HIPAA Training for Research Coordinators: How to Safely Access and Manage Identifiable Study Data (PHI)

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Training for Research Coordinators: How to Safely Access and Manage Identifiable Study Data (PHI)

Kevin Henry

HIPAA

August 25, 2026

8 minutes read
Share this article
HIPAA Training for Research Coordinators: How to Safely Access and Manage Identifiable Study Data (PHI)

As a research coordinator, you sit at the intersection of participant care, data integrity, and privacy. This guide shows you how to meet HIPAA requirements, access only the PHI you need, and implement practical controls that keep identifiable study data secure without slowing research.

HIPAA Training Requirements for Research Coordinators

Your HIPAA training should be role-based and completed before you handle any PHI, with refreshers at regular intervals or when policies change. Core modules must cover the HIPAA Privacy Rule, Security Rule, breach reporting, the minimum necessary standard, and your site’s PHI Access Controls.

  • Understand permissible uses/disclosures for research and how they differ from treatment, payment, and operations.
  • Recognize when a HIPAA Authorization is required versus when an Institutional Review Board Waiver or alteration applies.
  • Learn the difference between de-identified data, a Limited Data Set, and fully identifiable PHI, including when a Data Use Agreement is required.
  • Review device, email, messaging, and storage rules; know how to report a suspected incident immediately.
  • Sign and follow Confidentiality Agreements, and complete any study-specific privacy training required by sponsors or institutions.

Document completion dates, curricula, and competency checks in your training file. Keep those records current; auditors will ask for them.

Obtaining and Managing HIPAA Authorizations

Before you create, use, or disclose identifiable PHI for research, you typically need a signed HIPAA Authorization. Use a form that clearly states what information will be used, who may disclose and receive it, the research purpose, expiration (date or event), the participant’s right to revoke, and the participant’s signature and date.

Practical steps

  • Combine the HIPAA Authorization with the consent document if permitted, or maintain a separate signed form.
  • Capture signatures in person or via approved e-consent tools; record who obtained consent, when, and under what protocol.
  • Store signed Authorizations in your regulatory binder or eReg system, indexed by subject ID and visit date.
  • Track expirations and revocations. If a participant revokes, stop new uses/disclosures immediately and document what must be retained for integrity or oversight.

When a waiver or alteration applies

An IRB or Privacy Board may grant an Institutional Review Board Waiver or alteration when privacy risks are minimal, the research is impracticable without the waiver and without PHI, and there are adequate safeguards. Keep the approval letter, protocol identifiers, and any conditions with your study records and reference the waiver each time you access PHI under it.

De-Identification and Limited Data Sets

Two pathways to de-identification

  • Safe Harbor: remove all direct and quasi-identifiers specified by HIPAA.
  • Expert Determination: a qualified expert documents that re-identification risk is very small with applied methods and context.

Identifiers to remove under Safe Harbor

  • Names; geographic subdivisions smaller than a state (with limited ZIP code exceptions); all elements of dates (except year) related to an individual.
  • Telephone, fax, email; Social Security, medical record, health plan, and account numbers; certificate/license numbers.
  • Vehicle and device identifiers/serials; URLs and IP addresses; biometric identifiers; full-face photos and comparable images; any other unique codes.

Limited Data Set (LDS) and Data Use Agreement

An LDS may include city, state, ZIP, and dates (for example, admission or procedure dates) but excludes direct identifiers like names and contact details. Sharing or receiving an LDS requires a Data Use Agreement that restricts who may use the data, for what purpose, how it is safeguarded, and prohibits re-identification or re-disclosure.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Operational tips

  • Map data flows before extraction; create a redaction plan; validate outputs with spot checks.
  • When coding data, store the linkage key separately with tightened PHI Access Controls and limited personnel access.
  • Reassess re-identification risk when datasets are combined or when small-cell sizes could expose identities.

Data Sharing and Business Associate Agreements

When you need a Data Use Agreement

Use a Data Use Agreement when sharing or receiving a Limited Data Set across organizations. A DUA specifies permitted uses, user roles, safeguards, reporting obligations, and return or destruction at project end.

When you need a Business Associate Agreement

A Business Associate Agreement is required when a vendor or service provider performs functions involving PHI on behalf of a covered entity or its hybrid component (for example, cloud storage, eConsent platforms, transcription). Research collaborators who are not performing services for you are typically covered by Authorizations, waivers, or a DUA—not a BAA.

Confidentiality Agreements vs. DUA/BAA

Confidentiality Agreements support privacy culture but do not replace a DUA or BAA. Use them to bind workforce members, observers, or non-PHI contributors to privacy expectations alongside the appropriate data-sharing instrument.

Pre-sharing checklist

  • Confirm legal basis: HIPAA Authorization, Institutional Review Board Waiver, or Limited Data Set with Data Use Agreement.
  • Execute the right contract (BAA or DUA) before any transfer; verify recipient identity and role.
  • Share via approved, encrypted channels; avoid personal email or consumer cloud tools.
  • Log the disclosure and retention period; set reminders for timely data destruction or return.

Implementing Data Security Measures

PHI Access Controls

  • Apply role-based access so users see only the minimum necessary PHI for their tasks.
  • Use unique user IDs, multi-factor authentication, and session timeouts on systems with PHI.
  • Restrict access to coding keys and master subject lists to a small, need-to-know group.

Endpoint and storage protections

Transfer, sharing, and collaboration

  • Use secure transfer tools for datasets; never paste PHI into chat or messaging apps lacking a BAA.
  • Label files containing PHI or an LDS; apply watermarking or access expiration where available.

Monitoring and incident response

  • Enable audit logs on systems with PHI and review for anomalies.
  • If you suspect a breach, contain, report to your privacy/security office immediately, and document actions taken.

Accessing PHI on a Need-to-Know Basis

Apply the minimum necessary standard every time you view, download, or share PHI. Ask yourself whether each data element is essential for your task and whether a de-identified extract or Limited Data Set would suffice.

Examples

  • Appropriate: viewing contact information solely to schedule a study visit for a consented participant.
  • Inappropriate: browsing a friend’s chart, pulling complete records when only lab dates are needed, or sharing full notes when a problem list would do.

Handling ad hoc requests

  • Verify the requester’s role and legal basis (Authorization, waiver, or TPO exception).
  • Use “break-the-glass” workflows only when policy permits and always document the justification.

Maintaining PHI Disclosure Records

Maintain an accounting of disclosures for uses not related to treatment, payment, or operations. For research, log disclosures made under a waiver or as required by law, and maintain records that let you answer participant inquiries accurately.

What to capture

  • Date, recipient, and a brief description of the PHI disclosed.
  • Purpose and legal basis (HIPAA Authorization, Institutional Review Board Waiver, court order, etc.).
  • Protocol number, subject ID range or count, and the method of transfer.

How to organize

  • Use subject-level logs for individualized disclosures.
  • For large studies, maintain a protocol-level accounting that includes the study scope and time frames.

Retention and retrieval

  • Retain disclosure records for at least six years from the disclosure date or record creation, whichever is later.
  • Be prepared to furnish an accounting upon request; test your ability to retrieve complete logs promptly.

In practice, strong PHI Access Controls, clear legal bases (HIPAA Authorization, Institutional Review Board Waiver, or Limited Data Set with a Data Use Agreement), and disciplined logging form a durable privacy framework that enables high-quality research while protecting participants.

FAQs

What HIPAA training is mandatory for research coordinators?

You need role-based Privacy and Security Rule training before handling PHI, with periodic refreshers. Training should cover minimum necessary, PHI Access Controls, Authorizations and IRB waivers, de-identification vs. Limited Data Sets, reporting incidents, and secure communication/storage practices. Keep completion records and any required Confidentiality Agreements in your training file.

How should HIPAA Authorizations be obtained and documented?

Use your institution-approved form or combined consent/Authorization. Present it in plain language, ensure the participant understands what PHI will be used, and obtain a signature and date (in person or via approved e-consent). File the signed Authorization in the regulatory binder or eReg, log the action, track expirations, and document any revocations and their effective dates.

When is a Data Use Agreement required in research?

A Data Use Agreement is required whenever you share or receive a Limited Data Set across organizations. It defines permitted uses, safeguards, authorized users, reporting obligations, and return/destruction. You do not need a DUA for fully de-identified data, and you typically use a HIPAA Authorization or IRB waiver—not a DUA—when sharing fully identifiable PHI for research.

How can data be properly de-identified to comply with HIPAA?

Follow one of two methods: remove all Safe Harbor identifiers or obtain an Expert Determination that re-identification risk is very small. Validate outputs, store any linkage key separately with strict access controls, avoid small cells that could reveal identities, and reassess risk when combining datasets or adding new variables.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles