Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthWholesale & Retail Medical SupplyMedical supplies, delivered.79,000+ SKUs. Ships in 48h from 8 U.S. hubs. Net-30 for verified accounts.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

HIPAA in Clinical Research

A research activity falls under 'HIPAA in clinical research' when a HIPAA covered entity (or its business associate) creates, uses, or discloses protected health information (PHI) in connection with a systematic investigation designed to develop or contribute to generalizable knowledge (45 CFR 164.501). Because research is not treatment, payment, or health care operations, the Privacy Rule's general TPO permissions do not apply -- a covered entity may use or disclose PHI for research only through one of the pathways the Rule specifically authorizes: (1) a subject-signed Authorization meeting the core-element and required-statement standards of 45 CFR 164.508; (2) an IRB- or Privacy Board-granted waiver or alteration of Authorization under 45 CFR 164.512(i), documented against the Rule's minimal-risk criteria; (3) disclosure as a Limited Data Set under a Data Use Agreement (45 CFR 164.514(e)); (4) de-identification under the Safe Harbor or Expert Determination method (45 CFR 164.514(a)-(b)), which removes the data from HIPAA's scope entirely; or (5) narrower exceptions for reviews preparatory to research and for research on a decedent's information (both at 45 CFR 164.512(i)(1)). HIPAA governs this data-privacy layer only -- it is a separate federal regulatory regime from the Common Rule (45 CFR 46) and FDA human-subjects regulations that govern the ethical conduct of the research itself (IRB review, informed consent to participate). A single study involving PHI at a covered entity typically must satisfy both regimes concurrently, through separate, though often procedurally combined, analyses and documents.

ByCASRAI Editorial Board
· Last updated 17 Jul 2026

Examples

Worked examples

  • Is an instance

    A pharmaceutical sponsor's trial uses a combined Informed Consent/HIPAA Authorization form. The Authorization section satisfies 45 CFR 164.508's core elements (what PHI, who may use/disclose it, purpose, and 'end of the research study' as the expiration event) so the site, sponsor, CRO, and central lab may use and share the participant's PHI as described -- a separate legal analysis from whether the same participant has given valid Common Rule informed consent to enroll.

  • Is an instance

    An oncology department wants to review its own patients' EHR records to identify candidates for a retrospective chemotherapy-outcomes chart review. Because obtaining individual Authorization from every eligible patient is impracticable, the investigator requests an IRB-approved waiver of Authorization under 45 CFR 164.512(i), documented separately from the IRB's own Common Rule waiver-of-consent finding under 45 CFR 46.116(f).

Counter-examples

Looks similar, but isn't

  • Not an instance

    A university's anonymous online survey of student volunteers about study habits collects no health information and never touches data held by a covered entity. It is Common Rule human-subjects research requiring IRB review, but HIPAA's research provisions never engage -- there is no covered entity and no PHI in the data flow, so 164.508/164.512(i)/164.514 are simply not in play.

Editorial commentary

HIPAA in clinical research refers to the set of Privacy Rule provisions that specifically govern how a covered entity may use or disclose protected health information (PHI) for research, as distinct from its everyday use of PHI for treatment, payment, and health care operations. Because research is not one of those three permitted purposes, the Privacy Rule requires a covered entity to route any research use or disclosure of PHI through one of five specific pathways — and, critically, doing so satisfies HIPAA only. A study that also meets the federal definition of human subjects research must separately satisfy the Common Rule (45 CFR 46) and IRB review. The two regimes frequently apply to the very same study, are administered by different offices under different legal authority, and are not substitutes for one another.

Two distinct compliance regimes, often applied to the same study

It is a common misconception among new investigators that “IRB approval” and “HIPAA compliance” are the same checkbox. They are not:

  • The Common Rule (45 CFR 46, and the parallel FDA human-subjects regulations at 21 CFR 50/56 for FDA-regulated research) governs the ethics of involving human beings in research: IRB review of risks and benefits, and informed consent to participate.
  • HIPAA’s Privacy Rule (45 CFR Part 164, Subpart E) governs the privacy and security of health data held by a covered entity (a health plan, health care clearinghouse, or health care provider that transmits health information electronically in connection with a covered transaction) or its business associates — regardless of whether the person whose data it is has agreed to anything about a study’s design.

A hospital-based clinical trial or a retrospective chart review at an academic medical center is almost always subject to both regimes at once: the Common Rule/IRB analysis asks whether it is ethical and adequately consented human-subjects research; the HIPAA analysis, run separately, asks whether the specific use or disclosure of PHI that the study requires is one the Privacy Rule permits. In practice, institutions often combine the paperwork — a single “Informed Consent and HIPAA Authorization” form is common — but the two sets of legal requirements underneath that one document remain distinct, are evaluated against different regulatory criteria, and can diverge (for example, a study can obtain a Common Rule waiver of consent while still needing a separate HIPAA waiver of authorization, or vice versa, since the waiver criteria under 45 CFR 46.116(f) and 45 CFR 164.512(i) are not identical).

The default rule: PHI for research requires one of five pathways

Per HHS Office for Civil Rights guidance, a covered entity may use or disclose PHI for a research purpose only via one of the following:

1. Authorization (45 CFR 164.508)

A study-specific, signed Authorization is the default pathway. To be valid for research use, it must include the Rule’s core elements: a specific and meaningful description of the PHI to be used or disclosed, who may make the disclosure, to whom, the purpose, an expiration date or event (“end of the research study” is an acceptable event for research, including for a research database or repository), and the individual’s signature and date — plus required statements putting the individual on notice of their right to revoke the Authorization in writing, and of certain redisclosure risks. A defective Authorization (missing a core element, or improperly combined with other document types in ways the Rule restricts) is not valid, regardless of what the informed-consent portion of the same form says.

2. Waiver or alteration of Authorization (45 CFR 164.512(i))

Where obtaining individual Authorization is impracticable — most commonly for retrospective records-based research, or when a study is still in a recruitment-screening phase — an IRB or a separately constituted Privacy Board may grant a full or partial waiver. The Rule requires the Board to document that the waiver satisfies specific criteria, including: the use or disclosure involves no more than minimal privacy risk, based on (i) an adequate plan to protect identifiers from improper use or disclosure, (ii) an adequate plan to destroy identifiers at the earliest opportunity consistent with the research (absent a health or legal justification to retain them), and (iii) written assurances the PHI will not be reused or redisclosed except as permitted; that the research could not practicably be conducted without the waiver; and that it could not practicably be conducted without access to the PHI itself. A Privacy Board is a HIPAA-specific body — an institution may use its existing IRB in that role, or convene a separate Privacy Board, but either way the waiver documentation must independently satisfy 164.512(i), not merely restate an IRB’s Common Rule consent-waiver finding.

3. Limited Data Set with a Data Use Agreement (45 CFR 164.514(e))

A covered entity may disclose a Limited Data Set — PHI with direct identifiers (like name, street address, and Social Security number) removed but some indirect identifiers (like dates and geographic subdivisions larger than street address) retained — for research without Authorization or a waiver, provided the recipient signs a Data Use Agreement restricting how the data may be used, who may access it, and prohibiting re-identification or further disclosure. This pathway is common for multi-site registries and secondary-analysis datasets.

4. De-identification (45 CFR 164.514(a)-(b)): Safe Harbor vs. Expert Determination

Information that has been properly de-identified is no longer PHI and falls outside HIPAA’s scope entirely (though it may still be within the scope of the Common Rule, or of other research-ethics or data-governance requirements, if it is linked to an ongoing human-subjects study). The Privacy Rule recognizes two de-identification methods:

  • Safe Harbor — a checklist method: removing all 18 identifier categories enumerated at 45 CFR 164.514(b)(2) (names, geographic subdivisions smaller than a state, all elements of dates except year, telephone/fax numbers, email addresses, Social Security numbers, medical record numbers, biometric identifiers, full-face photos, and others), with no actual knowledge that the remaining information could be used to re-identify the individual.
  • Expert Determination — a statistical method: a person with appropriate knowledge of and experience with generally accepted statistical and scientific methods applies those methods to determine that the risk of re-identification is very small, and documents the analysis and methods used to reach that conclusion. This route is used when a dataset needs to retain more granular fields (e.g., exact dates, finer geography) than Safe Harbor would allow.

5. Narrower exceptions: preparatory-to-research review and decedent research

The Rule also permits a covered entity’s workforce to review PHI on-site, without Authorization or a waiver, solely to prepare a research protocol or for similar preparatory purposes (e.g., assessing feasibility or recruitment potential), provided no PHI leaves the covered entity and the review is represented as necessary for the research. A separate provision permits use or disclosure of a deceased individual’s PHI for research, provided the covered entity obtains representation that the use is solely for research on the decedent’s information.

Worked examples

Authorization pathway. A pharmaceutical sponsor’s clinical trial protocol uses a combined Informed Consent/HIPAA Authorization form. The Authorization section satisfies 45 CFR 164.508’s core elements — what PHI, who may use or disclose it, the purpose, and “end of the research study” as the expiration event — so the site, the sponsor, the CRO, and the central lab can use and share the participant’s PHI exactly as described. That Authorization analysis is entirely separate from whether the same participant has given valid Common Rule informed consent to be enrolled in the trial; both are required, and both are documented in the same form for participant convenience only.

