Examples
Worked examples
- Is an instance
An NIH-funded longitudinal study collecting identifiable data on illicit substance use is automatically covered by a CoC as of its NIH funding start date; if a state prosecutor later subpoenas the study's records seeking a participant's identity, the CoC allows the research team to decline to produce that identifying information in response to the subpoena.
- Is an instance
A clinical trial funded by an NIH cooperative agreement collects individual-level human genomic data alongside identifiable clinical information. Under NIH's Genomic Data Sharing policy, the individual-level genomic data is treated as covered information regardless of whether it is independently identifiable, and the trial's automatic CoC protection extends to it on the same basis as the rest of the study's identifiable, sensitive data.
Counter-examples
Looks similar, but isn't
- Not an instance
A university-funded (not NIH-funded) pilot survey on student study habits, using fully de-identified, non-sensitive responses with no link back to any individual, is not covered by NIH's automatic-issuance policy -- it is neither NIH-funded nor collecting identifiable, sensitive information, so no CoC attaches automatically.
Editorial commentary
A Certificate of Confidentiality (CoC) is a federal legal protection, issued under Section 301(d) of the Public Health Service Act (42 U.S.C. § 241(d)), that shields researchers from being legally compelled — by subpoena, court order, or other legal, administrative, or legislative demand — to disclose names or other identifying information about the people who participate in their research. For research funded in whole or in part by NIH, the protection has applied automatically, as a term and condition of the award, since October 1, 2017. A researcher does not apply for it, and no separate certificate document is issued; if the research is in scope, the protection already attaches.
What a CoC actually protects against
A CoC’s function is narrow and specific: it prevents a CoC holder from being forced to name a research participant, or to disclose identifiable, sensitive information about one, in response to a legal demand for that information — a subpoena in a civil or criminal case, a court order, or a comparable legislative or administrative proceeding. Under the statute, covered information is immune from legal process and cannot, without the individual’s consent, be admitted as evidence or used for any purpose in any judicial, legislative, or administrative proceeding. “Covered information” reaches beyond directly identifying data (name, address, Social Security number) to anything that carries at least a small risk of re-identification when combined with other available information — and, for genomic research, individual-level human genomic data is covered regardless of whether it is otherwise identifiable.
The protection is not absolute, and researchers cannot rely on it to withhold data in every circumstance. Recognized exceptions include: disclosures required by federal, state, or local law (for example, mandatory reporting of child abuse or certain communicable diseases); disclosure the research participant has consented to in writing; disclosure necessary for a U.S. Department of Health and Human Services audit or program evaluation; and disclosure required for FDA regulatory purposes where the research is FDA-regulated. Because these exceptions exist, NIH requires that informed consent documents for CoC-covered research describe both what the certificate protects and what it does not — a CoC is not a promise of absolute confidentiality, and consent language should not describe it as one.
What changed in 2017: automatic issuance
Before December 13, 2016, obtaining a CoC required an affirmative application: an investigator (or the NIH awarding Institute or Center, on the investigator’s behalf) had to request a certificate for a specific project, and NIH issued it as a separate document if approved. Section 2012 of the 21st Century Cures Act (Public Law 114-255), enacted December 13, 2016, amended Section 301(d) of the Public Health Service Act and directed the Secretary of Health and Human Services to issue certificates for research described in the statute, rather than leaving issuance discretionary and application-driven.
NIH implemented that mandate through NOT-OD-17-109, effective October 1, 2017: NIH-funded research that was ongoing on or after December 13, 2016, and that falls within the policy’s scope, is automatically deemed to have been issued a CoC. Because issuance is automatic and statutory rather than discretionary, no separate certificate document is produced for NIH awards covered by the policy — the protection is simply a standing term of the award, referenced by the applicable Notice of Award language rather than a standalone certificate a researcher files away. Other HHS agencies that fund human-subjects research — including CDC, HRSA, FDA, and BARDA — have since adopted comparable automatic-issuance policies of their own, each with its own effective date and scope; a researcher funded by one of these agencies should confirm which specific agency policy and effective date applies rather than assuming the NIH policy’s October 2017 date governs.
Which research is in scope
Under NIH’s policy, automatic issuance applies to NIH-funded research (grants, cooperative agreements, and NIH-conducted intramural research) that collects or uses identifiable, sensitive information — broadly, information through which an individual research participant is identified or identifiable, and where disclosure could reasonably lead to damage to the participant’s financial standing, employability, insurability, reputation, or could be stigmatizing or lead to criminal or civil liability. This commonly includes clinical and behavioral research on sensitive topics, research involving illegal conduct, substance use, sexual behavior or orientation, mental health, genetic information, and similarly sensitive human-subjects data. It also covers identifiable biospecimens and, per NIH’s Genomic Data Sharing framework, individual-level human genomic data specifically.
Whether a given project’s data actually meets this threshold, and what the resulting informed consent language should say, is an assessment the Institutional Review Board (IRB) makes during protocol review, not something a researcher self-certifies. For research that is not NIH-funded but still involves sensitive, identifiable human-subjects data, a CoC can still be requested from NIH under a separate, non-automatic application process — the automatic-issuance policy only covers research NIH itself funds.
CoC vs. de-identification: a legal shield, not a data-security control
A CoC is frequently confused with, or assumed to substitute for, technical de-identification — removing or masking identifiers so a dataset itself no longer points to a specific person. The two operate on entirely different axes. De-identification is a property of the data: it changes what the dataset contains and how re-identifiable it is, and it is typically what a data-security or data-sharing plan actually implements (encryption, access controls, HIPAA Safe Harbor or Expert Determination methods, and similar technical/administrative measures). A CoC does none of that. The data itself can remain fully identifiable; what a CoC does is create a legal barrier against a court, prosecutor, or other party compelling the researcher to hand that identifiable data over through legal process. A well-de-identified dataset reduces re-identification risk generally, including from parties with no legal subpoena power at all; a CoC does nothing if data is never legally demanded, and offers no protection at all against, say, a data breach or an insider disclosure outside a legal proceeding. The strongest privacy posture for sensitive human-subjects research typically uses both: technical de-identification or access controls to limit exposure generally, and a CoC (where the research qualifies) as a backstop against compelled legal disclosure of whatever identifiable information remains.
CoC vs. a data use agreement
A CoC is also distinct from a data use agreement (DUA). A DUA is a contract between institutions (or between a data provider and a recipient) that sets the negotiated terms under which a specific dataset may be accessed, used, and re-shared — permitted uses, security requirements, publication rights, and what happens to the data at the end of the agreement. A CoC is not a contract at all; it is a statutory protection that attaches automatically to qualifying NIH-funded research and applies regardless of how many institutions are involved or what any data-sharing contract between them says. A DUA cannot substitute for a CoC’s legal-process protection, and a CoC does not remove the need for a DUA when data is genuinely being transferred between institutions — the two commonly apply to the same project simultaneously, addressing different risks.
CoC and informed consent
Because a CoC’s protections and its exceptions both directly affect what a research participant should understand before enrolling, NIH expects CoC-covered research to describe the certificate in the study’s informed consent process, using consent language that states plainly what the certificate protects against (compelled legal disclosure of identifying information) and what it does not cover (the recognized exceptions above, and the fact that the researcher may still make certain disclosures the participant has agreed to in writing). This sits within the IRB’s broader review of the consent form under the human-subjects protections framework at 45 CFR 46 (the Common Rule) — see CASRAI’s guide to the informed consent process for how CoC disclosure fits alongside the other required elements of consent, and CASRAI’s guide to the IRB/REC approval process for where CoC applicability gets assessed during protocol review.
Worked examples
- An NIH-funded longitudinal study collecting identifiable data on illicit substance use is automatically covered by a CoC as of its NIH funding start date (assuming the research was ongoing on or after December 13, 2016). If a state prosecutor later subpoenas the study’s records seeking a participant’s identity in connection with a criminal case, the CoC allows the research team to decline to produce identifying information in response to that subpoena.
- A clinical trial funded by an NIH cooperative agreement collects individual-level genomic data alongside identifiable clinical information. Under NIH’s Genomic Data Sharing policy, the individual-level genomic data is treated as covered information regardless of whether it is independently identifiable, and the trial’s CoC protection extends to it on the same automatic basis as the rest of the study’s identifiable, sensitive data.
Counter-example
A university-funded (not NIH-funded) pilot survey on student study habits, using fully de-identified, non-sensitive responses with no link back to any individual, is not the kind of research NIH’s automatic-issuance policy covers — it is neither NIH-funded nor collecting identifiable, sensitive information. No CoC attaches automatically, and because the data carries no meaningful re-identification or legal-jeopardy risk, a researcher in this situation would have little practical reason to seek one even under the separate, non-automatic application process available for non-NIH-funded research.
References
- 21st Century Cures Act, Section 2012, Public Law 114-255 (December 13, 2016) — amended Section 301(d) of the Public Health Service Act.
- Public Health Service Act § 301(d), 42 U.S.C. § 241(d) — the statutory basis for Certificates of Confidentiality.
- NIH, NOT-OD-17-109, “Notice of Changes to NIH Policy for Issuing Certificates of Confidentiality” — establishes automatic issuance effective October 1, 2017.
- NIH Office of Science Policy, “Certificates of Confidentiality for NIH-Funded Research” — grants.nih.gov.
- HHS Office for Human Research Protections (OHRP), “Certificates of Confidentiality” guidance — hhs.gov.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Certificate of Confidentiality (CoC)"
vocab-term-identifier="https://casrai.org/dictionary/term/certificate-of-confidentiality-coc" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/certificate-of-confidentiality-coc",
"name": "Certificate of Confidentiality (CoC)",
"identifier": "https://casrai.org/dictionary/term/certificate-of-confidentiality-coc",
"description": "A Certificate of Confidentiality (CoC) is a federal legal protection, under Section 301(d) of the Public Health Service Act (42 U.S.C. 241(d)) as amended by the 21st Century Cures Act, that shields a researcher from being legally compelled -- by subpoena, court order, or similar legal, administrative, or legislative demand -- to disclose names or other identifying information about research participants. For NIH-funded research collecting or using identifiable, sensitive information, a CoC has attached automatically, as a standing term of the award, since October 1, 2017 (NOT-OD-17-109), replacing the prior application-based system under which investigators had to request a certificate for each project. A CoC does not de-identify or otherwise secure the underlying data -- it is a legal shield against compelled disclosure through legal process, not a data-security or data-masking control, and it does not protect against every disclosure (recognized exceptions include participant consent, certain legally mandated reporting, and DHHS or FDA regulatory access).",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/certificate-of-confidentiality-coc",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-17T09:59:47",
"inLanguage": "en"
}






