HIPAA Research Authorizations: IRB & Privacy Board Guide
Regulatory Background
Using protected health information (PHI) in research is heavily regulated under HIPAA and requires either a properly executed authorization from the patient or a waiver/alteration from an Institutional Review Board (IRB) or Privacy Board. HIPAA's Privacy Rule § 164.508 governs research authorizations—the written permission patients must provide before their PHI can be used in research. Additionally, HIPAA § 164.512(i) allows for waiver or alteration of authorization requirements for research under specific conditions, with approval from an IRB or Privacy Board. Understanding these requirements is essential for institutions conducting research and healthcare providers participating in research studies.
Key Regulatory Frameworks
- HIPAA Privacy Rule: Governs use and disclosure of PHI in research
- Common Rule (45 CFR 46): Federal regulations for human research protections (IRB requirements)
- FDA Regulations: Apply to research involving investigational drugs and devices
- State and Local Laws: May impose additional research protections
HIPAA Authorization for Research
When Authorization is Required
A valid HIPAA authorization is required to use PHI in research unless:
- The information is properly de-identified (Safe Harbor or Expert Determination method)
- An IRB or Privacy Board has waived or altered the authorization requirement
- The research involves only a limited data set with an executed Data Use Agreement
Required Components of Research Authorization
A valid research authorization must include:
1. Specific Description of PHI to be Used
- Identify specific types of health information that will be used (medical records, lab results, diagnostic images, etc.)
- Specify time period (e.g., "records from 2020-2025")
- Be specific enough that individuals understand what information will be disclosed
- Cannot say "all my health information" without specificity regarding research use
2. Identification of Research Use
- Describe the research study name and purpose
- Explain what the research is studying and why
- Identify principal investigator and their institution
- Explain potential benefits of the research
3. Persons or Entities Who May Receive Information
- Identify who will receive the PHI (research team, collaborating institutions, sponsors, etc.)
- May identify specific entities or "research team members at [Institution]"
- Must include any entities receiving information for data analysis or oversight
4. Duration of Authorization
- Specify how long the authorization is valid
- May specify a specific end date or condition (e.g., "until study completion")
- For ongoing research, may be indefinite but must specify review intervals
5. Right to Revoke
- Clearly state that individuals have right to revoke authorization at any time
- Explain how to revoke (who to contact, process)
- State that revocation will not affect past use of information already disclosed
6. Consequences of Refusal
- Clearly state that refusing to sign does not affect patient's medical care (if true)
- If refusal does affect care (e.g., required for treatment study participation), state that clearly
- Use plain language to explain consequences of refusal
7. Treatment/Payment/Enrollment Conditioning
- State whether authorization is conditioning for treatment/payment/health plan enrollment
- For most research, state that authorization is not a condition of treatment or payment
- For research conducted in treatment context, explain how authorization relates to treatment
8. Signature and Date
- Require patient signature (or authorized representative)
- Date of signature
- Signature of researcher obtaining authorization
Plain Language Requirement
The authorization must be written in plain, understandable language:
- Written at approximately 6th grade reading level
- Avoid medical jargon without explanation
- Explain research purpose in lay terms
- Use short paragraphs and clear structure
- HIPAA provides specific standard authorization form that may be used
Waiver or Alteration of Authorization by IRB or Privacy Board
Conditions for Waiver
An IRB or Privacy Board may waive or alter the authorization requirement if:
- Minimal Risk: Research presents minimal risk to privacy
- Practicality: Obtaining authorization would be impracticable (e.g., retrospective research on deceased patients)
- Public Health: Research is for public health activities or surveillance
- Health Oversight: Research is for health oversight or fraud/abuse detection activities
- Judicial/Administrative: Research is mandated by legal proceedings
Waiver Process
- Researcher submits request to IRB or Privacy Board explaining why authorization waiver is appropriate
- IRB/Privacy Board reviews waiver request and research protocol
- IRB/Privacy Board documents that waiver criteria are met and makes written determination
- IRB/Privacy Board may require alternative protections (such as honest broker protocols)
- Waiver is approved or denied with explanation
Privacy Board Composition and Role
A Privacy Board is an entity established by a covered entity to review and approve waiver/alteration of authorization. Membership must include:
- At Least One Physician: If the research involves treatment decisions
- At Least One Non-Affiliated Member: Someone not employed by the covered entity
- Community Representative: Someone representing patient/community interests (recommended)
- Varying Expertise: Members with diverse backgrounds and perspectives
Limited Data Set Alternative
Using Limited Data Sets for Research
Rather than obtaining individual authorizations or waiving authorization, researchers may use a limited data set for research purposes if:
- A Data Use Agreement is signed by the researcher and institution
- Limited data set contains only permitted identifiers (birth date month/year, city/state, dates related to individual, etc.)
- All other identifiers are removed
Data Use Agreement Requirements
The Data Use Agreement must specify:
- Research purposes for which limited data set will be used
- Restriction on re-disclosure to other parties
- Requirement to use minimum necessary limited data
- Protection of data using HIPAA-compliant safeguards
- Return or destruction of data when research is complete
- Notation of any re-identification that occurs
Implementation Guidance
For Researchers and Study Coordinators
- Determine Authorization Need: Determine whether research requires authorization, waiver, limited data set, or de-identification
- Obtain IRB/Privacy Board Approval: Get protocol review and approval before enrolling patients
- Obtain Authorization: Obtain informed consent and HIPAA authorization (or waiver) from research participants
- Secure PHI: Implement appropriate safeguards protecting research data
- Track Authorizations: Maintain records of authorizations and any revocations
- Limit Access: Restrict access to only research team members with need to know
- De-identify When Possible: Remove identifiers from analysis datasets when not necessary for research
For Healthcare Organizations Housing Research Data
- Establish research governance policies and oversight mechanisms
- Train staff on research PHI protections and authorization requirements
- Maintain secure systems for research data storage and access
- Audit research use of PHI for compliance with authorizations and waiver terms
- Respond promptly to authorization revocation requests
- Maintain documentation of research approvals and authorizations
Authorization Documentation
Maintain comprehensive records of research authorizations:
- Copy of signed research authorization form
- Date authorization was obtained
- Identification of person who obtained authorization
- IRB/Privacy Board approval documents
- Protocol and any amendments
- Records of authorization revocations
- Data Use Agreements (if applicable)
Frequently Asked Questions
Can a general research authorization cover multiple studies?
Potentially, but each research use must be specifically described in the authorization. You could have a broad research authorization authorizing use of PHI for "all research conducted by [Institution]" but this is less specific than HIPAA requires. Best practice is to obtain separate authorizations for specific research studies or obtain a broad authorization that describes the types of research that will be conducted. If you later want to use the PHI for a research purpose not described in the original authorization, you should obtain a new authorization from the patient or seek a waiver/alteration from the IRB or Privacy Board.
What happens if a patient revokes their research authorization?
Once a patient revokes authorization in writing, you must: (1) Stop using the patient's PHI for research purposes going forward, (2) Not use any PHI collected after the revocation date, (3) Remove the patient from the research study (no further data collection), and (4) Notify the research team of the revocation. However, PHI already collected and used before revocation remains usable under the authorization that was valid at the time of collection. Many research protocols include language explaining this to participants. If a large number of participants revoke authorization, it may affect the validity of the research, so researchers should consider this possibility when designing studies.
Can we use treatment records for research without new authorization?
No. Authorization is required to use treatment records for research purposes unless: (1) The research uses only de-identified information, (2) An IRB/Privacy Board has waived authorization, or (3) A limited data set with Data Use Agreement is used. Simply because PHI was originally collected for treatment purposes does not mean it can be used for research without proper authorization. The original authorization for treatment does not extend to research uses. However, if research is directly integrated with treatment (e.g., quality improvement study of treatment protocols), authorization requirements may be different, and you should consult with your IRB or Privacy Board.
What are the differences between IRB and Privacy Board reviews?
An IRB reviews research for subject safety, rights, and welfare (Common Rule compliance), while a Privacy Board reviews research for HIPAA privacy compliance. Many institutions use their IRB for both functions, but they are distinct reviews. The IRB focuses on informed consent, risk/benefit analysis, subject protection, and research protocols. A Privacy Board focuses specifically on HIPAA authorization waivers and limited data set uses. Some larger institutions have separate Privacy Boards, while others combine these functions in a single IRB. For HIPAA authorization waivers, at least one Privacy Board member or IRB member must review the HIPAA-specific aspects of the waiver request.
Ensure Research Compliance and Patient Protection
Medcurity provides research authorization templates, IRB/Privacy Board documentation tools, and compliance tracking systems for research involving PHI.
Streamline Research Compliance