Waiver pathway. An oncology department wants to review its own patients’ electronic health records to identify candidates for a retrospective chart-review study of chemotherapy outcomes. Because this uses PHI held by the hospital (a covered entity) for a research purpose, and obtaining individual Authorization from every eligible patient is impracticable, the investigator requests an IRB-approved waiver of Authorization under 45 CFR 164.512(i) — documented separately from, though often alongside, the IRB’s own Common Rule waiver-of-consent determination under 45 CFR 46.116(f).

No HIPAA at all. A university runs an anonymous online survey of undergraduate volunteers about study habits, collecting no health information and never touching data held by a covered entity. This is Common Rule human-subjects research requiring IRB review, but HIPAA’s research provisions never engage — there is no covered entity and no PHI anywhere in the data flow, so 164.508/164.512(i)/164.514 are simply not in play.

Frequently asked questions

Does a signed HIPAA Authorization also satisfy Common Rule informed consent?

No. They are legally distinct requirements evaluated against different regulatory criteria, even when combined into a single participant-facing document. A form can be valid under one framework and defective under the other.

Who can grant a waiver of HIPAA authorization — does it have to be the IRB?

Either an IRB or a separately constituted Privacy Board can grant it under 45 CFR 164.512(i); most institutions use the existing IRB in that role rather than standing up a separate Privacy Board, but the waiver documentation must independently address HIPAA’s minimal-risk criteria, not just restate a Common Rule consent-waiver finding.

Is de-identified data still regulated by HIPAA?

No — data that meets the Safe Harbor or Expert Determination standard is no longer PHI and falls outside the Privacy Rule. It may still be subject to the Common Rule or an institution’s own data-governance policy if it remains linked to an active human-subjects study.

Does a Limited Data Set need an Authorization or a waiver?

No, but the recipient must sign a Data Use Agreement under 45 CFR 164.514(e) restricting further use, access, and redisclosure, and prohibiting attempts to re-identify the data.

How does this differ from GDPR for research involving EU participants?

HIPAA and the EU’s GDPR are separate legal regimes with different scope, permitted-purpose logic, and enforcement mechanisms; a study spanning both jurisdictions typically needs a HIPAA analysis for any US covered-entity PHI and a separate GDPR lawful-basis analysis for EU personal data — see CASRAI’s GDPR and data protection compliance in research guide for that framework.

Related CASRAI resources

References

  • 45 CFR 164.508 — Uses and disclosures for which an authorization is required
  • 45 CFR 164.512(i) — Uses and disclosures for which an authorization or opportunity to agree or object is not required: research purposes
  • 45 CFR 164.514(a)-(b) — De-identification of protected health information (Safe Harbor and Expert Determination)
  • 45 CFR 164.514(e) — Limited data set
  • 45 CFR 46 (the Common Rule) — Federal Policy for the Protection of Human Subjects
  • HHS Office for Civil Rights, “Research” guidance, 45 CFR 164.501, 164.508, 164.512(i)
  • HHS, “Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with HIPAA”

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="HIPAA in Clinical Research"
      vocab-term-identifier="https://casrai.org/dictionary/term/hipaa-in-clinical-research" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/hipaa-in-clinical-research",
  "name": "HIPAA in Clinical Research",
  "identifier": "https://casrai.org/dictionary/term/hipaa-in-clinical-research",
  "description": "A research activity falls under 'HIPAA in clinical research' when a HIPAA covered entity (or its business associate) creates, uses, or discloses protected health information (PHI) in connection with a systematic investigation designed to develop or contribute to generalizable knowledge (45 CFR 164.501). Because research is not treatment, payment, or health care operations, the Privacy Rule's general TPO permissions do not apply -- a covered entity may use or disclose PHI for research only through one of the pathways the Rule specifically authorizes: (1) a subject-signed Authorization meeting the core-element and required-statement standards of 45 CFR 164.508; (2) an IRB- or Privacy Board-granted waiver or alteration of Authorization under 45 CFR 164.512(i), documented against the Rule's minimal-risk criteria; (3) disclosure as a Limited Data Set under a Data Use Agreement (45 CFR 164.514(e)); (4) de-identification under the Safe Harbor or Expert Determination method (45 CFR 164.514(a)-(b)), which removes the data from HIPAA's scope entirely; or (5) narrower exceptions for reviews preparatory to research and for research on a decedent's information (both at 45 CFR 164.512(i)(1)). HIPAA governs this data-privacy layer only -- it is a separate federal regulatory regime from the Common Rule (45 CFR 46) and FDA human-subjects regulations that govern the ethical conduct of the research itself (IRB review, informed consent to participate). A single study involving PHI at a covered entity typically must satisfy both regimes concurrently, through separate, though often procedurally combined, analyses and documents.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/hipaa-in-clinical-research",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-17T05:11:06",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →