PhysioNet is an NIH-funded biomedical data platform, managed by the MIT Laboratory for Computational Physiology in collaboration with the Margret and H.A. Rey Institute for Nonlinear Dynamics at Beth Israel Deaconess Medical Center, that hosts physiological signal recordings, electronic health record extracts, clinical text, and imaging data for research use. Its best-known resource is the MIMIC family of intensive-care databases, but PhysioNet’s real operational complexity for a research administrator is not the data itself — it’s the three-tier access model that decides who can get to it, and what they have to do first. This guide covers how that model works, what the credentialing process for restricted physiological and clinical signal data actually requires, and where it fits alongside the data governance controls institutions already use for other controlled-access repositories.
PhysioNet’s three access tiers
PhysioNet does not treat “access” as a single yes/no gate. Every hosted resource is published under one of three tiers, and the tier is set per dataset based on re-identification risk, not on a blanket platform-wide policy:
- Open access — available to any user with minimal restriction on reuse. Demo or subsampled versions of larger controlled-access datasets (for example, a small public MIMIC-IV demo subset) are frequently released this way, so a researcher can evaluate structure and fit before committing to the full credentialing process.
- Restricted access — available to any registered PhysioNet user who signs a Data Use Agreement (DUA) for that specific resource. No separate training or credentialing review is required at this tier.
- Credentialed access — available only to users who have completed PhysioNet’s credentialing process and signed the resource-specific DUA. This is the tier that governs the physiological and clinical signal datasets this guide is about, including the full MIMIC databases.
The distinction between restricted and credentialed matters operationally: a restricted-access resource asks a user to agree to terms; a credentialed-access resource asks PhysioNet to first verify that the user is a legitimate, trained researcher before those terms are ever offered.
Why physiological and clinical signal data needs a higher bar
PhysioNet’s own data is curated and de-identified before release, but de-identification and credentialing solve different problems. De-identification removes or alters direct identifiers from a dataset; it does not eliminate the residual risk that a sufficiently detailed, longitudinal, or high-resolution record could still be linked back to an individual by someone with the right auxiliary information — a concern that is more acute for ICU-length electronic health record extracts and continuous physiological waveforms than for a simple tabular dataset. Gating access behind identity verification and an enforceable use agreement, on top of de-identification, is PhysioNet’s way of controlling that residual risk without withholding the data from legitimate research entirely. This is the same logic behind sensitive-data repositories more broadly, and behind comparable controlled-access government resources like dbGaP and CMS research data (see CASRAI’s guide to CMS Data Use Agreement mechanics for a close analog outside the clinical-signal space).
Getting credentialed: the step-by-step process
To become a PhysioNet credentialed user and reach the datasets gated at that tier, a researcher generally goes through the following sequence:
- Create a PhysioNet account and complete basic profile/identity information.
- Submit a credentialing application through PhysioNet’s credentialing settings, which PhysioNet’s team reviews before granting credentialed status.
- Complete a recognized human-subjects/data-privacy training course. PhysioNet’s stated requirement for credentialed resources is the CITI Program’s “Data or Specimens Only Research” course — a shorter, more targeted module than the full human-subjects course, reflecting that credentialed users are working with de-identified secondary data rather than recruiting or interacting with participants directly.
- Wait for review. PhysioNet states that credentialing and training-report review is normally completed within 24–48 hours, though this is not a guaranteed turnaround and can run longer.
- Sign the resource-specific Data Use Agreement. Credentialing alone does not open every credentialed-access dataset — each one (each version of MIMIC-III, MIMIC-IV, MIMIC-IV-ED, MIMIC-CXR, and so on) carries its own DUA that a credentialed user must separately accept before that specific resource unlocks.
A practical consequence worth flagging for research administrators: credentialing is a platform-level status, but data access is granted dataset-by-dataset. A lab bringing on a new team member needs to budget time for both steps — the credentialing review and each dataset’s DUA — not just one of them.
What the Data Use Agreement actually restricts
PhysioNet’s credentialed-access DUAs are legally binding and follow a broadly consistent pattern across the datasets that use them: the signer agrees not to attempt to identify or re-identify any individual in the data, not to share the raw data with anyone who has not independently signed the same agreement, to store the data securely, and to cite the dataset appropriately in any resulting publication. That last point is not a courtesy convention — PhysioNet’s platform itself asks users to cite both the specific dataset’s own paper (for MIMIC-III, the 2016 Scientific Data paper by Johnson et al.) and the foundational PhysioNet resource paper (Goldberger et al., “PhysioBank, PhysioToolkit, and PhysioNet,” Circulation, 2000), which is how the platform sustains its NIH funding case and tracks reuse. A research administrator drafting a data management plan or reviewing a study’s data-source section should treat both the DUA’s use restrictions and its citation requirement as compliance obligations to document, not just as fine print.
MIMIC and PhysioNet’s other credentialed-access datasets
MIMIC (Medical Information Mart for Intensive Care) is PhysioNet’s flagship credentialed-access resource and the reason most institutions first encounter this process. It exists in several versions and modality-specific extensions, all requiring credentialed access for their full form:
- MIMIC-III — the original critical-care database covering ICU stays at Beth Israel Deaconess Medical Center.
- MIMIC-IV — a substantially updated and restructured successor, including a separate emergency-department extension (MIMIC-IV-ED).
- MIMIC-CXR — chest radiographs linked to MIMIC clinical data, for imaging and multimodal research.
- MIMIC-IV-Note and related text extensions — de-identified clinical free text paired with the structured MIMIC-IV data.
Each of these is a distinct PhysioNet resource with its own version history and its own DUA, even though a single credentialing approval covers all of them — a researcher does not need to be re-credentialed to move from MIMIC-III to MIMIC-IV, but does need to accept a new DUA for each. Open, non-credentialed demo subsets exist for some MIMIC resources specifically so a lab can prototype a pipeline before the full credentialing and DUA process is complete.
What this means for research administrators
A few practical points worth building into institutional onboarding or data-governance guidance for any lab planning to use PhysioNet’s credentialed resources:
- Institutional affiliation is checked, but the DUA is signed by the individual. PhysioNet’s credentialing process expects a real institutional or professional affiliation, but the agreement itself binds the named individual user, not the institution as a whole — unlike some data-sharing frameworks that route through an institutional signing official. Confirm whether your institution still wants central visibility into who has signed a PhysioNet DUA, even though it isn’t formally required to.
- Secondary use of de-identified, credentialed-access data does not automatically bypass IRB review. Many institutions treat PhysioNet’s credentialed datasets as exempt or non-human-subjects research given the de-identification involved, but that determination is made by the institution’s own IRB or privacy office under its own policy, not by PhysioNet — confirm the institutional position before assuming a project is exempt.
- Redistribution restrictions affect data-sharing plans. A funder-mandated data availability statement covering a PhysioNet-derived analysis should point readers to PhysioNet’s own access process rather than promise direct redistribution of the underlying credentialed data, since the DUA prohibits sharing raw data outside the agreement.
- Citation compliance is checkable. Because PhysioNet ties funding justification to citation tracking, a lab’s publication record using MIMIC or similar resources is a reasonable, low-effort thing for a research office to spot-check against the DUA’s citation requirement.
Frequently asked questions
Is PhysioNet credentialing a one-time process?
Credentialed status is granted once and is not tied to a single dataset, but each individual credentialed-access resource still requires its own separate DUA signature before it unlocks. Training credentials used to support credentialing (such as a CITI training report) are also subject to CITI’s own expiration and renewal cycle, independent of PhysioNet.
Do I need IRB approval to use MIMIC?
PhysioNet does not require proof of IRB approval as part of its own credentialing process, but that is a decision about PhysioNet’s gate, not your institution’s. Whether a specific project using MIMIC or another credentialed PhysioNet dataset needs IRB review, an exemption determination, or neither is set by your own institution’s human-subjects policy, and should be confirmed with your IRB or privacy office before starting analysis.
Can I share MIMIC data with a collaborator at another institution?
Only if that collaborator has independently completed PhysioNet’s credentialing process and signed the same resource’s DUA under their own account. The agreement does not permit redistributing the raw data, even to a co-author, without their own independent access.
What’s the difference between PhysioNet’s restricted and credentialed tiers?
Restricted-access resources require only that a registered user sign a Data Use Agreement. Credentialed-access resources — which includes the full MIMIC databases — require completing PhysioNet’s credentialing review and a recognized training course (CITI’s “Data or Specimens Only Research” course) in addition to signing the DUA.
How is this different from getting access to dbGaP?
The underlying goal is similar — controlled access to potentially re-identifiable human data, gated behind identity verification, training, and a signed use agreement — but the mechanics differ. dbGaP access requests route through a Data Access Committee tied to the specific study that deposited the data and are typically approved at the level of a named PI and institution; PhysioNet’s credentialing is a platform-wide individual status, with per-resource DUAs layered on top.







