How to Evaluate HIPAA Risk Before Sharing ePHI with a University Research Partner Under a DUA
Before you disclose electronic protected health information (ePHI) to a university research partner, you need a deliberate, defensible approach that balances scientific goals with HIPAA compliance. This guide shows you how to evaluate HIPAA risk under a Data Use Agreement (DUA) and implement practical controls that keep data safe while enabling research.
Understanding Data Use Agreements
A Data Use Agreement defines exactly how a university partner may handle the data you disclose, with special emphasis on a Limited Data Set and its permitted uses. It translates legal and policy obligations into operational terms that researchers can follow and auditors can verify.
Key elements to confirm
- Purpose and scope: the research aims, data categories (e.g., Limited Data Set), and minimum necessary standard.
- Authorized Users: named roles or individuals permitted to access the data, including how new users are approved and trained.
- Permitted uses and disclosures: what analyses are allowed, whether results may be shared, and any publication conditions.
- Re-disclosure controls: prohibitions on passing data to third parties without prior written approval.
- Re-identification Restrictions: explicit bans on attempting to identify individuals or contacting them.
- Data Safeguards: administrative, physical, and technical protections aligned with the HIPAA Security Rule.
- Reporting Requirements: timelines, contacts, and content for incident and breach notifications.
- Retention and destruction: how long data may be kept, secure storage requirements, and verifiable destruction methods.
- Audit and oversight: rights to inspect controls, review logs, and require corrective action.
Aligning the DUA with the research plan
Ensure the dataset description, analysis methods, and sharing boundaries in the protocol match the DUA terms. If you are disclosing a Limited Data Set, the DUA must reflect its identifiers, permitted linkages, and strict Re-identification Restrictions.
Conducting ePHI Risk Assessments
A structured risk assessment under the HIPAA Security Rule helps you spot threats before data moves. Treat this as both a security risk analysis and an ePHI Vulnerability Assessment focused on research workflows and tools.
Step-by-step approach
- Inventory assets: systems, applications, storage locations, and users that will handle ePHI at both institutions.
- Map data flows: how data is extracted, transferred, processed, analyzed, and archived, including any cloud or HPC use.
- Identify threats and vulnerabilities: unauthorized access, misconfiguration, credential theft, insecure code, and data linkage risks.
- Evaluate likelihood and impact: rate inherent risk, then note existing controls that reduce it.
- Define treatments: add or strengthen controls, narrow the dataset, or change the processing model (e.g., secure enclave).
- Document and validate: record decisions, residual risk, and sign-offs by Privacy and Security Officers.
Depth checks for research environments
- Access channels: remote access, shared workstations, and lab devices used by students and visiting scholars.
- Toolchain risk: statistical software, notebooks, and scripts; review package provenance and data export settings.
- Data lifecycle: interim files, caches, backups, and logs that might inadvertently store ePHI.
Reviewing Institutional Policies
Your risk posture depends on how well your partner’s rules align with yours. Require written policies and proof that operational practices meet those policies—especially for trainees and cross-appointed researchers.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk AssessmentDocuments to request and reconcile
- Information security program and HIPAA training standards for all Authorized Users.
- Acceptable use, account provisioning, and termination procedures for research staff.
- Incident response and breach handling, including Reporting Requirements and escalation paths.
- Data management plan: retention, destruction, and publication review processes.
- IRB/Privacy Board determinations and minimum necessary rationale for a Limited Data Set.
- Device, encryption, and endpoint management policies (e.g., mobile, BYOD, removable media).
Implementing Safeguards for ePHI
Translate the assessment into layered Data Safeguards that make inappropriate access unlikely and detectable. Use administrative, technical, and physical protections that reflect the HIPAA Security Rule.
Administrative safeguards
- Access governance: approve and review Authorized Users, least privilege, and role-based access controls.
- Training and attestations: annual HIPAA training plus project-specific handling rules under the DUA.
- Change management: define how tools, locations, or personnel changes trigger re-approval.
Technical safeguards
- Strong authentication: MFA for all remote and privileged access; unique credentials, no sharing.
- Encryption: protected transfer (e.g., SFTP or HTTPS) and encryption at rest in approved environments.
- Segmentation and secure enclaves: isolate research data; disable general internet egress where feasible.
- Logging and monitoring: capture access, queries, and exports; alert on anomalies and failed logins.
- Data loss prevention: block unauthorized exports; require vetted, auditable analysis tools.
Physical safeguards
- Controlled spaces: locked labs, restricted server rooms, and clean desk practices.
- Device protection: managed endpoints with patching, disk encryption, and port/USB controls.
Establishing Reporting and Compliance Procedures
Clear, practiced procedures ensure fast, compliant responses when something goes wrong. Your DUA should specify Reporting Requirements and how the parties coordinate investigations and notifications.
What your plan should include
- Triggers and timelines: define incidents that must be reported and the timeframes for notification.
- Contacts and roles: named privacy, security, and research leads at both institutions.
- Content of reports: what happened, systems and data affected, number of records, containment, and mitigation steps.
- Forensic handling: preserve logs and evidence; suspend risky processes; restrict access pending review.
- Corrective actions: user re-training, control updates, and re-validation before resuming data use.
- Ongoing assurance: periodic attestations, access recertification, and audit rights execution.
Restricting Re-identification Risks
Even a Limited Data Set can be re-identified when combined with external data. Use technical and contractual Re-identification Restrictions to make re-linkage impractical and noncompliant.
Practical risk-reduction tactics
- Minimize features: share only what the analysis truly needs; generalize dates and locations when possible.
- Control linkages: prohibit joining to external datasets unless expressly approved and documented.
- Protect keys: store any code-to-identity keys separately with stricter controls and limited custodians.
- Output governance: review tables and figures for small-cell risk before publication or sharing.
- Safe environments: prefer query-only or enclave models that restrict raw data exports.
Conclusion
Evaluate HIPAA risk by nailing the DUA terms, performing a focused ePHI Vulnerability Assessment, aligning institutional policies, deploying layered Data Safeguards, enforcing strong Reporting Requirements, and hardening against re-identification. This disciplined approach lets you collaborate with a university research partner while protecting individuals and your organization.
FAQs
What is a Data Use Agreement in the context of ePHI sharing?
A DUA is a written contract that governs how a university partner may use and protect data you disclose for research, especially a Limited Data Set. It names Authorized Users, defines permitted uses, sets Data Safeguards and Reporting Requirements, and imposes strict Re-identification Restrictions.
How do you perform a risk assessment for ePHI under HIPAA?
Identify systems and users, map data flows, and run an ePHI Vulnerability Assessment to find threats and weaknesses. Rate likelihood and impact, align controls to the HIPAA Security Rule, remediate gaps, document residual risk, and obtain leadership sign-off. Reassess when tools, personnel, or scope change.
What safeguards are required under a DUA to protect ePHI?
Typical requirements include role-based access for Authorized Users, MFA, encryption in transit and at rest, network segmentation, logging, secure transfer and storage, validated analysis tools, training, and verifiable destruction. These Data Safeguards should map directly to HIPAA Security Rule standards.
How should inappropriate disclosures of ePHI be reported?
Report immediately to the contacts named in the DUA, and within the timeframe it specifies. Provide incident details, affected data, containment and mitigation steps, and supporting logs. Work with privacy and security officers to assess breach status, complete notifications if required, and implement corrective actions.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk Assessment