{"id":12636,"date":"2025-11-06T13:58:21","date_gmt":"2025-11-06T18:58:21","guid":{"rendered":"https:\/\/labs.icahn.mssm.edu\/minervalab\/?page_id=12636"},"modified":"2025-11-21T12:02:24","modified_gmt":"2025-11-21T17:02:24","slug":"compliance-overview-hipaa-and-institutional-review-board-requirements","status":"publish","type":"page","link":"https:\/\/labs.icahn.mssm.edu\/minervalab\/compliance-overview-hipaa-and-institutional-review-board-requirements\/","title":{"rendered":"Compliance Overview: HIPAA and Institutional Review Board Requirements"},"content":{"rendered":"<p>[et_pb_section bb_built=&#8221;1&#8243; inner_width=&#8221;auto&#8221; inner_max_width=&#8221;1080px&#8221;][et_pb_row][et_pb_column type=&#8221;4_4&#8243; custom_padding__hover=&#8221;|||&#8221; custom_padding=&#8221;|||&#8221;][et_pb_text admin_label=&#8221;Breadcrumb&#8221; _builder_version=&#8221;4.27.4&#8243; background_pattern_color=&#8221;rgba(0,0,0,0.2)&#8221; background_mask_color=&#8221;#ffffff&#8221; text_text_shadow_horizontal_length=&#8221;text_text_shadow_style,%91object Object%93&#8243; text_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; text_text_shadow_vertical_length=&#8221;text_text_shadow_style,%91object Object%93&#8243; text_text_shadow_vertical_length_tablet=&#8221;0px&#8221; text_text_shadow_blur_strength=&#8221;text_text_shadow_style,%91object Object%93&#8243; text_text_shadow_blur_strength_tablet=&#8221;1px&#8221; link_text_shadow_horizontal_length=&#8221;link_text_shadow_style,%91object Object%93&#8243; link_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; link_text_shadow_vertical_length=&#8221;link_text_shadow_style,%91object Object%93&#8243; link_text_shadow_vertical_length_tablet=&#8221;0px&#8221; link_text_shadow_blur_strength=&#8221;link_text_shadow_style,%91object Object%93&#8243; link_text_shadow_blur_strength_tablet=&#8221;1px&#8221; ul_text_shadow_horizontal_length=&#8221;ul_text_shadow_style,%91object Object%93&#8243; ul_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; ul_text_shadow_vertical_length=&#8221;ul_text_shadow_style,%91object Object%93&#8243; ul_text_shadow_vertical_length_tablet=&#8221;0px&#8221; ul_text_shadow_blur_strength=&#8221;ul_text_shadow_style,%91object Object%93&#8243; ul_text_shadow_blur_strength_tablet=&#8221;1px&#8221; ol_text_shadow_horizontal_length=&#8221;ol_text_shadow_style,%91object Object%93&#8243; ol_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; ol_text_shadow_vertical_length=&#8221;ol_text_shadow_style,%91object Object%93&#8243; ol_text_shadow_vertical_length_tablet=&#8221;0px&#8221; ol_text_shadow_blur_strength=&#8221;ol_text_shadow_style,%91object Object%93&#8243; ol_text_shadow_blur_strength_tablet=&#8221;1px&#8221; quote_text_shadow_horizontal_length=&#8221;quote_text_shadow_style,%91object Object%93&#8243; quote_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; quote_text_shadow_vertical_length=&#8221;quote_text_shadow_style,%91object Object%93&#8243; quote_text_shadow_vertical_length_tablet=&#8221;0px&#8221; quote_text_shadow_blur_strength=&#8221;quote_text_shadow_style,%91object Object%93&#8243; quote_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_text_shadow_horizontal_length=&#8221;header_text_shadow_style,%91object Object%93&#8243; header_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_text_shadow_vertical_length=&#8221;header_text_shadow_style,%91object Object%93&#8243; header_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_text_shadow_blur_strength=&#8221;header_text_shadow_style,%91object Object%93&#8243; header_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_2_text_shadow_horizontal_length=&#8221;header_2_text_shadow_style,%91object Object%93&#8243; header_2_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_2_text_shadow_vertical_length=&#8221;header_2_text_shadow_style,%91object Object%93&#8243; header_2_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_2_text_shadow_blur_strength=&#8221;header_2_text_shadow_style,%91object Object%93&#8243; header_2_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_3_text_shadow_horizontal_length=&#8221;header_3_text_shadow_style,%91object Object%93&#8243; header_3_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_3_text_shadow_vertical_length=&#8221;header_3_text_shadow_style,%91object Object%93&#8243; header_3_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_3_text_shadow_blur_strength=&#8221;header_3_text_shadow_style,%91object Object%93&#8243; header_3_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_4_text_shadow_horizontal_length=&#8221;header_4_text_shadow_style,%91object Object%93&#8243; header_4_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_4_text_shadow_vertical_length=&#8221;header_4_text_shadow_style,%91object Object%93&#8243; header_4_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_4_text_shadow_blur_strength=&#8221;header_4_text_shadow_style,%91object Object%93&#8243; header_4_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_5_text_shadow_horizontal_length=&#8221;header_5_text_shadow_style,%91object Object%93&#8243; header_5_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_5_text_shadow_vertical_length=&#8221;header_5_text_shadow_style,%91object Object%93&#8243; header_5_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_5_text_shadow_blur_strength=&#8221;header_5_text_shadow_style,%91object Object%93&#8243; header_5_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_6_text_shadow_horizontal_length=&#8221;header_6_text_shadow_style,%91object Object%93&#8243; header_6_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_6_text_shadow_vertical_length=&#8221;header_6_text_shadow_style,%91object Object%93&#8243; header_6_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_6_text_shadow_blur_strength=&#8221;header_6_text_shadow_style,%91object Object%93&#8243; header_6_text_shadow_blur_strength_tablet=&#8221;1px&#8221; box_shadow_horizontal_tablet=&#8221;0px&#8221; box_shadow_vertical_tablet=&#8221;0px&#8221; box_shadow_blur_tablet=&#8221;40px&#8221; box_shadow_spread_tablet=&#8221;0px&#8221; vertical_offset_tablet=&#8221;0&#8243; horizontal_offset_tablet=&#8221;0&#8243; z_index_tablet=&#8221;0&#8243;]<\/p>\n<p><a href=\"https:\/\/labs.icahn.mssm.edu\/minervalab\/\">Scientific Computing and Data<\/a> \/ <a href=\"https:\/\/labs.icahn.mssm.edu\/minervalab\/air-ms-artificial-intelligence-ready-mount-sinai\/\">AIR<strong>\u00b7<\/strong>MS (AI Ready Mount Sinai)<\/a> \/ Compliance Overview (HIPAA and IRB Requirements)<\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; background_pattern_color=&#8221;rgba(0,0,0,0.2)&#8221; background_mask_color=&#8221;#ffffff&#8221; text_text_shadow_horizontal_length=&#8221;text_text_shadow_style,%91object Object%93&#8243; text_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; text_text_shadow_vertical_length=&#8221;text_text_shadow_style,%91object Object%93&#8243; text_text_shadow_vertical_length_tablet=&#8221;0px&#8221; text_text_shadow_blur_strength=&#8221;text_text_shadow_style,%91object Object%93&#8243; text_text_shadow_blur_strength_tablet=&#8221;1px&#8221; link_text_shadow_horizontal_length=&#8221;link_text_shadow_style,%91object Object%93&#8243; link_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; link_text_shadow_vertical_length=&#8221;link_text_shadow_style,%91object Object%93&#8243; link_text_shadow_vertical_length_tablet=&#8221;0px&#8221; link_text_shadow_blur_strength=&#8221;link_text_shadow_style,%91object Object%93&#8243; link_text_shadow_blur_strength_tablet=&#8221;1px&#8221; ul_text_shadow_horizontal_length=&#8221;ul_text_shadow_style,%91object Object%93&#8243; ul_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; ul_text_shadow_vertical_length=&#8221;ul_text_shadow_style,%91object Object%93&#8243; ul_text_shadow_vertical_length_tablet=&#8221;0px&#8221; ul_text_shadow_blur_strength=&#8221;ul_text_shadow_style,%91object Object%93&#8243; ul_text_shadow_blur_strength_tablet=&#8221;1px&#8221; ol_text_shadow_horizontal_length=&#8221;ol_text_shadow_style,%91object Object%93&#8243; ol_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; ol_text_shadow_vertical_length=&#8221;ol_text_shadow_style,%91object Object%93&#8243; ol_text_shadow_vertical_length_tablet=&#8221;0px&#8221; ol_text_shadow_blur_strength=&#8221;ol_text_shadow_style,%91object Object%93&#8243; ol_text_shadow_blur_strength_tablet=&#8221;1px&#8221; quote_text_shadow_horizontal_length=&#8221;quote_text_shadow_style,%91object Object%93&#8243; quote_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; quote_text_shadow_vertical_length=&#8221;quote_text_shadow_style,%91object Object%93&#8243; quote_text_shadow_vertical_length_tablet=&#8221;0px&#8221; quote_text_shadow_blur_strength=&#8221;quote_text_shadow_style,%91object Object%93&#8243; quote_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_text_shadow_horizontal_length=&#8221;header_text_shadow_style,%91object Object%93&#8243; header_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_text_shadow_vertical_length=&#8221;header_text_shadow_style,%91object Object%93&#8243; header_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_text_shadow_blur_strength=&#8221;header_text_shadow_style,%91object