Skip to main content
v2026.11,610 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.1

Certificate of Confidentiality (CoC)

A Certificate of Confidentiality (CoC) is a federal legal protection, under Section 301(d) of the Public Health Service Act (42 U.S.C. 241(d)) as amended by the 21st Century Cures Act, that shields a researcher from being legally compelled -- by subpoena, court order, or similar legal, administrative, or legislative demand -- to disclose names or other identifying information about research participants. For NIH-funded research collecting or using identifiable, sensitive information, a CoC has attached automatically, as a standing term of the award, since October 1, 2017 (NOT-OD-17-109), replacing the prior application-based system under which investigators had to request a certificate for each project. A CoC does not de-identify or otherwise secure the underlying data -- it is a legal shield against compelled disclosure through legal process, not a data-security or data-masking control, and it does not protect against every disclosure (recognized exceptions include participant consent, certain legally mandated reporting, and DHHS or FDA regulatory access).

ByCASRAI Editorial Board
· Last updated 16 Aug 2026

Ask about Certificate of Confidentiality (CoC)

Answers are drawn from this dictionary entry and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Examples

Worked examples

  • Is an instance

    An NIH-funded longitudinal study collecting identifiable data on illicit substance use is automatically covered by a CoC as of its NIH funding start date; if a state prosecutor later subpoenas the study's records seeking a participant's identity, the CoC allows the research team to decline to produce that identifying information in response to the subpoena.

  • Is an instance

    A clinical trial funded by an NIH cooperative agreement collects individual-level human genomic data alongside identifiable clinical information. Under NIH's Genomic Data Sharing policy, the individual-level genomic data is treated as covered information regardless of whether it is independently identifiable, and the trial's automatic CoC protection extends to it on the same basis as the rest of the study's identifiable, sensitive data.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A university-funded (not NIH-funded) pilot survey on student study habits, using fully de-identified, non-sensitive responses with no link back to any individual, is not covered by NIH's automatic-issuance policy -- it is neither NIH-funded nor collecting identifiable, sensitive information, so no CoC attaches automatically.

Editorial commentary

A Certificate of Confidentiality (CoC) is a federal legal protection, issued under Section 301(d) of the Public Health Service Act (42 U.S.C. § 241(d)), that shields researchers from being legally compelled — by subpoena, court order, or other legal, administrative, or legislative demand — to disclose names or other identifying information about the people who participate in their research. For research funded in whole or in part by NIH, the protection has applied automatically, as a term and condition of the award, since October 1, 2017. A researcher does not apply for it, and no separate certificate document is issued; if the research is in scope, the protection already attaches.

What a CoC actually protects against

A CoC’s function is narrow and specific: it prevents a CoC holder from being forced to name a research participant, or to disclose identifiable, sensitive information about one, in response to a legal demand for that information — a subpoena in a civil or criminal case, a court order, or a comparable legislative or administrative proceeding. Under the statute, covered information is immune from legal process and cannot, without the individual’s consent, be admitted as evidence or used for any purpose in any judicial, legislative, or administrative proceeding. “Covered information” reaches beyond directly identifying data (name, address, Social Security number) to anything that carries at least a small risk of re-identification when combined with other available information — and, for genomic research, individual-level human genomic data is covered regardless of whether it is otherwise identifiable.

The protection is not absolute, and researchers cannot rely on it to withhold data in every circumstance. Recognized exceptions include: disclosures required by federal, state, or local law (for example, mandatory reporting of child abuse or certain communicable diseases); disclosure the research participant has consented to in writing; disclosure necessary for a U.S. Department of Health and Human Services audit or program evaluation; and disclosure required for FDA regulatory purposes where the research is FDA-regulated. Because these exceptions exist, NIH requires that informed consent documents for CoC-covered research describe both what the certificate protects and what it does not — a CoC is not a promise of absolute confidentiality, and consent language should not describe it as one.

What changed in 2017: automatic issuance

Before December 13, 2016, obtaining a CoC required an affirmative application: an investigator (or the NIH awarding Institute or Center, on the investigator’s behalf) had to request a certificate for a specific project, and NIH issued it as a separate document if approved. Section 2012 of the 21st Century Cures Act (Public Law 114-255), enacted December 13, 2016, amended Section 301(d) of the Public Health Service Act and directed the Secretary of Health and Human Services to issue certificates for research described in the statute, rather than leaving issuance discretionary and application-driven.

NIH implemented that mandate through NOT-OD-17-109, effective October 1, 2017: NIH-funded research that was ongoing on or after December 13, 2016, and that falls within the policy’s scope, is automatically deemed to have been issued a CoC. Because issuance is automatic and statutory rather than discretionary, no separate certificate document is produced for NIH awards covered by the policy — the protection is simply a standing term of the award, referenced by the applicable Notice of Award language rather than a standalone certificate a researcher files away. Other HHS agencies that fund human-subjects research — including CDC, HRSA, FDA, and BARDA — have since adopted comparable automatic-issuance policies of their own, each with its own effective date and scope; a researcher funded by one of these agencies should confirm which specific agency policy and effective date applies rather than assuming the NIH policy’s October 2017 date governs.

Which research is in scope

Under NIH’s policy, automatic issuance applies to NIH-funded research (grants, cooperative agreements, and NIH-conducted intramural research) that collects or uses identifiable, sensitive information — broadly, information through which an individual research participant is identified or identifiable, and where disclosure could reasonably lead to damage to the participant’s financial standing, employability, insurability, reputation, or could be stigmatizing or lead to criminal or civil liability. This commonly includes clinical and behavioral research on sensitive topics, research involving illegal conduct, substance use, sexual behavior or orientation, mental health, genetic information, and similarly sensitive human-subjects data. It also covers identifiable biospecimens and, per NIH’s Genomic Data Sharing framework, individual-level human genomic data specifically.

Whether a given project’s data actually meets this threshold, and what the resulting informed consent language should say, is an assessment the Institutional Review Board (IRB) makes during protocol review, not something a researcher self-certifies. For research that is not NIH-funded but still involves sensitive, identifiable human-subjects data, a CoC can still be requested from NIH under a separate, non-automatic application process — the automatic-issuance policy only covers research NIH itself funds.

CoC vs. de-identification: a legal shield, not a data-security control

A CoC is frequently confused with, or assumed to substitute for, technical de-identification — removing or masking identifiers so a dataset itself no longer points to a specific person. The two operate on entirely different axes. De-identification is a property of the data: it changes what the dataset contains and how re-identifiable it is, and it is typically what a data-security or data-sharing plan actually implements (encryption, access controls, HIPAA Safe Harbor or Expert Determination methods, and similar technical/administrative measures). A CoC does none of that. The data itself can remain fully identifiable; what a CoC does is create a legal barrier against a court, prosecutor, or other party compelling the researcher to hand that identifiable data over through legal process. A well-de-identified dataset reduces re-identification risk generally, including from parties with no legal subpoena power at all; a CoC does nothing if data is never legally demanded, and offers no protection at all against, say, a data breach or an insider disclosure outside a legal proceeding. The strongest privacy posture for sensitive human-subjects research typically uses both: technical de-identification or access controls to limit exposure generally, and a CoC (where the research qualifies) as a backstop against compelled legal disclosure of whatever identifiable information remains.

CoC vs. a data use agreement

A CoC is also distinct from a data use agreement (DUA). A DUA is a contract between institutions (or between a data provider and a recipient) that sets the negotiated terms under which a specific dataset may be accessed, used, and re-shared — permitted uses, security requirements, publication rights, and what happens to the data at the end of the agreement. A CoC is not a contract at all; it is a statutory protection that attaches automatically to qualifying NIH-funded research and applies regardless of how many institutions are involved or what any data-sharing contract between them says. A DUA cannot substitute for a CoC’s legal-process protection, and a CoC does not remove the need for a DUA when data is genuinely being transferred between institutions — the two commonly apply to the same project simultaneously, addressing different risks.

CoC and informed consent

Because a CoC’s protections and its exceptions both directly affect what a research participant should understand before enrolling, NIH expects CoC-covered research to describe the certificate in the study’s informed consent process, using consent language that states plainly what the certificate protects against (compelled legal disclosure of identifying information) and what it does not cover (the recognized exceptions above, and the fact that the researcher may still make certain disclosures the participant has agreed to in writing). This sits within the IRB’s broader review of the consent form under the human-subjects protections framework at 45 CFR 46 (the Common Rule) — see CASRAI’s guide to the informed consent process for how CoC disclosure fits alongside the other required elements of consent, and CASRAI’s guide to the IRB/REC approval process for where CoC applicability gets assessed during protocol review.

What a CoC protects, and what it does not

Researchers most often misunderstand a CoC by treating it as a general confidentiality guarantee. It is narrower than that, and the gap between what it covers and what it does not is exactly what an informed consent form needs to explain. The table below summarizes the distinction.

Protected against NOT protected against
A subpoena issued in a civil, criminal, or administrative case seeking a participant’s identity or identifying information Voluntary disclosure by the researcher — for example, reporting a finding the participant separately agreed to in writing
A court order compelling production of identifiable research records Mandatory state or local reporting laws, such as child abuse/neglect reporting or reportable communicable diseases
Use of covered information as evidence, or for any purpose, in a judicial, legislative, or administrative proceeding, without the participant’s consent An FDA inspection or other FDA regulatory action, where the research is FDA-regulated
Legislative demands (e.g., a subpoena from a legislative body) for identifying information A U.S. Department of Health and Human Services audit or program evaluation of the research
Re-identification risk from indirectly identifying data, and individual-level human genomic data specifically The participant’s own request that their identifying information be disclosed, or a request from someone the participant has authorized
Disclosure sought through legal process regardless of who currently holds a copy of the covered information Data breaches, hacking, or insider disclosure outside any legal proceeding — a CoC is a legal shield, not a data-security control

Documentation, duration, and what happens if NIH funding lapses

Because issuance is automatic, NIH does not produce a physical certificate document for NIH-funded research. The protection is documented instead through the NIH CoC Policy itself, the award’s Notice of Award, the NIH Grants Policy Statement (for grants and cooperative agreements), and the NIH Division of Grants Statement Contract Handbook’s special contract requirements (for NIH-funded contracts). An institution or investigator confirming that a specific project is covered points to these documents, not to a separate certificate on file.

CoC protection does not need to be extended or renewed while NIH funding continues; it applies automatically as a standing term of the award for the life of the project, including during an approved no-cost extension. Two duration points matter operationally:

  • All identifiable, sensitive information already collected or used under a covered project is protected in perpetuity, and that permanent protection extends to every copy of that information, wherever it subsequently resides.
  • If NIH funding lapses or ends, the study is no longer automatically deemed to have a CoC going forward. Already-collected data keeps its permanent protection, but any new data collected from already-enrolled or new participants after funding ends is not automatically covered — a new CoC would need to be obtained (through NIH’s separate, non-automatic application process) to cover it, unless enrollment and data collection were already complete when funding ended.

Flow-down: collaborators, subrecipients, and multi-site studies

A CoC attaches to the covered research and its data, not to a single individual’s employment status or institutional affiliation. Because protection extends to all copies of covered information wherever they reside, a subrecipient institution, a collaborating investigator at a non-NIH-funded site, or a contractor handling identifiable study data on behalf of the award is working with data the CoC already covers — they do not need to separately request their own certificate for that same project’s data. In practice, this makes flow-down a subaward-agreement and training issue rather than a second application: the lead institution should make sure every subrecipient, collaborating site, and data-handling contractor understands (a) that the data is CoC-covered, (b) what disclosures the CoC does and does not permit, and (c) that the recognized exceptions above apply the same way regardless of which site or individual currently holds the data. This is typically documented in the subaward agreement or data use agreement governing the collaboration, alongside — not instead of — the CoC protection itself. A collaborating site that is conducting genuinely separate, non-NIH-funded research using its own independently collected data, rather than working with the NIH award’s covered data, is a different case, and would need to evaluate on its own whether it needs to request a CoC under the non-automatic process described below.

CoCs outside NIH: other agencies and non-NIH-funded research

NIH’s automatic-issuance policy under NOT-OD-17-109 governs NIH-funded research specifically. Other HHS agencies that fund human-subjects research — including the CDC, HRSA, FDA, and BARDA — have adopted their own comparable automatic-issuance CoC policies, each with a separate policy document and effective date (BARDA’s, for example, took effect July 17, 2023 under BARDA-CoC-001-2023). A researcher funded by one of these agencies should confirm the specific policy and effective date that agency has published rather than assuming NIH’s October 2017 date applies across HHS.

For research that is not funded by any agency with an automatic-issuance policy — including privately funded, foundation-funded, or university-funded human-subjects research collecting identifiable, sensitive information — a CoC can still be requested from NIH under a separate, non-automatic application process, submitted through NIH’s online CoC request system. NIH reviews these requests against the same substantive standard (identifiable, sensitive human-subjects data) used to determine automatic coverage for NIH-funded projects; approval is not guaranteed and is not automatic simply because the researcher applies.

What the informed consent form should say

NIH does not prescribe one mandatory sentence, but it does require CoC-covered research’s informed consent process to describe, in language a participant can understand, both what the certificate protects against and what it does not. An IRB reviewing a CoC-covered protocol’s consent form is checking for coverage of these elements, at minimum:

  • That a Certificate of Confidentiality is in effect, and what it protects (compelled disclosure of identifying information through legal process).
  • That the certificate does not prevent the participant’s own voluntary disclosure of their involvement or the study’s results, if they choose to share it.
  • The recognized exceptions that apply — mandatory reporting laws, DHHS audit/evaluation, FDA regulatory access where applicable, and disclosure the participant has separately consented to in writing.
  • That the certificate is not a promise of absolute confidentiality, and should not be described to participants as one.

Illustrative example (composite consent language demonstrating these required elements, not an official NIH-issued or verbatim required text — institutions should use their own IRB-approved consent template language):

“To help protect your privacy, this research is covered by a Certificate of Confidentiality issued under federal law. The researchers cannot be forced to disclose information that could identify you as a research participant in any court, legislative, or administrative proceeding, even in response to a subpoena, unless you consent. The Certificate does not stop you from voluntarily sharing information about yourself or your participation. It also does not prevent disclosure required by law, such as reporting of child abuse or certain communicable diseases, or disclosure needed for a federal government audit or FDA oversight of this research.”

Last verified: August 16, 2026, against NIH NOT-OD-17-109, the NIH Office of Science Policy Certificates of Confidentiality guidance (grants.nih.gov), and the underlying statute, 42 U.S.C. § 241(d) as amended by Section 2012 of the 21st Century Cures Act.

Worked examples

  • An NIH-funded longitudinal study collecting identifiable data on illicit substance use is automatically covered by a CoC as of its NIH funding start date (assuming the research was ongoing on or after December 13, 2016). If a state prosecutor later subpoenas the study’s records seeking a participant’s identity in connection with a criminal case, the CoC allows the research team to decline to produce identifying information in response to that subpoena.
  • A clinical trial funded by an NIH cooperative agreement collects individual-level genomic data alongside identifiable clinical information. Under NIH’s Genomic Data Sharing policy, the individual-level genomic data is treated as covered information regardless of whether it is independently identifiable, and the trial’s CoC protection extends to it on the same automatic basis as the rest of the study’s identifiable, sensitive data.

Counter-example

A university-funded (not NIH-funded) pilot survey on student study habits, using fully de-identified, non-sensitive responses with no link back to any individual, is not the kind of research NIH’s automatic-issuance policy covers — it is neither NIH-funded nor collecting identifiable, sensitive information. No CoC attaches automatically, and because the data carries no meaningful re-identification or legal-jeopardy risk, a researcher in this situation would have little practical reason to seek one even under the separate, non-automatic application process available for non-NIH-funded research.

References

  • 21st Century Cures Act, Section 2012, Public Law 114-255 (December 13, 2016) — amended Section 301(d) of the Public Health Service Act.
  • Public Health Service Act § 301(d), 42 U.S.C. § 241(d) — the statutory basis for Certificates of Confidentiality.
  • NIH, NOT-OD-17-109, “Notice of Changes to NIH Policy for Issuing Certificates of Confidentiality” — establishes automatic issuance effective October 1, 2017.
  • NIH Office of Science Policy, “Certificates of Confidentiality for NIH-Funded Research” — grants.nih.gov.
  • HHS Office for Human Research Protections (OHRP), “Certificates of Confidentiality” guidance — hhs.gov.

Frequently Asked Questions

Do collaborators or subrecipients need their own Certificate of Confidentiality?

No, not for the same project’s covered data. A CoC attaches to the covered research and extends to all copies of the covered information regardless of who holds them, so a subrecipient institution, collaborating investigator, or contractor working with that project’s data is already working with CoC-covered information. The lead institution’s subaward agreement or data use agreement should make the collaborators aware of the CoC and its limits; a genuinely separate, non-NIH-funded study using independently collected data is a different case and would need its own eligibility assessment.

Do agencies other than NIH issue Certificates of Confidentiality?

Yes. Other HHS agencies that fund human-subjects research, including CDC, HRSA, FDA, and BARDA, have adopted their own comparable automatic-issuance policies, each with its own effective date — a researcher should confirm the specific agency policy that applies rather than assuming NIH’s October 2017 date governs. For research funded by an agency without such a policy, or funded outside HHS entirely, a CoC can still be requested from NIH under a separate, non-automatic application process.

What does a Certificate of Confidentiality protect against?

A CoC prevents a researcher from being legally compelled — by subpoena, court order, or a similar legal, administrative, or legislative demand — to disclose the identity or other identifying, sensitive information of a research participant. Covered information cannot, without the participant’s consent, be used as evidence or for any purpose in a judicial, legislative, or administrative proceeding. It reaches beyond directly identifying data such as a name or Social Security number to any information carrying at least a small re-identification risk, and it covers individual-level human genomic data outright.

Do researchers need to apply for a Certificate of Confidentiality?

For NIH-funded research, no. Since October 1, 2017, the protection has applied automatically as a term and condition of the award to research that falls within the policy’s scope, and no separate certificate document is issued. Before that date, researchers had to submit an affirmative application for a CoC; for research that is not NIH-funded, a CoC can still be requested from NIH under that separate, non-automatic application process.

Is a Certificate of Confidentiality the same as de-identifying research data?

No. De-identification changes what a dataset contains, removing or masking identifiers so the data itself no longer points to a specific person. A CoC does not alter the data at all — it can remain fully identifiable — and instead creates a legal barrier preventing a court or other party from compelling the researcher to hand that identifiable data over through legal process.

Is a Certificate of Confidentiality the same as a data use agreement?

No. A data use agreement (DUA) is a contract between institutions that sets negotiated terms for accessing, using, and re-sharing a specific dataset. A CoC is not a contract; it is a statutory protection that attaches automatically to qualifying NIH-funded research regardless of any DUA between the institutions involved. The two commonly apply to the same project at once, addressing different risks.

Are there exceptions to what a Certificate of Confidentiality protects?

Yes. Recognized exceptions include disclosures required by federal, state, or local law (such as mandatory reporting of child abuse or certain communicable diseases), disclosure the participant has consented to in writing, disclosure needed for a U.S. Department of Health and Human Services audit or program evaluation, and disclosure required for FDA regulatory purposes in FDA-regulated research. Because of these exceptions, informed consent documents for CoC-covered research must describe both what the certificate protects and what it does not.

Does a Certificate of Confidentiality apply automatically to every NIH-funded study?

No — only to NIH-funded research that collects or uses identifiable, sensitive information, where disclosure could reasonably damage a participant’s financial standing, employability, insurability, or reputation, or lead to stigma or criminal or civil liability. Whether a specific project meets that threshold is assessed by the Institutional Review Board (IRB) during protocol review, not self-certified by the researcher.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Certificate of Confidentiality (CoC)"
      vocab-term-identifier="https://casrai.org/dictionary/term/certificate-of-confidentiality-coc" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/certificate-of-confidentiality-coc",
  "name": "Certificate of Confidentiality (CoC)",
  "identifier": "https://casrai.org/dictionary/term/certificate-of-confidentiality-coc",
  "description": "A Certificate of Confidentiality (CoC) is a federal legal protection, under Section 301(d) of the Public Health Service Act (42 U.S.C. 241(d)) as amended by the 21st Century Cures Act, that shields a researcher from being legally compelled -- by subpoena, court order, or similar legal, administrative, or legislative demand -- to disclose names or other identifying information about research participants. For NIH-funded research collecting or using identifiable, sensitive information, a CoC has attached automatically, as a standing term of the award, since October 1, 2017 (NOT-OD-17-109), replacing the prior application-based system under which investigators had to request a certificate for each project. A CoC does not de-identify or otherwise secure the underlying data -- it is a legal shield against compelled disclosure through legal process, not a data-security or data-masking control, and it does not protect against every disclosure (recognized exceptions include participant consent, certain legally mandated reporting, and DHHS or FDA regulatory access).",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/certificate-of-confidentiality-coc",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-08-16T23:18:46",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →