{"id":729,"date":"2018-05-02T08:50:54","date_gmt":"2018-05-02T08:50:54","guid":{"rendered":"https:\/\/az.research.umich.edu\/medschool\/document\/handling-patient-data-general-security-guidelines\/"},"modified":"2025-12-08T09:50:35","modified_gmt":"2025-12-08T14:50:35","slug":"handling-patient-data-general-security-guidelines","status":"publish","type":"document","link":"https:\/\/az.research.umich.edu\/medschool\/informational\/handling-patient-data-general-security-guidelines\/","title":{"rendered":"Handling Patient Data General Security Guidelines"},"template":"","categories":[58],"tags":[],"content-type":[5],"topic":[45,66],"update-type":[],"class_list":["post-729","document","type-document","status-publish","hentry","category-data-office-for-clinical-translational-research","content-type-informational","topic-hipaa-protected-health-information","topic-investigator-study-team-responsibilities"],"acf":{"use_legacy_editor":true,"updated_date":"2025-12-05 14:00:00","update_notice":false,"author":"Data Office","summary":"Use of patient health data for research is a distinct privilege \u2013 not a right. To minimize the <a class=\"gtip\" href=\"\/medschool\/glossary\/risk\">risk<\/a> of unauthorized disclosure of patient data and other sensitive information, data security must be a top priority for\u00a0all.\u00a0<a class=\"gtip\" href=\"\/medschool\/glossary\/research\">Research<\/a> performed at the\u00a0University of Michigan is governed by related institutional and federal policies.","button_links":null,"related_content":"","legacy_path":"handling-patient-data-general-security-guidelines","legacy_node_id":258,"legacy_related_nids":"","legacy_content_section":[{"legacy_section_type":"heading","legacy_heading":"Guidance For Safe Data Handling","legacy_subheading":"","legacy_section_text":"","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"text_area","legacy_heading":"","legacy_subheading":"","legacy_section_text":"<table style=\"border-collapse: collapse;width: 100%;height: 304px\">\r\n<tbody>\r\n<tr style=\"height: 25px\">\r\n<td style=\"width: 50%;text-align: center;height: 25px\"><span style=\"color: #75988d\"><strong>DO'S<\/strong><\/span><\/td>\r\n<td style=\"width: 50%;text-align: center;height: 25px\"><span style=\"color: #9a3324\"><strong>DONT'S<\/strong><\/span><\/td>\r\n<\/tr>\r\n<tr style=\"height: 51px\">\r\n<td style=\"width: 50%;height: 51px\">Use a secure file share solution like <a href=\"https:\/\/its.umich.edu\/communication\/collaboration\/dropbox\">DropBox<\/a><\/td>\r\n<td style=\"width: 50%;height: 51px\">Ever e-mail files with\u00a0<a href=\"https:\/\/az.research.umich.edu\/medschool\/glossary\/protected-health-information-phi\">PHI<\/a>, even if using a secure Michigan Medicine Outlook e-mail account<\/td>\r\n<\/tr>\r\n<tr style=\"height: 51px\">\r\n<td style=\"width: 50%;height: 51px\">All data should be stored on a secured shared drive or within an approved\u00a0<a href=\"https:\/\/az.research.umich.edu\/medschool\/glossary\/umhs\">MM<\/a> environment<\/td>\r\n<td style=\"width: 50%;height: 51px\">Save files to your desktop<\/td>\r\n<\/tr>\r\n<tr style=\"height: 25px\">\r\n<td style=\"width: 50%;height: 25px\" width=\"288\">All data files must be encrypted<\/td>\r\n<td style=\"width: 50%;height: 25px\">Remove password protection<\/td>\r\n<\/tr>\r\n<tr style=\"height: 76px\">\r\n<td style=\"width: 50%;height: 76px\">Place participant identifier (MRNs names, addresses) data, and crosswalk key in separate, password-protected files<\/td>\r\n<td style=\"width: 50%;height: 76px\">Share the crosswalk of identifiers<\/td>\r\n<\/tr>\r\n<tr style=\"height: 76px\">\r\n<td style=\"width: 50%;height: 76px\">Know the details of the IRB approval<\/td>\r\n<td style=\"width: 50%;height: 76px\">Collect more data than approved or share data with individuals not listed as research team members in the IRB.<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<span style=\"background-color: #ffcb05\"><strong>\r\nIMPORTANT:<\/strong><\/span> The #1 cause of disclosure of PHI is Cyber Attacks, so do not rely on the MM firewall to protect sensitive data \u2013 take additional precautions.","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"heading","legacy_heading":"Offices that Govern These Policies","legacy_subheading":"","legacy_section_text":"","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null},{"legacy_section_type":"text_area","legacy_heading":"","legacy_subheading":"","legacy_section_text":"<ul>\r\n \t<li><a href=\"https:\/\/research.medicine.umich.edu\/institutional-review-boards-irbmed\">Institutional Review Boards (IRBMED)<\/a><\/li>\r\n \t<li><a href=\"http:\/\/research-compliance.umich.edu\/office-human-research-compliance-review-ohrcr\">Office of Research Compliance Review (ORCR)<\/a><\/li>\r\n \t<li><a href=\"https:\/\/safecomputing.umich.edu\/about\">Information and Infrastructure Assurance\u00a0(IIA)<\/a><\/li>\r\n \t<li><a href=\"https:\/\/safecomputing.umich.edu\/protect-the-u\/safely-use-sensitive-data\/protect-sensitive-data\">U-MICH Safe Computing<\/a><\/li>\r\n<\/ul>","legacy_media_position":"","legacy_media_file":"","legacy_media_url":"","legacy_glossary_term":"","legacy_glossary_nids":"","legacy_resource":"","legacy_resource_nids":"","legacy_buttons":null}],"update_notice_type":[],"update_notice_start":"","update_notice_end":"","update_notice_text_blocks":null,"global_contact_block":false,"contact_name":"","contact_email":"","contact_additional_info":"Contact us at\u00a0<a href=\"mailto:DataOffice@umich.edu\">DataOffice@umich.edu<\/a>\u00a0or\u00a0(734) 615-2100\r\n\r\nNorth Campus Research Complex,\u00a0Building 400,\u00a01600 Huron Parkway,\u00a0Ann Arbor, MI 48105\r\n\r\nA list of Data Office contacts is available in the\u00a0<a href=\"https:\/\/research.medicine.umich.edu\/department\/staff?title=&amp;field_dept_staff_org_assignment_tid=982\">Personnel Directory<\/a>.\r\n\r\nEdited By: <a href=\"mailto:dagi@umich.edu\">dagi@umich.edu<\/a>\r\nLast Updated: December 5, 2025 2:30 PM","global_contact_block_select":null},"_links":{"self":[{"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document"}],"about":[{"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/types\/document"}],"version-history":[{"count":3,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/729\/revisions"}],"predecessor-version":[{"id":1851,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/document\/729\/revisions\/1851"}],"wp:attachment":[{"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/media?parent=729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/categories?post=729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/tags?post=729"},{"taxonomy":"content-type","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/content-type?post=729"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/topic?post=729"},{"taxonomy":"update-type","embeddable":true,"href":"https:\/\/az.research.umich.edu\/medschool\/wp-json\/wp\/v2\/update-type?post=729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}