Is Roam Research HIPAA Compliant for Research Coordinators Keeping Daily Logs with Names?
HIPAA Compliance Overview
Under the Health Insurance Portability and Accountability Act, you may only store Protected Health Information with vendors that meet HIPAA requirements. PHI is individually identifiable health information created or received by a covered entity or its business associate and related to health, care delivery, or payment.
What counts as PHI in daily logs
Names are one of HIPAA’s direct identifiers. A daily research log that lists participant names alongside study activities, visit status, symptoms, dosing, or scheduling becomes PHI because identity is linked to health-related context. Even a note like “John Doe—missed morning dose” constitutes PHI.
When HIPAA applies in research
HIPAA applies when research is conducted by, or on behalf of, a covered entity (for example, a hospital or health plan) or when a vendor stores or processes PHI for that entity. If your logs include identifiable study data derived from clinical operations, you must treat the workspace as PHI and apply HIPAA Security Rule controls.
Bottom line: storing names in daily logs typically triggers HIPAA unless the data are fully de-identified. To use a cloud note system for PHI, a signed Business Associate Agreement is required and appropriate security controls must be in place.
Roam Research Business Associate Agreement
Why you need a BAA with Roam
A Business Associate Agreement formalizes Roam Research’s obligations to safeguard PHI, restrict use and disclosure, and report incidents. Without a BAA, a cloud note platform cannot act as a business associate, and you should not store PHI—including names tied to study context—in that system.
What to confirm in the BAA
- Scope of services and permitted uses of PHI.
- Security Controls aligned to the HIPAA Security Rule (access control, encryption, audit logging, incident response).
- Breach notification timelines and cooperation duties.
- Subprocessor oversight and flow-down obligations.
- Return or destruction of PHI at contract end.
- Right to receive summaries of audits/assessments (for example, a SOC 2 Type II Audit report).
If a BAA is not available
Do not enter PHI into Roam. Use subject IDs or coded data, keep the linkage file in a HIPAA-compliant system, and document that no PHI touches the note workspace. This preserves Data Confidentiality while allowing operational notes to continue.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
SOC 2 Type II Audit Details
What a SOC 2 Type II covers
A SOC 2 Type II Audit evaluates whether a service provider’s controls operated effectively over a defined period. Reports are mapped to Trust Services Criteria such as Security, Availability, Confidentiality, Processing (operational) integrity, and Privacy.
How to use a SOC 2 report in HIPAA due diligence
- Verify the audit period, scope, and in-scope systems that would store your research notes.
- Review control tests for access control, change management, vulnerability management, and encryption in transit/at rest.
- Check noted exceptions and management’s remediation to gauge residual risk.
- Map relevant controls to your HIPAA risk analysis and risk management plan.
Limits of SOC 2 for HIPAA
SOC 2 Type II supports assurance on Security Controls and Operational Integrity but is not a substitute for a BAA or a HIPAA-specific assessment. You still need vendor commitments in contract, configuration hardening, and ongoing monitoring.
Security Measures and Data Protection
Security controls to expect from a cloud note platform
- Encryption in transit (TLS) and encryption at rest using strong, industry-standard ciphers.
- Role-based access control, least privilege, and workspace-level permissions.
- Multi-factor authentication and, where available, Single Sign-On with enforced policies.
- Comprehensive audit logs for access, sharing, exports, and administrative changes.
- Backups, disaster recovery, and tested incident response procedures.
- Secure software development lifecycle, vulnerability scanning, and independent testing.
- Data lifecycle controls: retention settings, secure deletion, export governance, and customer data return on exit.
Data confidentiality and operational integrity in practice
To maintain Data Confidentiality, ensure that only authorized coordinators can access the PHI workspace and that exports are encrypted at rest off-platform. For Operational Integrity, monitor logs, validate backups, and routinely test recovery so study operations can continue during disruptions.
Using Roam for PHI Management
Configure the workspace
- Create a dedicated research workspace for PHI; disable public or shared links and restrict invites.
- Apply least-privilege roles and require MFA for all users. Review access before each study phase.
- Standardize daily log templates to minimize free-text PHI; prefer structured fields and tags.
Control data flow
- Use subject codes in daily notes; keep the code key in a separate HIPAA-compliant system.
- Govern exports and backups. If exports are required, encrypt files and store them in approved repositories.
- Audit for accidental PHI spill into personal pages, pinned notes, or unmanaged devices.
Ongoing oversight
- Run periodic access reviews and reconcile membership with active study staff.
- Log and investigate policy violations (for example, unapproved sharing or bulk exports).
- Document all controls in your research SOPs and training records.
Steps to Request a BAA
- Describe your use case: PHI types, data volume, and required features (logging, retention, SSO/MFA).
- Contact the vendor’s sales or compliance team to request a Business Associate Agreement and security documentation (for example, SOC 2 Type II summary, penetration test letter).
- Perform a HIPAA risk analysis mapping vendor Security Controls to your safeguards.
- Negotiate BAA terms: breach notice windows, subcontractor management, and data return/destruction.
- Obtain internal approvals from Privacy, Security, and Legal; then execute the BAA.
- Configure the workspace according to your policy (MFA, RBAC, export controls) before ingesting PHI.
- Monitor and re-assess annually or when the service or study scope changes.
Best Practices for Research Coordinators
- Default to de-identification. Use names only when necessary and justified by protocol or operations.
- Keep the subject-code key outside the note system used for daily logs.
- Implement strong authentication, device encryption, and auto-lock on all endpoints.
- Write concise, purposeful entries to reduce PHI sprawl; avoid duplicating identifiers across pages.
- Review audit logs weekly; document corrective actions for anomalies.
- Align notes with IRB-approved practices and your HIPAA policies; update templates when protocols change.
- Maintain an exit plan: how you will export, return, or destroy PHI at study closeout.
FAQs.
Is a Business Associate Agreement required to use Roam for PHI?
Yes. If your daily logs include PHI—such as participant names linked to study or clinical information—you must have a signed BAA with the vendor before storing that data. Without a BAA, do not put PHI in the system.
Can Roam securely store names in daily logs?
Names are identifiers. Storing them is only appropriate if a BAA is in place and the workspace is configured with strong Security Controls (MFA, RBAC, logging, encryption) and governed by your HIPAA policies. If you lack a BAA, use subject codes and keep the linkage elsewhere.
What security standards does Roam comply with?
Compliance claims can change. Request current documentation directly from the vendor—such as a SOC 2 Type II Audit report summary and security whitepaper—and confirm how those controls support HIPAA requirements in your risk analysis.
How can research coordinators ensure HIPAA compliance with Roam?
Secure a BAA, minimize PHI in notes, enforce MFA and least-privilege access, govern exports and backups, review audit logs, and document procedures in SOPs. Use subject codes by default and keep the code key in a separate HIPAA-compliant system.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.