Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Research Misconduct Whistleblower Protections: What Retaliation Looks Like and How ORI Investigates It

What 42 CFR Part 93 requires to protect research-misconduct complainants and witnesses from retaliation, what retaliation looks like in practice, and how ORI investigates a retaliation complaint.

Every institutional policy compliant with 42 CFR Part 93 has to include protections for the person who raises a research-misconduct concern — the complainant, or in common usage, the whistleblower. Those protections are narrower and more procedural than they sound: they turn on a “good faith” standard, they run through the institution first rather than the federal Office of Research Integrity (ORI) directly, and what actually counts as prohibited retaliation is defined only loosely in the regulation itself. This guide covers the protection specifically — what the regulation requires, what retaliation looks like in practice, how a retaliation complaint gets investigated, and what a whistleblower can actually do if they believe they’ve been retaliated against.

This page assumes you already know the basic shape of a research-misconduct case (allegation, inquiry, investigation, finding). If you need that background first, see How a Research Misconduct Investigation Actually Works. For the 2024 final rule that updated 42 CFR Part 93’s definitions, evidentiary standards, and case timelines more broadly, see ORI’s 42 CFR Part 93 Final Rule: What Changed for Research Misconduct in 2026 — that piece covers the regulation as a whole; this one goes deep on the retaliation-protection piece specifically.

What the regulation actually requires

The core retaliation-protection obligation sits in 42 CFR § 93.300(d), part of institutions’ general responsibilities for compliance. It requires institutions to:

“Take all reasonable and practical steps to protect the positions and reputations of good faith complainants, witnesses, and committee members and to protect these individuals from retaliation by respondents and/or other institutional members.”

Three things about that language matter in practice:

  • It’s an institutional obligation, not a direct ORI guarantee. The regulation tells the institution what it must do; ORI’s role is oversight, not front-line protection. An institution that fails to take “reasonable and practical steps” is the one out of compliance, not ORI.
  • “Reasonable and practical” is a standard, not a checklist. The regulation doesn’t specify exactly what steps satisfy it — institutions build out the specifics (non-retaliation clauses in policy, restricted access to the complainant’s identity, monitoring for adverse actions during and after a case) in their own compliant procedures.
  • Protection extends to witnesses and committee members too, not only the original complainant. Anyone drawn into a misconduct proceeding in good faith is nominally covered.

The confidentiality piece works alongside this: institutions must limit disclosure of respondent, complainant, and research-subject identities to what’s required under 42 CFR § 93.108, which is one of the practical mechanisms institutions use to satisfy the anti-retaliation obligation — if fewer people know who raised the concern, there’s less surface area for retaliation to occur. Confidentiality is not absolute, though: once an investigation is underway, a respondent generally has a right to know and respond to the specific evidence against them, which can make full anonymity impossible to sustain through to a finding.

The “good faith” gate

Retaliation protection under 42 CFR Part 93 is not unconditional — it applies to good faith complainants and witnesses. ORI defines good faith as having “a belief in the truth of one’s allegation or testimony that a reasonable person in the complainant’s or witness’s position could have based on the information known to the complainant or witness at the time.” That’s an honest-belief standard measured against what a reasonable person would have concluded from the same information — it does not require the underlying allegation to turn out to be substantiated. A complainant who raises a concern in good faith and turns out to be wrong is still protected; the finding doesn’t have to go their way for the protection to apply.

The flip side matters too: an allegation made recklessly, or with willful disregard of facts that would disprove it, falls outside the good-faith standard and outside these protections. Institutional policy generally treats a knowingly false or malicious allegation as a potential compliance problem in its own right, separate from whatever the underlying misconduct allegation was.

What retaliation looks like in practice

Neither 42 CFR Part 93 nor ORI’s published guidance enumerates a specific, exhaustive list of prohibited retaliatory acts — “retaliation” is left as a general term for the institution and ORI to apply case by case. In practice, drawing on how retaliation is treated across adjacent whistleblower-protection frameworks (including the general federal Whistleblower Protection Act of 1989, which ORI cites as a related resource for federal-employee cases), the kinds of adverse action that typically get scrutinized as potential retaliation include:

  • Adverse personnel actions — termination, demotion, suspension, involuntary reassignment, a sudden negative performance evaluation, or denial of a promotion or tenure case that follows closely on a good-faith report.
  • Professional exclusion — removal from a grant, project, or manuscript; denial of authorship credit or lab resources the complainant previously had access to; exclusion from meetings, decisions, or communications relevant to their role.
  • Harassment or a hostile environment — conduct by the respondent or others at the institution intended to make the complainant’s working environment untenable.
  • Reputational harm — negative or altered references, informal blacklisting within a field or department, or disclosure of the complainant’s identity beyond what confidentiality rules permit.

What ties these together, and what an institution or ORI actually looks for, is timing and connection to the underlying report — an adverse action that follows a good-faith complaint and has a plausible causal link to it is what triggers scrutiny, not adverse actions in general. A poor performance review issued for reasons wholly unconnected to the misconduct report is not retaliation merely because it happened afterward.

How a retaliation complaint gets investigated

Retaliation complaints follow a different, narrower path than the underlying misconduct case:

Where to report it

ORI’s guidance directs a complainant who believes they’ve been retaliated against to first raise it with the institutional official named to receive research-misconduct allegations in the institution’s own policy — typically the Research Integrity Officer. Complainants can also contact ORI’s Division of Investigative Oversight directly (240-453-8800) if they believe the institution itself isn’t handling the retaliation concern appropriately, or if the retaliation is coming from the institution rather than an individual respondent.

The jurisdiction test ORI applies

Before ORI will act on a retaliation complaint, it assesses whether the matter falls under PHS jurisdiction at all, using three criteria:

  1. The underlying allegation concerns PHS-defined research misconduct — fabrication, falsification, or plagiarism (FFP).
  2. The research involved is PHS-supported.
  3. There is a plausible link between the original misconduct allegation and the alleged retaliation.

That third criterion is doing most of the work in practice: ORI is screening for a credible connection between “this person reported misconduct” and “this adverse thing then happened to them,” not adjudicating every workplace grievance that happens to follow a misconduct report. If a complaint doesn’t clear this jurisdictional screen — for example, the research wasn’t PHS-supported, or there’s no plausible connection between the alleged retaliation and the original report — ORI does not have authority to pursue it, and the complainant may need to look to other channels (institutional HR/EEO processes, applicable state whistleblower statutes, or, for federal employees specifically, the Whistleblower Protection Act of 1989, 5 U.S.C. § 1201).

Who actually investigates

Primary responsibility sits with the institution, consistent with 93.300(d)’s framing as an institutional obligation. ORI’s own published materials on this are comparatively thin on step-by-step investigative procedure once jurisdiction is established — the published resource most directly on point is ORI’s Guidelines to Institutions and Whistleblowers: Responding to Possible Retaliation, referenced from ORI’s retaliation-complaints pages as the fuller procedural resource. ORI’s oversight role is real (it can act where an institution fails to meet its 93.300(d) obligations, and it is the body a complainant can escalate to), but day-to-day handling of a retaliation concern is, by design, mostly an institutional-compliance function rather than a direct federal investigation in every case.

What a whistleblower can do if they believe they’ve been retaliated against

None of the following is legal advice, and a complainant facing what looks like retaliation should weigh consulting an employment attorney alongside these regulatory channels — but as a starting sequence, based on ORI’s own published guidance:

  1. Document the timeline. Note the date of the original good-faith report and the date, nature, and source of any adverse action that followed, specifically enough to support the “plausible link” ORI’s jurisdictional test looks for.
  2. Report it to the institutional official named in policy — usually the Research Integrity Officer — per the institution’s own compliant procedure.
  3. Contact ORI’s Division of Investigative Oversight if the institution’s response is inadequate, or if the institution itself appears to be the source of the retaliation, or if you’re unsure the matter falls under PHS jurisdiction at all.
  4. Check whether the case is PHS-jurisdictional before assuming ORI is the right venue — research that isn’t PHS-supported, or an allegation that doesn’t concern FFP, sits outside ORI’s authority regardless of how clear-cut the retaliation looks.
  5. Look to parallel channels where PHS jurisdiction doesn’t apply — institutional HR/EEO grievance processes, applicable state whistleblower-protection statutes, or, for federal employees, the Whistleblower Protection Act of 1989.

Frequently asked questions

Does 42 CFR Part 93 protect a complainant even if the misconduct allegation isn’t substantiated?

Yes. Protection under 93.300(d) turns on whether the complaint was made in good faith at the time, not on whether the eventual finding supports it. A good-faith complainant whose allegation is ultimately not substantiated is still entitled to the same protection from retaliation as one whose allegation is confirmed.

Can a false or malicious accusation ever be treated as its own violation?

Retaliation protections are explicitly limited to good-faith reports. An allegation made recklessly or with willful disregard of disproving facts falls outside the good-faith standard, and institutional policy generally treats a knowingly false or malicious report as a separate compliance concern from the underlying misconduct case.

Is ORI the right place to report retaliation for research that isn’t PHS-funded?

Not directly. ORI’s jurisdiction under 42 CFR Part 93 is limited to PHS-supported research and PHS-defined misconduct (FFP). Non-PHS research falls to the applicable funder’s own misconduct policy (for example, NSF’s parallel process under 45 CFR Part 689) or to institutional, state, or general employment-law channels.

What’s the difference between this page and CASRAI’s guide to the 2024 final rule?

That piece walks through what changed across 42 CFR Part 93 broadly — definitions, evidentiary standards, case timelines, institutional reporting. This page is scoped specifically to the retaliation-protection provisions and how a retaliation complaint itself gets handled, which is a distinct process from the underlying misconduct inquiry/investigation.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →