Skip to main content
Category: Uses and Disclosures

Research Disclosures

Simply put

In the HIPAA context, research disclosures generally refer to the sharing of protected health information (PHI) for research purposes under conditions permitted by the HIPAA Privacy Rule. The Privacy Rule sets specific pathways, such as obtaining an individual's authorization or a waiver approved by an Institutional Review Board or Privacy Board, before PHI may be used or disclosed for research. Note that the evidence provided does not directly address HIPAA research disclosures, so the specific regulatory requirements below should be confirmed against the current Privacy Rule text.

Formal definition

The evidence packet supplied does not contain material specific to HIPAA research disclosures; the sources address disclosure in unrelated contexts (financial conflict-of-interest disclosures, corporate securities disclosure, technical disclosures, and a nursing concept analysis). As a result, a reliable evidence-based technical definition cannot be constructed from the provided sources. In general HIPAA practice, research disclosures are governed by the Privacy Rule, which addresses PHI in all forms (oral, paper, and electronic), and typically require one of several permitted mechanisms (for example, individual authorization, an IRB/Privacy Board waiver or alteration of authorization, review preparatory to research, or research on decedents' information), subject to any applicable de-identification or limited data set provisions. Practitioners should verify the precise conditions, documentation requirements, and any additional obligations imposed by the HITECH Act, the Common Rule, or state law against the current regulatory text rather than relying on the sources in this evidence packet.

Why it matters

Research disclosures sit at the intersection of two priorities that can pull in opposite directions: advancing medical and scientific knowledge, and protecting the privacy of individuals whose protected health information (PHI) may be used to conduct that research. Under the HIPAA Privacy Rule, PHI generally cannot be shared for research purposes freely; instead, covered entities and their business associates must rely on one of the specific pathways the rule permits, such as individual authorization or a waiver approved by an Institutional Review Board (IRB) or Privacy Board. Getting these pathways wrong can expose an organization to enforcement action by HHS OCR and can undermine the trust that patients place in the institutions holding their data.

Because research disclosures often involve multiple parties, an academic medical center, affiliated investigators, sponsors, and downstream data recipients, the governance around them tends to be complex. The applicable requirements may differ depending on whether the data is fully identifiable, de-identified, or shared as a limited data set, and the documentation obligations attached to each pathway are not interchangeable. Missteps frequently arise not from bad intent but from applying the wrong mechanism to a given research activity or from incomplete documentation of the basis for a disclosure.

It is important to flag that the evidence packet supplied for this entry does not address HIPAA research disclosures; the available sources discuss disclosure in unrelated contexts such as financial conflict-of-interest statements, corporate securities disclosure, technical disclosures, and a nursing concept analysis. For that reason, practitioners should treat the general descriptions here as orientation only and confirm the specific conditions, permitted pathways, and documentation requirements against the current text of the HIPAA Privacy Rule and any applicable overlapping frameworks.

Who it's relevant to

Privacy Officers and Compliance Teams
Privacy officers at covered entities are typically responsible for determining which Privacy Rule pathway applies to a proposed research disclosure and for ensuring the supporting documentation, such as authorizations or waiver approvals, is complete and retained. They should confirm the applicable conditions against the current Privacy Rule text and watch for additional obligations under the HITECH Act, the Common Rule, or state law.
IRBs and Privacy Boards
Institutional Review Boards and Privacy Boards play a defined role in approving waivers or alterations of authorization for research uses and disclosures of PHI. Members and administrators need to understand the specific criteria and documentation the Privacy Rule requires for these approvals, verifying details against the current regulatory text.
Researchers and Research Administrators
Investigators and their supporting administrative staff must know which mechanism governs the data they intend to use, and how requirements differ between fully identifiable PHI, a limited data set, and de-identified information. Because the specific conditions differ by pathway, they should coordinate with their privacy office rather than assume a single approach applies to all research.
Legal Counsel Advising Healthcare and Research Organizations
Counsel advising covered entities and business associates on research arrangements should account for the interplay between HIPAA and overlapping frameworks such as the Common Rule and state law, which may impose stricter requirements. They should confirm penalty exposure and enforcement considerations, which are handled by HHS OCR for HIPAA, against current guidance.

Inside Research Disclosures

Authorization for Research Use or Disclosure
A HIPAA Privacy Rule authorization signed by the individual permitting a covered entity to use or disclose PHI for a specified research purpose. Research authorizations may be combined with informed consent documents and, unlike most authorizations, may describe an end 'when the research study ends' or state that there is no expiration.
IRB or Privacy Board Waiver of Authorization
A mechanism under the Privacy Rule allowing an Institutional Review Board (IRB) or Privacy Board to waive or alter the authorization requirement when specified criteria are met, generally including that the research could not practicably be conducted without the waiver and without access to the PHI, and that the risk to privacy is minimal.
Reviews Preparatory to Research
A pathway permitting use or disclosure of PHI to prepare a research protocol or determine feasibility, typically conditioned on representations that access is solely to prepare research, that no PHI is removed, and that the PHI is necessary for the research purpose.
Research on Decedents' Information
A pathway permitting use or disclosure of a decedent's PHI for research, typically conditioned on representations that the use is solely for research on decedents, that the PHI is necessary for the research, and, upon request, documentation of death.
De-identified Data and Limited Data Sets
De-identified information (which is not PHI and generally falls outside the Privacy Rule) and limited data sets (which retain certain identifiers and may be disclosed for research under a data use agreement). These options can reduce the need for individual authorization.
Accounting of Disclosures
Certain research disclosures made without individual authorization may need to be included in the accounting of disclosures a covered entity provides to individuals on request, subject to the specific conditions and exceptions in the Privacy Rule.
Minimum Necessary Considerations
Uses and disclosures of PHI for research, other than those made pursuant to an authorization, are generally subject to the Privacy Rule's minimum necessary standard, limiting PHI to that reasonably needed for the research purpose.

Common questions

Answers to the questions practitioners most commonly ask about Research Disclosures.

Does HIPAA prohibit using PHI for research without individual authorization?
No. While authorization is one common pathway, the HIPAA Privacy Rule generally permits disclosure of PHI for research under several other mechanisms as well, including an IRB or Privacy Board waiver or alteration of the authorization requirement, reviews preparatory to research, research on decedents' information, and the use of a limited data set with a data use agreement. Authorization is not the only route. The specific conditions for each pathway are set by the Privacy Rule, and readers should confirm the applicable requirements against the current regulatory text.
Does obtaining HITRUST certification or meeting Security Rule safeguards satisfy the requirements for research disclosures?
No. Research disclosures are governed by the HIPAA Privacy Rule, which addresses when and how PHI in any form may be used or disclosed. Security Rule safeguards apply to protecting ePHI but do not authorize a disclosure. HITRUST certification is a private, voluntary attestation against the HITRUST CSF and does not by itself establish HIPAA compliance or provide a lawful basis for a research disclosure. These are distinct obligations, and satisfying one does not substitute for the Privacy Rule conditions that permit research use.
How does a covered entity decide which research disclosure pathway to use?
The choice generally depends on the nature of the research and the data involved. If direct identifiers can be removed, a limited data set with a data use agreement or de-identification may reduce administrative burden. Where individual participation and identifiable data are needed, an authorization may be appropriate. Where obtaining authorization is impracticable, an IRB or Privacy Board waiver may be considered. Reviews preparatory to research and research on decedents' information have their own narrower conditions. Covered entities typically evaluate these options against the study's purpose, the level of identifiability required, and the conditions set out in the current Privacy Rule.
What documentation should be retained for a research disclosure?
Covered entities generally maintain documentation appropriate to the pathway used. For a waiver or alteration, this typically includes the IRB or Privacy Board's documented approval and the required determinations. For a limited data set, the executed data use agreement is retained. For authorization-based disclosures, the signed authorization is kept. Records supporting reviews preparatory to research and research on decedents' information are also generally documented. Retention periods and accounting-of-disclosure obligations should be confirmed against the current regulation, as certain research disclosures may need to be included in an accounting of disclosures.
What is a data use agreement and when is it required for research?
A data use agreement is a written agreement required under the Privacy Rule when a covered entity discloses a limited data set for research, public health, or health care operations. It generally establishes permitted uses and disclosures of the limited data set, identifies who may use or receive the data, and includes safeguards and restrictions such as prohibiting re-identification or contact with individuals. It is distinct from a business associate agreement and applies specifically to limited data set disclosures. The precise required terms should be verified against the current regulatory text.
Do state laws or other frameworks add requirements beyond HIPAA for research disclosures?
Yes, in many cases. HIPAA sets a federal floor, but state laws may impose additional or more stringent requirements, particularly for sensitive categories of information. Other frameworks and requirements, such as the Common Rule governing human subjects research, FDA regulations for regulated studies, and the HITECH Act, may also apply depending on the research context. A disclosure that satisfies the HIPAA Privacy Rule does not necessarily satisfy every other applicable legal or ethical requirement, so readers should evaluate the full set of authorities relevant to their study.

Common misconceptions

An IRB or Privacy Board waiver of authorization means the researcher faces no HIPAA restrictions on the PHI.
A waiver removes the individual authorization requirement only; the covered entity's other Privacy Rule obligations still generally apply, including minimum necessary and, in applicable cases, inclusion of the disclosure in an accounting of disclosures. A waiver must also meet the specific regulatory criteria assessed by the IRB or Privacy Board.
De-identified data and limited data sets are the same thing and both fall outside HIPAA.
They are distinct. De-identified information generally is not PHI and is outside the Privacy Rule when the de-identification standard is met. A limited data set still contains certain identifiers, remains PHI, and may be disclosed for research only under a data use agreement with specified terms.
A single IRB approval of a study automatically satisfies the HIPAA authorization requirement.
IRB approval of a study under the Common Rule and the HIPAA authorization or waiver requirements are separate determinations. Obtaining research consent does not by itself meet the Privacy Rule's authorization elements unless the document is structured to satisfy both, and state law or the HITECH Act may impose additional requirements.

Best practices

Determine early which research pathway applies (authorization, IRB/Privacy Board waiver, reviews preparatory to research, decedents' research, de-identified data, or a limited data set) and document the basis for that choice.
When relying on a waiver of authorization, retain the IRB or Privacy Board documentation confirming the required criteria were evaluated and met, and reassess if the protocol changes.
Use a limited data set with a data use agreement, or fully de-identified data, where feasible to reduce reliance on individual authorizations and to limit exposure of PHI.
Apply the minimum necessary standard to research uses and disclosures that are not made pursuant to an authorization, restricting PHI to what the protocol reasonably requires.
Track research disclosures that may need to appear in an individual's accounting of disclosures and maintain records sufficient to produce that accounting on request.
Confirm the current regulatory text, and check whether applicable state law or the HITECH Act imposes stricter research disclosure requirements, before finalizing study documentation.