Alabama Clinical Trial eSource Privacy Laws: What Research Site Networks Need to Know

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Alabama Clinical Trial eSource Privacy Laws: What Research Site Networks Need to Know

Kevin Henry

Data Privacy

July 24, 2026

8 minutes read
Share this article
Alabama Clinical Trial eSource Privacy Laws: What Research Site Networks Need to Know

Overview of Alabama Personal Data Protection Act

The Alabama Personal Data Protection Act (referred to here as ALDPA) is Alabama’s comprehensive consumer privacy law, codified at Title 8, Chapter 44 of the Code of Alabama. It establishes baseline obligations for controllers and processors that collect or use personal data about Alabama residents and will take effect on May 1, 2027. For research site networks, this law operates alongside HIPAA and FDA rules and can apply to non‑PHI data associated with eSource workflows (for example, patient portals, recruitment sites, or analytics). ([alison.legislature.state.al.us](https://alison.legislature.state.al.us/code-of-alabama?section=8-44-1&utm_source=openai))

Scope and thresholds

ALDPA applies to entities doing business in Alabama or targeting Alabama residents that either control or process the personal data of more than 25,000 consumers, or derive 25% or more of gross revenue from the sale of personal data (regardless of consumer count). Importantly, certain data types are exempt—most notably Protected Health Information (PHI) subject to HIPAA—so ALDPA typically does not regulate PHI itself but may govern adjacent, non‑PHI data processed by research networks. ([whitecase.com](https://www.whitecase.com/insight-alert/alabama-enacts-comprehensive-data-privacy-law?utm_source=openai))

ALDPA’s exemptions for specific activities and data include processing for public interest in public health and other carved‑out contexts; covered entities relying on such exemptions bear the burden of demonstrating that their processing qualifies. ([alison.legislature.state.al.us](https://alison.legislature.state.al.us/code-of-alabama?section=8-44-10&utm_source=openai))

Consumer Rights under ALDPA

Rights you must operationalize

  • Access and confirmation: Provide consumers with confirmation of processing and access to their personal data.
  • Correction and deletion: Enable consumers to correct inaccuracies and request deletion of personal data, subject to limited exceptions.
  • Data Portability Rights: Supply a portable, readily usable copy of personal data the consumer provided, where technically feasible.
  • Opt‑out: Offer clear means to opt out of targeted advertising, sale of personal data, and certain profiling. ([keepinglawsimple.org](https://www.keepinglawsimple.org/area/alabama/bill/2026/HB351))

Request handling and authentication

ALDPA requires controllers to provide secure, reliable methods for submitting rights requests and forbids forcing consumers to create a new account to exercise those rights. Controllers must authenticate requesters and describe request channels in their privacy notices. State law references an opt‑out mechanism and prescribes timing standards (e.g., a 45‑day window noted in legislative summaries) for responses. ([alison.legislature.state.al.us](https://alison.legislature.state.al.us/code-of-alabama?section=8-44-7&utm_source=openai))

Roles of controllers and processors

Research site networks may act as controllers when they determine purposes and means of processing (for example, operating an eSource platform across sites), or as processors when handling data under a sponsor’s documented instructions. Align contracts to ALDPA’s controller–processor requirements and ensure processors implement appropriate technical and organizational measures.

HIPAA Privacy Rule for Clinical Trials

Lawful bases for using PHI in research

Under the HIPAA Privacy Rule, a covered entity may use or disclose PHI for research with an individual’s HIPAA authorization (45 CFR 164.508) or without authorization if an Institutional Review Board (IRB) or Privacy Board approves a waiver or alteration under 45 CFR 164.512(i). Limited pathways also exist for preparatory‑to‑research activities and research on decedents’ PHI, all subject to the “minimum necessary” standard where applicable. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/research/index.html?utm_source=openai))

Participant access and eSource

Participants generally have a right to access PHI, but during a clinical trial they may agree to temporarily suspend access to records created in the trial; that access must be reinstated once the study ends. Build eSource workflows and participant communications to reflect this nuance. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/standards-privacy-individually-identifiable-health-information/index.html?utm_source=openai))

Operational implications

For eSource systems, document HIPAA authorizations (or IRB/Privacy Board waivers), apply minimum‑necessary disclosures, maintain audit trails of access and edits, and ensure all service providers with access to PHI are subject to Business Associate Agreements. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/318/does-hipaa-require-documentation-of-irb-or-privacy-board-approval/index.html?utm_source=openai))

Privacy and Security Measures of Alabama One Health Record

Alabama One Health Record (OHR) is the state’s health information exchange that enables authorized providers to securely share medical information and access a longitudinal patient record through a web‑enabled login. Its operations are designed to comply with HIPAA and support secure care coordination across the state. ([onehealthrecord.alabama.gov](https://www.onehealthrecord.alabama.gov/HealthInformationExchange.aspx?utm_source=openai))

Security posture you can leverage

OHR implements encryption and Direct Secure Messaging for protected exchange and has achieved HITRUST Common Security Framework (CSF) Certification—an assurance signal many research networks recognize when integrating HIE connections into their Clinical Trial Data Security programs. Technical materials also note use of recognized security standards (e.g., OASIS WS‑Security). ([onehealthrecord.alabama.gov](https://onehealthrecord.alabama.gov/RecipientPrivacyandSecurity.aspx?utm_source=openai))

Integration considerations for research networks

When connecting eSource or EDC tools to OHR, validate the data minimization approach, role‑based access, and consent flows. Ensure your participation agreements and internal SOPs reflect how data from OHR will be used in research and how consumer rights (where applicable) will be handled alongside HIPAA duties. ([onehealthrecord.alabama.gov](https://onehealthrecord.alabama.gov/Content/uploads/AHIE-Policies-And-Procedures%20Latest.pdf?utm_source=openai))

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Genetic Data Privacy Regulations in Alabama

Alabama’s Genetic Data Privacy Act (Title 8, Chapter 43; 2024) focuses on direct‑to‑consumer genetic testing companies. It requires prominent privacy notices, initial express consent for specified uses, separate express consent for additional uses or disclosures, and informed consent consistent with 45 CFR Part 46 when genetic data are used for research. Consumers must be able to access their data, delete accounts, and request destruction of samples; contractors are bound to the same confidentiality obligations. ([law.justia.com](https://law.justia.com/codes/alabama/title-8/chapter-43/section-8-43-3/?utm_source=openai))

The Act restricts disclosures of genetic data to insurers and employers without express written consent. For research site networks, implications arise when partnering with or importing data from genetic testing companies; ensure Genetic Data Consent aligns with research purposes and your broader HIPAA/ALDPA posture. ([law.justia.com](https://law.justia.com/codes/alabama/title-8/chapter-43/section-8-43-4/?utm_source=openai))

Confidentiality of Patient Records in State Registries

Alabama’s State Administrative Codes and program rules impose strict confidentiality for state registries (for example, the Alabama Statewide Cancer Registry and the immunization registry, ImmPRINT). Access for research typically requires formal review and agreements, with patient‑specific data protected against public disclosure. ([law.cornell.edu](https://www.law.cornell.edu/regulations/alabama/title-420/chapter-420-7-3?utm_source=openai))

Research access pathways

The cancer registry allows controlled releases for research after proposal review, IRB approvals, and confidentiality agreements; guidance emphasizes de‑identification where possible and safeguards against residual disclosure. ([law.cornell.edu](https://www.law.cornell.edu/regulations/alabama/Ala-Admin-Code-r-420-7-3-.06?utm_source=openai))

Public health reporting and HIPAA

Notifiable disease reporting to the Alabama Department of Public Health is mandated by law; ADPH operates as a public health authority under HIPAA, permitting certain PHI disclosures without patient authorization for surveillance and investigation. ([law.justia.com](https://law.justia.com/codes/alabama/title-22/title-1/chapter-11a/article-1/section-22-11a-2/?utm_source=openai))

eSource Implementation Compliance in Clinical Trials

Build a unified compliance map

  • Data mapping: Classify all eSource data by type (PHI vs. non‑PHI personal data) to determine which regime applies—HIPAA, ALDPA, the Genetic Data Privacy Act, or registry rules.
  • Roles and contracts: Define whether you are a controller or processor under ALDPA, execute DPAs where needed, and maintain BAAs for PHI.
  • Record integrity: Validate systems and maintain complete audit trails, electronic signatures, and change histories to meet FDA expectations under 21 CFR Part 11 and related eSource guidance. ([fda.gov](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/part-11-electronic-records-electronic-signatures-scope-and-application?lng=en-US&ss=page_is-an-electronic-signature-legal_undefined&utm_source=openai))
  • Security by design: Align controls to the HITRUST Common Security Framework—identity and access management, encryption in transit/at rest, privileged access monitoring, incident response, and vendor risk management—to strengthen Clinical Trial Data Security.
  • Rights operations: Build workflows to intake, authenticate, and fulfill ALDPA consumer requests (including Data Portability Rights) for non‑PHI data while preserving HIPAA’s rules for PHI.
  • Registry interfaces: When sending data to state registries, follow applicable State Administrative Codes and program SOPs for confidentiality and research access.

Conclusion

In Alabama, clinical trial eSource programs sit at the intersection of ALDPA, HIPAA, state registries, and FDA expectations. Map your data, define controller‑processor roles, engineer to Part 11 and HITRUST CSF, and operationalize consumer rights for non‑PHI—all while preserving HIPAA’s research pathways and registry confidentiality. This integrated approach keeps your network compliant and your data trustworthy. ([alison.legislature.state.al.us](https://alison.legislature.state.al.us/code-of-alabama?section=8-44-1&utm_source=openai))

FAQs

What entities are subject to ALDPA requirements?

ALDPA covers entities that do business in Alabama or target Alabama residents and either control or process data of more than 25,000 consumers or derive at least 25% of gross revenue from the sale of personal data. Exemptions include PHI under HIPAA and certain other regulated data types, so PHI is generally outside ALDPA; non‑PHI data linked to trials (for example, recruitment or portal analytics) can be in scope. ([whitecase.com](https://www.whitecase.com/insight-alert/alabama-enacts-comprehensive-data-privacy-law?utm_source=openai))

How does HIPAA affect access to clinical trial data?

PHI used in research typically requires HIPAA authorization, or an IRB/Privacy Board waiver under 45 CFR 164.512(i). Participants may agree to a temporary suspension of access to research records during a trial, with access restored once the trial ends; build eSource processes to honor that timing. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/research/index.html?utm_source=openai))

What security measures protect eSource data in Alabama?

Core controls include encryption, strong identity and access management, audit trails, and vendor due diligence. Alabama’s One Health Record reinforces secure exchange using Direct Secure Messaging and has HITRUST CSF Certification—useful signals when integrating HIE data into your eSource ecosystem and broader HITRUST‑aligned security program. ([onehealthrecord.alabama.gov](https://onehealthrecord.alabama.gov/Technology.aspx?utm_source=openai))

How does the Alabama Genetic Data Privacy Act impact research data use?

Direct‑to‑consumer genetic testing companies must provide clear privacy notices, obtain express consent for specified uses and disclosures, and secure informed consent aligned with 45 CFR Part 46 for research. Consumers can access their data, delete accounts, and request destruction of samples; contractors are bound by equivalent confidentiality duties. If your research imports such data, verify that required Genetic Data Consent exists and that downstream uses match the consents obtained. ([law.justia.com](https://law.justia.com/codes/alabama/title-8/chapter-43/section-8-43-3/?utm_source=openai))

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles