and whether it involves protected health information held by a covered entity or business associate under HIPAA. Because the scopes differ, an activity may fall under one framework, both, or neither. Institutions commonly involve their IRB, privacy office, and legal counsel in this determination, and should confirm applicability against the current regulatory text of each framework.
Who within an organization typically oversees Common Rule and HIPAA responsibilities in a research context?
In many institutions, an Institutional Review Board (IRB) has a central role in matters connected to the Common Rule, while the privacy officer and security officer generally oversee HIPAA responsibilities. Because these functions address different frameworks, coordination among them is typically important where a research activity implicates both. Organizations should confirm their internal governance structure and the specific responsibilities assigned to each role against their own policies and current regulatory guidance.
What documentation practices help when an activity may be subject to both the Common Rule and HIPAA?
Because the two frameworks have separate requirements, organizations generally benefit from documenting how each applicable requirement is addressed rather than assuming that satisfying one covers the other. This typically includes maintaining records that reflect the analysis of each framework's applicability and the basis for any determination. Specific documentation obligations differ by framework and may be affected by other requirements such as state law or the HITECH Act, so organizations should verify what applies against current guidance.
If our activity involves both frameworks, how do we reconcile potentially different requirements?
Where both the Common Rule and HIPAA apply to the same activity, an organization generally must satisfy each framework's requirements rather than choosing between them. When the requirements differ, the practical approach in most cases is to meet the obligations of each applicable framework independently. Additional requirements may arise from state law or other frameworks beyond HIPAA. Because reconciling overlapping requirements can be fact-specific, organizations should confirm the applicable obligations against the current regulatory text and, where appropriate, consult legal counsel.

Common misconceptions

The Common Rule and the HIPAA Privacy Rule are the same thing or one satisfies the other.
They are separate frameworks with different scopes and authorities. The Common Rule governs the ethical conduct of human subjects research, while the HIPAA Privacy Rule governs the use and disclosure of PHI by covered entities and, through business associate agreements, their business associates. Research using PHI may trigger obligations under both, and satisfying one does not automatically satisfy the other.
Complying with the Common Rule means an organization is HIPAA compliant.
Compliance with the Common Rule does not by itself demonstrate compliance with HIPAA. Each framework imposes its own distinct requirements, and organizations conducting research with PHI should evaluate both separately and confirm current requirements against the applicable regulatory text.
The Common Rule applies to all handling of health data.
The Common Rule generally applies in the context of human subjects research, particularly research that is federally funded or conducted, rather than to routine handling of health information. General uses and disclosures of PHI outside of research are typically addressed under the HIPAA Privacy Rule, and additional requirements may arise under state law or other frameworks.

Best practices

When research involves protected health information, evaluate obligations under both the Common Rule and the HIPAA Privacy Rule separately, and do not assume compliance with one satisfies the other.
Engage your Institutional Review Board (IRB) early for human subjects research to confirm whether IRB review and approval are required for the planned activity.
Verify current informed consent elements and other requirements against the applicable regulatory text rather than relying on prior versions, as regulations are periodically updated.
Coordinate between research, privacy, and compliance functions so that PHI used in research is handled consistently with both research ethics requirements and HIPAA Privacy Rule obligations.
Confirm whether state law or other frameworks impose additional requirements beyond the Common Rule and HIPAA for a given research activity.
Document the basis for how each framework applies to a research project, and confirm the applicability and scope of the Common Rule against current guidance where uncertainty exists.