Data Security and Confidentiality Guidelines for Clinical Research at Sparrow Health System Introduction This document was created to give you guidelines to follow in order to ensure that all confidential health information is protected as you procure, use, transfer, and store the data to complete your project. If you have additional questions after reading this document, a reference list is provided at the end to help you find answers to your questions or you may contact the IRB Office or Privacy Department. Guidelines for Data Procurement • Follow all Institutional Review Board (IRB) policies and procedures when requesting data located in Policy and Procedure Manual (PPM) • Limit your data requests to the minimum necessary. The minimum necessary standard is the minimum necessary to accomplish the intended purpose of the project. For example, do not collect age and date of birth if collecting age only will meet the intended purpose of the project. De-identify data using one of the two approved methods: the statistical method or the “safe harbor” method. See HIPAA Policy, HP-22, De-identified Information and Department of Health and Human Services De-identification Guidelines for more information. • Follow the correct path to data procurement – direct all inquiries for data to Sparrow’s Data Analytics Department. You can complete the general report request and email the completed form to Sparrow’s IT HelpDesk at
[email protected]. Your request will then be forwarded to the Data Analytics Department. (Note: Case studies are excluded from this requirement.) • Use of Protected Health Information Preparatory to Research - an investigator may review protected health information solely to prepare a research protocol, or for similar purposes preparatory to research.