Object%93&#8243; header_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_2_text_shadow_horizontal_length=&#8221;header_2_text_shadow_style,%91object Object%93&#8243; header_2_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_2_text_shadow_vertical_length=&#8221;header_2_text_shadow_style,%91object Object%93&#8243; header_2_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_2_text_shadow_blur_strength=&#8221;header_2_text_shadow_style,%91object Object%93&#8243; header_2_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_3_text_shadow_horizontal_length=&#8221;header_3_text_shadow_style,%91object Object%93&#8243; header_3_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_3_text_shadow_vertical_length=&#8221;header_3_text_shadow_style,%91object Object%93&#8243; header_3_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_3_text_shadow_blur_strength=&#8221;header_3_text_shadow_style,%91object Object%93&#8243; header_3_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_4_text_shadow_horizontal_length=&#8221;header_4_text_shadow_style,%91object Object%93&#8243; header_4_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_4_text_shadow_vertical_length=&#8221;header_4_text_shadow_style,%91object Object%93&#8243; header_4_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_4_text_shadow_blur_strength=&#8221;header_4_text_shadow_style,%91object Object%93&#8243; header_4_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_5_text_shadow_horizontal_length=&#8221;header_5_text_shadow_style,%91object Object%93&#8243; header_5_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_5_text_shadow_vertical_length=&#8221;header_5_text_shadow_style,%91object Object%93&#8243; header_5_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_5_text_shadow_blur_strength=&#8221;header_5_text_shadow_style,%91object Object%93&#8243; header_5_text_shadow_blur_strength_tablet=&#8221;1px&#8221; header_6_text_shadow_horizontal_length=&#8221;header_6_text_shadow_style,%91object Object%93&#8243; header_6_text_shadow_horizontal_length_tablet=&#8221;0px&#8221; header_6_text_shadow_vertical_length=&#8221;header_6_text_shadow_style,%91object Object%93&#8243; header_6_text_shadow_vertical_length_tablet=&#8221;0px&#8221; header_6_text_shadow_blur_strength=&#8221;header_6_text_shadow_style,%91object Object%93&#8243; header_6_text_shadow_blur_strength_tablet=&#8221;1px&#8221; box_shadow_horizontal_tablet=&#8221;0px&#8221; box_shadow_vertical_tablet=&#8221;0px&#8221; box_shadow_blur_tablet=&#8221;40px&#8221; box_shadow_spread_tablet=&#8221;0px&#8221; vertical_offset_tablet=&#8221;0&#8243; horizontal_offset_tablet=&#8221;0&#8243; z_index_tablet=&#8221;0&#8243;]<\/p>\n<h1><strong><span style=\"color: #00aeef\">Compliance Overview: <\/span><span style=\"color: #00aeef\">Health Insurance Portability and Accountability Act<\/span><span style=\"color: #00aeef\"> (HIPAA) and Institutional Review Board (IRB) Requirements<\/span><\/strong><\/h1>\n<h2>\u00a0<\/h2>\n<h2>\u00a0<\/h2>\n<h2><span style=\"color: #00aeef\"><strong><span class=\"LineBox SCXP38020518 BCX8\"><span class=\"TextRun CommentHighlight CommentHighlightRest SCXP38020518 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-usefontface=\"false\" data-contrast=\"none\"><span class=\"NormalTextRun CommentStart CommentHighlightPipeRest SCXP38020518 BCX8\">Steps to Obtain <\/span><\/span><\/span><span class=\"LineBox SCXP38020518 BCX8\"><span class=\"TextRun CommentHighlight CommentHighlightRest SCXP38020518 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-usefontface=\"false\" data-contrast=\"none\"><span class=\"NormalTextRun SCXP38020518 BCX8\">IRB Approval <\/span><\/span><\/span><\/strong><\/span><span class=\"LineBox SCXP38020518 BCX8\"><span style=\"color: #00aeef\"><strong><span class=\"TextRun CommentHighlight CommentHighlightRest SCXP38020518 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-usefontface=\"false\" data-contrast=\"none\"><span class=\"NormalTextRun SCXP38020518 BCX8\">and Data Access<\/span><\/span><\/strong><\/span><span class=\"EOP CommentHighlightPipeRest SCXP38020518 BCX8\">\u200b<\/span><\/span><\/h2>\n<p><img decoding=\"async\" src=\"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-content\/uploads\/sites\/342\/2025\/11\/HIPAA-IRB-slides-for-AIR-MS_Nov_6_2025_ET-1.jpg\" \/><br \/>\u00a0<\/p>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:0.9,&quot;335562766&quot;:4,&quot;335562767&quot;:10,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\">\u00a0<\/h2>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:0.9,&quot;335562766&quot;:4,&quot;335562767&quot;:10,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><strong><span style=\"color: #00aeef\">Overview<\/span><\/strong><\/h2>\n<p><span style=\"color: #000000\">Research involves several important compliance steps\u2014such as preparing a strong IRB protocol, defining clear inclusion and exclusion criteria, completing data use agreements (DUAs), and securing appropriate computational resources. Although this process may seem daunting, it is designed to be as efficient as possible and to ensure that studies are conducted responsibly and accurately. By following the guidelines below, researchers can complete their projects effectively while safeguarding patient privacy. Key concepts researchers should be aware of are:<\/span><\/p>\n<ul>\n<li><strong><span style=\"color: #000000\">HIPAA\u00a0<\/span><\/strong><\/li>\n<li><strong><span style=\"color: #000000\">Identified vs. De-Identified Data<\/span><\/strong><\/li>\n<li><strong><span style=\"color: #000000\">HIPAA Minimum Necessary Rule and Inclusion \/ Exclusion Criteria<\/span><\/strong><\/li>\n<li><strong><span style=\"color: #000000\">IRB<\/span><\/strong><\/li>\n<\/ul>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:0.9,&quot;335562766&quot;:4,&quot;335562767&quot;:10,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\">\u00a0<\/h2>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:0.9,&quot;335562766&quot;:4,&quot;335562767&quot;:10,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><strong><span style=\"color: #00aeef\">What is HIPAA?\u200b<\/span><\/strong><\/h2>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:0.9,&quot;335562766&quot;:4,&quot;335562767&quot;:10,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><a href=\"https:\/\/www.hhs.gov\/hipaa\/index.html\" data-hyperlinktype=\"0\"><b><span data-usefontface=\"false\" data-contrast=\"none\">HIPAA<\/span><\/b><\/a><span data-usefontface=\"false\" data-contrast=\"none\">\u00a0<span style=\"color: #000000\">establishes <\/span><\/span><span style=\"color: #000000\">national standards for guarding <b>protected health information (PHI)<\/b>\u00a0and promotes the\u00a0<b>secure, ethical use of medical data<\/b> in both healthcare and research.\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:0.9,&quot;335562766&quot;:4,&quot;335562767&quot;:10,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\"><span style=\"color: #000080\"><b>Importance of HIPAA<\/b><\/span>\u200b<\/span><\/p>\n<ul style=\"font-weight: 400\">\n<li data-charcodes=\"8226\" data-font=\"Arial,Sans-Serif\" data-buautonum=\"8\" data-margin=\"450\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span style=\"color: #000000\"><b>Protects Patient Privacy &#8211; <\/b>Safeguards all PHI from unauthorized access or disclosure.\u200b<\/span><\/li>\n<li data-charcodes=\"8226\" data-font=\"Arial,Sans-Serif\" data-buautonum=\"8\" data-margin=\"450\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span style=\"color: #000000\"><b>Ensures Data Security &#8211; <\/b>Requires administrative, physical, and technical safeguards to keep health data secure.\u200b<\/span><\/li>\n<li data-charcodes=\"8226\" data-font=\"Arial,Sans-Serif\" data-buautonum=\"8\" data-margin=\"450\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span style=\"color: #000000\"><b>Empowers Patients &#8211; <\/b>Gives patients rights to access, review, and request corrections to their medical records.\u200b<\/span><\/li>\n<li data-charcodes=\"8226\" data-font=\"Arial,Sans-Serif\" data-buautonum=\"8\" data-margin=\"450\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span style=\"color: #000000\"><b>Standardizes Practices &#8211; <\/b>Sets national standards for healthcare transactions and data sharing.\u200b<\/span><\/li>\n<li data-charcodes=\"8226\" data-font=\"Arial,Sans-Serif\" data-buautonum=\"8\" data-margin=\"450\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span style=\"color: #000000\"><b>Supports Insurance Portability &#8211; <\/b>Ensures patients can maintain health insurance coverage when changing jobs and prohibits discrimination based on pre-existing conditions.\u200b<\/span><\/li>\n<li data-charcodes=\"8226\" data-font=\"Arial,Sans-Serif\" data-buautonum=\"8\" data-margin=\"450\" data-aria-posinset=\"6\" data-aria-level=\"1\"><span style=\"color: #000000\"><b>Enforces Accountability &#8211; <\/b>Establishes penalties for violations and promotes compliance across all healthcare entities.<\/span><\/li>\n<\/ul>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\">\u00a0<\/h2>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><strong><span style=\"color: #00aeef\">Identified vs. De-Identified Data<\/span><\/strong><\/h2>\n<p><span style=\"color: #000000\">The first question researchers need to ask when working with health data is if they need de-identified or identified data:<\/span><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-content\/uploads\/sites\/342\/2025\/11\/De-ID-and-ID-Figure-e1763589835893.jpg\" \/><\/p>\n<p><span style=\"color: #000000\">Based on this critical decision, the use of identified \/ de-identified data will determine how the IRB protocol, your inclusion\/exclusion criteria, and other project requirements are drafted.<\/span><\/p>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\">\u00a0<\/h2>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><strong><span style=\"color: #00aeef\">Minimum Necessary Information Requirement<\/span><\/strong><\/h2>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\">HIPAA requires that only the minimum necessary information be provided for a specific research question. The minimum necessary rule can be found here:<\/span> <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/guidance\/minimum-necessary-requirement\/index.html\">Minimum Necessary Requirement | HHS.gov<\/a>.<\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\">This is a critical rule to address when getting data for research: projects must have a focused project question, and clear inclusion \/ exclusion criteria. While it&#8217;s tempting to ask for all possible data and explore that data, this can increase the risk to patients if data were accidentally to leak to the public, if it were released through hacking, etc. So, at all times, only the smallest necessary dataset should be provided to researchers to address their questions.\u00a0<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\">Key to this minimum necessary information requirement is well-defined inclusion \/ exclusion criteria. Here&#8217;s an example of some well-defined criteria:<\/span><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-content\/uploads\/sites\/342\/2025\/11\/HIPAA-IRB-slides-for-AIR-MS_Nov_6_2025_ET_3.jpg\" \/><\/p>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\">\u200b<\/h2>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><strong><span style=\"color: #00aeef\">The Institutional Review Board\u00a0<\/span><\/strong><\/h2>\n<ul>\n<li data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\">An <\/span><a href=\"https:\/\/icahn.mssm.edu\/about\/faculty-resources\/handbook\/research\/irb\" data-hyperlinktype=\"0\"><b><span data-usefontface=\"true\" data-contrast=\"none\">IRB<\/span><\/b><\/a><span style=\"color: #000000\"><a style=\"color: #000000\" href=\"https:\/\/icahn.mssm.edu\/about\/faculty-resources\/handbook\/research\/irb\" data-hyperlinktype=\"0\">\u00a0<\/a>is a federally mandated ethics committee that reviews research involving human participants to ensure it is\u00a0<b>ethical, scientifically sound, and minimizes risk<\/b>.\u200b<\/span><\/li>\n<li data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\">The IRB\u2019s mission is to\u00a0<b>protect the rights, welfare, and privacy<\/b>\u00a0of human subjects while supporting responsible scientific advancement.\u200b<\/span><\/li>\n<\/ul>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\">\u00a0<\/h2>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><strong><span style=\"color: #00aeef\">Why the IRB Matters\u200b<\/span><\/strong><\/h2>\n<ul>\n<li data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\"><b>Protects Participants:\u00a0<\/b>Reviews and approves studies to safeguard participants\u2019 rights and well-being.\u200b<\/span><\/li>\n<li data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\"><b>Balances Risk and Benefit:\u00a0<\/b>Evaluates potential risks and ensures they are justified by the expected research benefits.\u200b<\/span><\/li>\n<li data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\"><b>Ensures Ethical Conduct:\u00a0<\/b>Confirms research follows federal regulations, Mount Sinai policies, and ethical standards.\u200b<\/span><\/li>\n<li data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\"><b>Validates Scientific Design:\u00a0<\/b>Reviews study methods to ensure sound, justified, and transparent research practices.\u200b<\/span><\/li>\n<li data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><span style=\"color: #000000\"><b>Crucial Distinction for AIR\u00b7MS Access:\u00a0<\/b>Access to PHI via Artificial Intelligence-Ready Mount Sinai (AIR\u00b7MS) requires IRB approval.<\/span><\/li>\n<\/ul>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\">\u00a0<\/h2>\n<h2 data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:2,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:7.5}\"><strong><span style=\"color: #00aeef\">Frequently Asked Questions<\/span><\/strong><\/h2>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\"><span style=\"color: #000080\"><b>Q: What are HIPAA compliant environments?<\/b><\/span>\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\">A: These are secure systems or platforms that meet HIPAA standards for guarding protected health information through proper encryption, access controls, and auditing.\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\"><span style=\"color: #000080\"><b>Q: What\u2019s the difference between identified and de-identified data?<\/b><\/span>\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\">A:<i> <\/i><i>Identified data<\/i>\u00a0includes personal information that can directly or indirectly identify an individual (e.g., name, date of birth).\u200b<i>De-identified data<\/i>\u00a0has had all identifiers removed so individuals cannot reasonably be identified.\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\"><span style=\"color: #000080\"><b>Q: What is the purpose of the minimum necessary rule?<\/b><\/span>\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\">A: It limits access to or use of PHI to the smallest amount needed to accomplish a task or purpose.\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\"><span style=\"color: #000080\"><b>Q: Where can I learn more about inclusion\/exclusion criteria for datasets at Mount Sinai?<\/b><\/span>\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\">A: You can learn more about inclusion and exclusion criteria for datasets at Mount Sinai by visiting the <a href=\"https:\/\/labs.icahn.mssm.edu\/msdw\/services\/\">Mount Sinai Data Warehouse<\/a> or Research Informatics website, or by contacting the <a href=\"https:\/\/icahn.mssm.edu\/about\/faculty-resources\/handbook\/research\/irb\">Mount Sinai IRB or data governance office<\/a> for specific dataset documentation and guidance.<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\"><span style=\"color: #000080\"><b>Q: How long does IRB protocol approval take?<\/b><\/span>\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\">A: Typically, IRB approval can take anywhere from a few weeks to several months, depending on the complexity of the study and the review type (expedited, exempt, or full board).\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\"><span style=\"color: #000080\"><b>Q: What\u2019s a DUA and why do I need to sign it?<\/b><\/span>\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\">A: A <i>DUA<\/i>\u00a0is a legal contract that governs the sharing of restricted or limited-use data. It protects privacy and\u00a0defines how the data can be used and safeguarded.\u200b<\/span><\/p>\n<p data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559683&quot;:0,&quot;335559685&quot;:0,&quot;335559731&quot;:0,&quot;335559737&quot;:0,&quot;335562764&quot;:2,&quot;335562765&quot;:1,&quot;335562766&quot;:4,&quot;335562767&quot;:0,&quot;335562768&quot;:4,&quot;335562769&quot;:0}\"><span style=\"color: #000000\">\u200b<\/span><\/p>\n<p>\u200b<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p><div class=\"et_pb_row et_pb_row_0 et_pb_row_empty\">\n\t\t\t\t\n\t\t\t\t\n\t\t\t\t\n\t\t\t\t\n\t\t\t\t\n\t\t\t<\/div> Scientific Computing and Data \/ AIR\u00b7MS (AI Ready Mount Sinai) \/ Compliance Overview (HIPAA and IRB Requirements) &nbsp; Compliance Overview: Health Insurance Portability and Accountability Act (HIPAA) and Institutional Review Board (IRB) Requirements\u00a0\u00a0Steps to Obtain IRB Approval and Data Access\u200b\u00a0\u00a0OverviewResearch involves several important compliance steps\u2014such as preparing a strong IRB protocol, defining clear inclusion [&hellip;]<\/p>\n","protected":false},"author":699,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"class_list":["post-12636","page","type-page","status-publish","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-json\/wp\/v2\/pages\/12636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-json\/wp\/v2\/users\/699"}],"replies":[{"embeddable":true,"href":"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-json\/wp\/v2\/comments?post=12636"}],"version-history":[{"count":51,"href":"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-json\/wp\/v2\/pages\/12636\/revisions"}],"predecessor-version":[{"id":12844,"href":"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-json\/wp\/v2\/pages\/12636\/revisions\/12844"}],"wp:attachment":[{"href":"https:\/\/labs.icahn.mssm.edu\/minervalab\/wp-json\/wp\/v2\/media?parent=12636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}