Get Compliance Tools

HIPAA Research Authorizations: IRB & Privacy Board Guide

Last updated: March 2026 | Regulatory Deep Dive

Regulatory Background

Using protected health information (PHI) in research is heavily regulated under HIPAA and requires either a properly executed authorization from the patient or a waiver/alteration from an Institutional Review Board (IRB) or Privacy Board. HIPAA's Privacy Rule § 164.508 governs research authorizations—the written permission patients must provide before their PHI can be used in research. Additionally, HIPAA § 164.512(i) allows for waiver or alteration of authorization requirements for research under specific conditions, with approval from an IRB or Privacy Board. Understanding these requirements is essential for institutions conducting research and healthcare providers participating in research studies.

Key Regulatory Frameworks

Key Context: Institutions conducting research must navigate both HIPAA privacy requirements and Common Rule (IRB) requirements. These often overlap but serve different purposes: HIPAA protects privacy, while Common Rule protects research subject safety and rights.

HIPAA Authorization for Research

When Authorization is Required

A valid HIPAA authorization is required to use PHI in research unless:

Required Components of Research Authorization

A valid research authorization must include:

1. Specific Description of PHI to be Used

2. Identification of Research Use

3. Persons or Entities Who May Receive Information

4. Duration of Authorization

5. Right to Revoke

6. Consequences of Refusal

7. Treatment/Payment/Enrollment Conditioning

8. Signature and Date

Plain Language Requirement

The authorization must be written in plain, understandable language:

Waiver or Alteration of Authorization by IRB or Privacy Board

Conditions for Waiver

An IRB or Privacy Board may waive or alter the authorization requirement if:

Waiver Process

  1. Researcher submits request to IRB or Privacy Board explaining why authorization waiver is appropriate
  2. IRB/Privacy Board reviews waiver request and research protocol
  3. IRB/Privacy Board documents that waiver criteria are met and makes written determination
  4. IRB/Privacy Board may require alternative protections (such as honest broker protocols)
  5. Waiver is approved or denied with explanation

Privacy Board Composition and Role

A Privacy Board is an entity established by a covered entity to review and approve waiver/alteration of authorization. Membership must include:

Limited Data Set Alternative

Using Limited Data Sets for Research

Rather than obtaining individual authorizations or waiving authorization, researchers may use a limited data set for research purposes if:

Data Use Agreement Requirements

The Data Use Agreement must specify:

Implementation Guidance

For Researchers and Study Coordinators

  1. Determine Authorization Need: Determine whether research requires authorization, waiver, limited data set, or de-identification
  2. Obtain IRB/Privacy Board Approval: Get protocol review and approval before enrolling patients
  3. Obtain Authorization: Obtain informed consent and HIPAA authorization (or waiver) from research participants
  4. Secure PHI: Implement appropriate safeguards protecting research data
  5. Track Authorizations: Maintain records of authorizations and any revocations
  6. Limit Access: Restrict access to only research team members with need to know
  7. De-identify When Possible: Remove identifiers from analysis datasets when not necessary for research

For Healthcare Organizations Housing Research Data

Authorization Documentation

Maintain comprehensive records of research authorizations:

Frequently Asked Questions

Can a general research authorization cover multiple studies?

Potentially, but each research use must be specifically described in the authorization. You could have a broad research authorization authorizing use of PHI for "all research conducted by [Institution]" but this is less specific than HIPAA requires. Best practice is to obtain separate authorizations for specific research studies or obtain a broad authorization that describes the types of research that will be conducted. If you later want to use the PHI for a research purpose not described in the original authorization, you should obtain a new authorization from the patient or seek a waiver/alteration from the IRB or Privacy Board.

What happens if a patient revokes their research authorization?

Once a patient revokes authorization in writing, you must: (1) Stop using the patient's PHI for research purposes going forward, (2) Not use any PHI collected after the revocation date, (3) Remove the patient from the research study (no further data collection), and (4) Notify the research team of the revocation. However, PHI already collected and used before revocation remains usable under the authorization that was valid at the time of collection. Many research protocols include language explaining this to participants. If a large number of participants revoke authorization, it may affect the validity of the research, so researchers should consider this possibility when designing studies.

Can we use treatment records for research without new authorization?

No. Authorization is required to use treatment records for research purposes unless: (1) The research uses only de-identified information, (2) An IRB/Privacy Board has waived authorization, or (3) A limited data set with Data Use Agreement is used. Simply because PHI was originally collected for treatment purposes does not mean it can be used for research without proper authorization. The original authorization for treatment does not extend to research uses. However, if research is directly integrated with treatment (e.g., quality improvement study of treatment protocols), authorization requirements may be different, and you should consult with your IRB or Privacy Board.

What are the differences between IRB and Privacy Board reviews?

An IRB reviews research for subject safety, rights, and welfare (Common Rule compliance), while a Privacy Board reviews research for HIPAA privacy compliance. Many institutions use their IRB for both functions, but they are distinct reviews. The IRB focuses on informed consent, risk/benefit analysis, subject protection, and research protocols. A Privacy Board focuses specifically on HIPAA authorization waivers and limited data set uses. Some larger institutions have separate Privacy Boards, while others combine these functions in a single IRB. For HIPAA authorization waivers, at least one Privacy Board member or IRB member must review the HIPAA-specific aspects of the waiver request.

Ensure Research Compliance and Patient Protection

Medcurity provides research authorization templates, IRB/Privacy Board documentation tools, and compliance tracking systems for research involving PHI.

Streamline Research Compliance