Skip to main content
Category: Uses and Disclosures

Institutional Review Board (IRB) Waiver

Also known as: IRB Waiver, IRB Waiver of Authorization, Waiver of HIPAA Authorization, IRB Waiver of Informed Consent
Simply put

An IRB waiver is a formal decision by an Institutional Review Board allowing researchers to use or disclose protected health information (PHI) without first obtaining each individual's written authorization or consent. This typically applies to research studies where obtaining individual permission would be impractical, and only when specific documented conditions are met. It does not remove all protections for research participants; other rules and safeguards may still apply.

Formal definition

Under the HIPAA Privacy Rule, an IRB (or Privacy Board) may approve a waiver of the individual authorization normally required for a covered entity to use or disclose PHI for research, provided the required documentation demonstrating that the applicable waiver criteria are satisfied is furnished. A parallel but legally distinct mechanism exists under the Common Rule governing human subjects research, where an IRB may waive the requirement to obtain informed consent when certain conditions are met; these two waivers arise from separate authorities and should not be conflated. IRBs may also, in defined circumstances, waive documentation of consent (for example, the requirement to obtain a participant's signature). The specific criteria, documentation elements, and process requirements are set by the current regulatory text and institutional policy, and readers should verify them against the applicable HIPAA Privacy Rule provisions, the Common Rule, and current agency guidance. An IRB waiver addresses the authorization/consent requirement only and does not by itself establish overall HIPAA or research compliance; state law, the HITECH Act, and other frameworks may impose additional requirements.

Why it matters

Research involving protected health information often requires a covered entity to obtain each individual's written authorization before their PHI can be used or disclosed. For large retrospective studies, registry work, or research using existing records, obtaining authorization from every individual can be impractical or impossible. The IRB waiver mechanism under the HIPAA Privacy Rule provides a lawful pathway for such research to proceed when an Institutional Review Board (or Privacy Board) documents that the applicable waiver criteria are satisfied. Without this mechanism, a significant category of health research could stall, so understanding when and how a waiver applies is important for both compliance and the advancement of legitimate research.

A recurring source of confusion is that two distinct waivers can arise in the same study. The HIPAA Privacy Rule permits an IRB to waive the individual authorization normally required for use or disclosure of PHI, while the Common Rule governing human subjects research permits an IRB to waive the requirement to obtain informed consent. These arise from separate legal authorities and carry separate criteria and documentation requirements; treating one as satisfying the other can leave a study out of compliance with the requirement that was never actually addressed. IRBs may also, in defined circumstances, waive the requirement to document consent, such as obtaining a participant's signature, which is again a distinct action.

Because an IRB waiver addresses only the authorization or consent requirement, it should never be mistaken for a determination that a study is fully HIPAA compliant or otherwise cleared of regulatory obligations. Other Privacy Rule safeguards, state law, the HITECH Act, and additional frameworks may impose further requirements, and the specific criteria and documentation elements are set by current regulatory text and institutional policy. Compliance and research staff who rely on a waiver should confirm they have satisfied the correct authority for each requirement rather than assuming a single approval covers everything.

Who it's relevant to

Privacy Officers at Covered Entities
Privacy officers must ensure that any research use or disclosure of PHI relying on an IRB waiver is supported by the required documentation demonstrating that the applicable waiver criteria under the HIPAA Privacy Rule were met. They should confirm the waiver addresses the authorization requirement specifically and should not treat it as blanket clearance for all HIPAA obligations.
Researchers and Principal Investigators
Investigators conducting studies involving PHI need to understand which waiver they are seeking. A HIPAA waiver of authorization is distinct from a Common Rule waiver of informed consent, and a waiver of documentation of consent (such as a signature) is another separate action. Investigators should work with their IRB to secure the correct approvals and documentation for their study design.
Institutional Review Board and Privacy Board Members
IRB and Privacy Board members apply the waiver criteria and produce the documentation that supports each type of waiver. They should keep the HIPAA and Common Rule authorities distinct, verify criteria against current regulatory text and institutional policy, and be aware that waiver criteria and documentation requirements have been subject to process changes over time.
Compliance and Legal Counsel in Healthcare Research
Counsel advising on research programs should confirm that reliance on an IRB waiver does not create a false assumption of overall compliance. State law, the HITECH Act, and other frameworks may impose additional requirements beyond what the waiver addresses, and figures, criteria, and citations should be confirmed against current guidance.

Inside IRB Waiver

IRB or Privacy Board Review
Under the HIPAA Privacy Rule, an Institutional Review Board (IRB) or a Privacy Board may approve a waiver or alteration of the individual authorization normally required to use or disclose protected health information (PHI) for research. Either body is generally permitted to grant the waiver, provided it is properly constituted under the applicable requirements.
Waiver Criteria
The Privacy Rule specifies criteria an IRB or Privacy Board must find satisfied before approving a waiver, generally including that the use or disclosure involves no more than minimal risk to the privacy of individuals, that the research could not practicably be conducted without the waiver, and that it could not practicably be conducted without access to and use of the PHI. Practitioners should confirm the specific criteria against the current regulatory text.
Documentation Requirements
An approved waiver typically must be documented, including identification of the reviewing body, the date of approval, a statement that the waiver criteria were satisfied, a brief description of the PHI for which use or disclosure is being approved, and a statement that the waiver was reviewed under the applicable normal or expedited procedures, generally signed by the chair or designee.
Scope of Application
An IRB waiver applies specifically to the authorization requirement of the HIPAA Privacy Rule for research uses and disclosures of PHI by covered entities. It is one of several research pathways under the Privacy Rule and does not, by itself, address Security Rule safeguards for ePHI or obligations under other frameworks.
Relationship to the Common Rule
IRB review under the HIPAA Privacy Rule is distinct from, though it may overlap operationally with, IRB obligations under the Common Rule (human subjects research protections). A HIPAA waiver of authorization is a separate determination from Common Rule informed consent or its waiver, and satisfying one does not automatically satisfy the other.

Common questions

Answers to the questions practitioners most commonly ask about IRB Waiver.

Does an IRB waiver eliminate the need to follow HIPAA when using PHI for research?
No. An IRB (or Privacy Board) waiver of authorization is itself a mechanism created under the HIPAA Privacy Rule; it does not remove HIPAA from the equation. It permits a covered entity to use or disclose PHI for research without obtaining individual authorization only when specified regulatory criteria are met and documented. The covered entity and any business associates remain subject to their other HIPAA obligations, and researchers must still adhere to the conditions the IRB imposed. Readers should verify the specific waiver criteria against the current Privacy Rule text.
Is an IRB waiver the same thing as a research participant's authorization?
No. These are distinct pathways. An individual authorization is a signed permission from the research subject that meets the Privacy Rule's content requirements. An IRB (or Privacy Board) waiver is a documented approval that no such individual authorization is required for the described use or disclosure, granted because the request satisfies the regulatory waiver criteria. A waiver is generally sought when obtaining authorization from each individual is impracticable, whereas authorization involves direct permission from each person. They are not interchangeable, and the applicable conditions differ.
Who can approve a HIPAA waiver of authorization for a research use of PHI?
Under the Privacy Rule, a waiver or alteration of authorization may generally be approved by either an IRB or a Privacy Board that meets the composition requirements described in the regulation. Both routes require documentation that the applicable waiver criteria have been satisfied. Confirm the specific membership and procedural requirements against the current regulatory text, and note that an institution's own policies or applicable state law may add further steps.
What documentation should a covered entity retain when relying on an IRB waiver?
In general, the covered entity should retain documentation reflecting the IRB or Privacy Board's approval, an identification of the reviewing body, the date of approval, a statement that the required waiver criteria were found to be satisfied, a brief description of the PHI for which use or disclosure was determined necessary, and appropriate signature by the required official. Because retention specifics and required elements are defined in the regulation and may be supplemented by institutional policy, verify the current requirements before establishing a records-retention approach.
Do we still need to track the disclosure of PHI made under an IRB waiver?
Often, yes. Disclosures of PHI made pursuant to a waiver of authorization can fall within the accounting-of-disclosures obligations, which differ from disclosures made under an individual's authorization. Because the accounting requirements and any applicable exceptions are set out in the Privacy Rule and are subject to interpretation, covered entities should map their research disclosures against the current accounting rules and their own policies rather than assume no tracking is needed.
How does an IRB waiver interact with a limited data set or a business associate arrangement?
These are separate mechanisms that may be used together or as alternatives. A limited data set used with a data use agreement is a distinct Privacy Rule pathway that does not require a waiver, and researchers sometimes choose it instead of seeking a waiver. When a business associate or a research vendor handles PHI on the covered entity's behalf, the applicable obligations generally flow through a business associate agreement, independent of whether a waiver was granted. Determining which combination applies depends on the data involved and the relationships, so confirm the appropriate structure against the current regulation and your agreements.

Common misconceptions

An IRB waiver eliminates all HIPAA obligations for a research project.
A waiver generally addresses only the Privacy Rule's individual authorization requirement for the specified research use or disclosure of PHI. Other obligations, such as minimum necessary considerations, accounting of disclosures where applicable, and Security Rule safeguards for ePHI, typically continue to apply. Readers should confirm scope against the current regulation.
Only an IRB can grant a HIPAA waiver of authorization.
Under the Privacy Rule, either a properly constituted IRB or a Privacy Board may approve a waiver or alteration of authorization. The two bodies have different composition requirements, but both are generally recognized pathways for HIPAA research waivers.
A waiver of HIPAA authorization is the same as a waiver of informed consent under the Common Rule.
These are separate determinations governed by different requirements. A HIPAA waiver of authorization concerns the use or disclosure of PHI under the Privacy Rule, while Common Rule consent concerns human subjects protections. A project may require both, and approving one does not by itself satisfy the other.

Best practices

Verify that the reviewing body is properly constituted as an IRB or Privacy Board under the applicable requirements before relying on its waiver approval.
Confirm the current waiver criteria and documentation elements against the applicable Privacy Rule text, since specific requirements should be checked against current guidance rather than assumed.
Maintain complete waiver documentation, including the reviewing body's identity, approval date, a statement that the criteria were met, a description of the PHI covered, the review procedure used, and an appropriate signature.
Treat the waiver as addressing only the authorization requirement, and separately confirm that minimum necessary practices, Security Rule safeguards for any ePHI, and other applicable obligations are met.
Coordinate the HIPAA waiver determination with any Common Rule IRB review to ensure both human subjects consent obligations and PHI authorization obligations are addressed as distinct items.
Check whether state law or other frameworks impose additional research or privacy requirements beyond HIPAA, and document how those are addressed.