An honest broker is a neutral third party — an individual or a designated institutional system — who obtains identifiable clinical records, specimens, or data on a study team’s behalf, strips out the identifiers, and hands researchers only the de-identified result. The role exists specifically to let researchers use clinical data without ever touching the identifiable version themselves, which is what allows many retrospective, data-only studies to proceed as de-identified or limited-data-set research rather than as full human subjects research requiring the same review as a prospective clinical trial.
The honest broker system was formalized and popularized at academic medical centers — the University of Pittsburgh’s Human Research Protection Office and UPMC’s Collaborative Honest Brokers System are among the most frequently cited institutional models — and variants now operate under that name or a close equivalent (data warehouse, self-service data request office, research data honest broker) at most large U.S. academic health centers, including Children’s Hospital of Philadelphia, the University of Nebraska Medical Center, and UW Medicine. This guide covers what the role actually does, the regulatory logic that makes it work, who can and cannot serve as one, and where its limits are.
What an honest broker does
A 2015 peer-reviewed analysis, “Establishing the role of honest broker: bridging the gap between protecting personal health data and clinical research efficiency,” identified four characteristics that consistently define the role across institutions:
- De-identification of clinical data. The broker’s core function is removing or masking identifiers from records, specimens, or datasets before they reach a research team.
- Independence. The broker is not part of the research team in any capacity — not an investigator, study coordinator, statistician, or co-author on any resulting publication.
- Purpose verification. The broker confirms the requested data is used only for the purpose the IRB (or equivalent oversight body) actually approved.
- Provision of de-identified data. The broker delivers the finished, de-identified dataset or specimen set to the researcher — the researcher never independently accesses the identifiable source.
Practically, an honest broker typically has routine, job-based access to a clinical or research data source already — a cancer registry, an electronic medical record system, a pathology archive, a biorepository — as part of their normal institutional role (clinical informatics staff, registry abstractor, data warehouse analyst). They are not granted special access solely to perform the broker function; that pre-existing, legitimate access is part of what makes the arrangement defensible as routine data stewardship rather than a workaround.
Why the role exists: the regulatory logic
The honest broker model sits at the intersection of two distinct federal frameworks that most U.S. clinical research has to satisfy simultaneously:
- The Common Rule (45 CFR 46). Under 45 CFR 46.102, “human subjects research” requires that an investigator obtain data through intervention/interaction with a living individual or obtain identifiable private information about them. Data that has been properly de-identified is, by definition, no longer identifiable — so a study built entirely on data an honest broker has already de-identified may not meet the regulatory definition of human subjects research at all, or may qualify for exempt or expedited review rather than full board review. See CASRAI’s Human Subjects Research: Definition Under 45 CFR 46.102 guide for the full test.
- HIPAA’s Privacy Rule. Separately, if the source data is Protected Health Information held by a HIPAA covered entity, removing it from PHI status requires either the Safe Harbor method (removing all 18 identifier categories at 45 CFR 164.514(b)(2)) or Expert Determination (a qualified statistician certifying a very small re-identification risk) under 45 CFR 164.514(a)-(b). An honest broker performing Safe Harbor de-identification takes the resulting dataset out of HIPAA’s scope entirely, which is why institutional honest broker policies are frequently issued jointly by the IRB and the covered entity’s privacy office.
The honest broker is the person or system that actually performs that de-identification step — turning identifiable clinical data into a dataset that satisfies both frameworks’ thresholds before a researcher ever receives it. Without a documented, independent broker, a researcher who both pulls the identifiable data and de-identifies it themselves is harder to distinguish, procedurally, from a researcher simply accessing identifiable data for research purposes — which is exactly the human-subjects and HIPAA exposure the role is designed to avoid.
Honest broker vs. related roles and mechanisms
The honest broker role is frequently confused with adjacent but distinct roles and instruments:
- Honest broker vs. the treating clinician. A patient’s treating physician has identifiable clinical access as part of direct patient care, not as a research function, and cannot serve as an honest broker for their own patients’ data if they are also involved in the study — the independence requirement specifically rules this out.
- Honest broker vs. the research team. The whole point of the role is separation: an investigator, coordinator, or study statistician cannot simultaneously act as the honest broker for their own study’s data, because that would collapse the independence the model depends on.
- Honest broker vs. a Data Use Agreement. A Data Use Agreement (DUA) is the contractual instrument governing how a recipient may use a limited data set once received; an honest broker is the person or process that produces the de-identified or limited data set in the first place. Many institutional workflows use both together — see CASRAI’s Limited Data Set vs. De-Identified Data comparison for how the two source-data types differ.
- Honest broker vs. a general data warehouse or self-service query tool. Some institutions operationalize the honest broker function as an automated system (a de-identified data warehouse or cohort-discovery tool) rather than a named individual — the same four defining characteristics still apply to the system as a whole, per the honest broker literature cited above.
- Honest broker vs. de-identification generally. De-identification is a data property and a technical process; “honest broker” is the institutional role and governance model built around who is allowed to perform that process and under what oversight. See CASRAI’s Data Anonymisation in Research guide for the underlying techniques (Safe Harbor, Expert Determination, k-anonymity, and related methods) independent of who applies them.
What honest broker status does — and does not — eliminate
A properly documented honest broker pathway is not a way to bypass IRB oversight entirely; institutions structure it as a defined, IRB-reviewed pathway rather than an informal exemption. In practice, most institutional honest broker policies still require:
- An approved protocol or honest broker certification. The researcher requesting the service typically submits a request describing the data needed and its research purpose, and the IRB (or a designated reviewer) confirms the request is appropriately scoped before the broker fulfills it.
- Institutional broker certification and training. Individuals serving as honest brokers are commonly required to complete specific training — for example, CITI Program modules covering Responsible Conduct of Research, Human Subjects Research, and Privacy & Information Security — and to sign an institutional assurance or certification form before performing broker functions.
- Privacy office sign-off. Because the process removes data from HIPAA’s PHI scope, many institutions route honest broker policies and individual certifications through the covered entity’s privacy officer, not the IRB alone.
- Recruitment-related honest broker use still triggers additional review in some workflows. Using an honest broker or clinical data warehouse to identify potentially eligible patients for a study (rather than to build a purely retrospective de-identified dataset) commonly still requires a limited IRB review, a HIPAA waiver of authorization, or a documented recruitment protocol, because contacting or approaching those individuals is a separate step the de-identification itself does not cover.
In other words, the honest broker role changes who touches identifiable data and how a specific dataset gets de-identified — it does not, by itself, remove the underlying institutional obligation to have an approved, documented process governing that data flow.
Common institutional names for this role
Terminology varies by institution even where the underlying function is the same. Names encountered in real institutional policies include “honest broker,” “honest broker system,” “collaborative honest brokers system,” “research data warehouse honest broker,” “de-identified data service,” and “self-service data request” function. Some institutions formalize the role as an individual designation (a named, trained staff member certified per request or per data source); others formalize it as a standing office or automated system that fulfills the same four defining functions. When evaluating an unfamiliar institution’s policy, the label matters less than confirming the same core elements are present: independence from the research team, a defined de-identification method, purpose verification against an approved protocol, and delivery of only the de-identified result to the requester.
Frequently asked questions
Can a member of the research team also serve as the honest broker for that same study?
No. Independence from the research team — not being an investigator, coordinator, statistician, or listed co-author on the study — is one of the role’s defining characteristics across every institutional model reviewed in the honest broker literature. A researcher de-identifying their own study’s data does not satisfy the honest broker requirement.
Does using an honest broker mean a study doesn’t need IRB review at all?
Not automatically. It can mean a study qualifies for exempt or expedited review, or falls outside the Common Rule’s definition of human subjects research, if the researcher genuinely never receives identifiable private information. But the honest broker pathway itself is typically only available through an approved institutional process, and any step involving contact with or identification of specific individuals (such as recruitment screening) commonly still requires separate IRB and HIPAA review.
What’s the difference between an honest broker and a data use agreement?
They operate at different stages. The honest broker is the person or process that produces a de-identified or limited data set from an identifiable source. A Data Use Agreement is the contract governing how the recipient may use that data set once they have it — typically required for a limited data set (which retains some indirect identifiers, like dates) but not for fully de-identified data under HIPAA Safe Harbor, which carries no such requirement because it has been removed from PHI status entirely.
Can an honest broker be an automated system rather than a person?
Yes. Several academic medical centers operationalize the function as a de-identified clinical data warehouse or cohort-discovery tool rather than (or in addition to) a named individual. The same four defining functions — de-identification, independence, purpose verification, and provision of only de-identified output — still apply to the system’s design and governance.
Does HIPAA use the term “honest broker”?
No. “Honest broker” is an institutional and research-informatics term, not a defined term in the HIPAA Privacy Rule itself. The regulatory mechanisms the role relies on — Safe Harbor de-identification and Expert Determination under 45 CFR 164.514(a)-(b), and the Limited Data Set/Data Use Agreement pathway under 164.514(e) — are HIPAA-defined; the honest broker is the institutional role built around correctly applying them before a researcher receives the data.
Related CASRAI resources
- De-identification
- Limited Data Set (HIPAA)
- Limited Data Set vs. De-Identified Data (HIPAA)
- Data Use Agreement (DUA)
- HIPAA in Clinical Research
- HIPAA Privacy Rule
- IRB (Institutional Review Board)
- Common Rule (45 CFR 46)
- Human Subjects Research: Definition Under 45 CFR 46.102
- Data Anonymisation in Research
- Electronic Medical Record (EMR)
- Research Integrity & Compliance (cluster pillar)







