Skip to content
Global Mobile Healthcare Research Consortium

Research Resources

Data Privacy and Data-Sharing Standards

Responsible data sharing begins with a specific purpose and the smallest amount of data needed to achieve it. Every project should define what it will collect, who can access the data, how the data will move, where they will be stored, how findings will be reported, and when the data will be returned or destroyed.

IRB approval, participant consent, HIPAA authorization, and a data-sharing agreement are related protections. One does not automatically replace the others.

This page offers planning guidance. Requirements vary based on the organizations, data, participants, locations, funder, and applicable law. Seek review from the appropriate privacy, security, IRB, compliance, and legal offices.

Know what kind of data you have

Aggregate data

Aggregate data present totals or summaries rather than individual-level records. They can still create privacy risks when a group, location, diagnosis, or event is rare.

De-identified data

Under the HIPAA Privacy Rule, protected health information can be de-identified through Safe Harbor or Expert Determination. Removing names is not enough. Other laws, contracts, and institutional policies may define de-identification differently.

Limited data set

A HIPAA limited data set excludes specified direct identifiers but may retain some dates and geographic information. It is still protected health information. A data use agreement is required when it is disclosed for research, public health, or healthcare operations.

Coded or pseudonymized data

In coded or pseudonymized data, direct identifiers are replaced with a code, but a key may still connect the data to a person. These data are not automatically de-identified. Document who controls the key and whether the research team can obtain it.

Identifiable data

Data may identify a person directly or make their identity easy to determine when combined with other information. Limit access closely and put all required permissions and safeguards in place.

Apply these standards across the data lifecycle

1. Define the purpose

State the research question and the permitted uses of the data. Do not assume that future uses are allowed. Address them explicitly in consent, authorization, IRB review, and agreements as applicable.

2. Minimize the data

For every requested field, ask why it is needed. Reduce precision when possible. Exact dates, detailed locations, free text, photographs, device identifiers, and rare characteristics can increase identification risk.

3. Map the data flow

Document where the data originate, who collects them, every transfer and storage location, the analysis environment, and each backup, output, archive, and destruction step. Include paper records, mobile devices, messaging systems, spreadsheets, cloud platforms, and vendor systems.

4. Confirm authority and permission

Identify the basis for collection, use, and disclosure. This may include participant consent, HIPAA authorization, an IRB or Privacy Board waiver, a limited data set with a data use agreement, another legal permission, or use of properly de-identified data.

5. Limit access by role

Give each person access only to the data needed for their assigned work. Use named accounts, strong authentication, regular access reviews, and prompt removal of access when a role ends. Avoid shared credentials.

6. Use approved transfer and storage methods

Use systems approved by the organizations responsible for the data. Encrypt data in transit and at rest when required. Avoid personal email, unapproved file-sharing accounts, personal devices, and removable media unless an approved process specifically permits them.

7. Protect location and small-group information

A route, parking site, date, or combination of characteristics may identify a person or a small community. Set reporting rules for small cells and rare events. The team may need to combine time periods, reduce geographic detail, or withhold a result.

8. Review analytic outputs

Check tables, quotations, maps, images, case descriptions, and free text before release. An output can reveal someone’s identity even when direct identifiers were removed from the source file.

9. Prepare for incidents

Document whom to contact, how quickly to report, how access will be contained, what records will be preserved, and which organizational or legal procedures apply.

10. Close the project

Follow the approved retention period. Return or destroy data as required, remove access, address backups and derived files, and document the steps taken. Do not keep a convenience copy for an unspecified future project.

Data-sharing agreement checklist

A data-sharing or data use agreement should address:

  • Parties and authorized contacts
  • Purpose and permitted uses
  • Data elements and level of identifiability
  • Source, quality, and known limitations
  • Approved users and access method
  • Storage, transfer, and security requirements
  • Prohibition or limits on re-identification and participant contact
  • Data linkage and creation of derived data
  • Contractors, students, vendors, and other downstream recipients
  • Incident reporting and response
  • Small-number, quotation, map, and publication rules
  • Ownership, stewardship, and intellectual property
  • Review of findings and protection of scientific integrity
  • Retention, return, destruction, and certification
  • Auditing, amendment, termination, and dispute resolution
  • Requirements that continue after the agreement ends

Mobile healthcare data require added care

Mobile programs should specifically review:

  • Vehicle and portable-device security
  • Paper forms used where connectivity is limited
  • Offline collection and later synchronization
  • Route, schedule, and precise location data
  • Text messages and patient communication
  • Photographs, video, and social media
  • Free-text notes containing identifiers
  • Shared clinical and research systems
  • Small rural, tribal, immigrant, unhoused, or condition-specific populations
  • Data collected by community partners or site hosts

Frequently asked questions

Is a spreadsheet de-identified if names are removed?

Not necessarily. Dates, locations, record numbers, contact details, free text, and combinations of characteristics may identify a person. Under HIPAA, de-identification must meet the requirements for Safe Harbor or Expert Determination.

Does HIPAA apply to every mobile clinic or research partner?

No. HIPAA applies to covered entities, business associates, and protected health information as defined by the rule. Other privacy requirements, contracts, state laws, and institutional policies may apply even when HIPAA does not.

Is de-identified data risk-free?

No. De-identification reduces risk, but it cannot guarantee that no one will ever be identified. The risk may be greater when detailed data can be combined with other sources.

Who owns research data?

Ownership and stewardship depend on institutional policy, contracts, funding terms, law, consent, and the project agreement. Decide access, control, permitted use, and future use before sharing begins.

Can a researcher use the data for another study?

Only when the future use is permitted by the applicable consent, authorization, IRB review, agreements, law, and organizational policies. The original agreement should not be treated as unlimited permission.

Authoritative resources

All research resources

Reviewed by
Mollie Williams, DrPH, MPH
Last reviewed
2026-08-28

Have a research question or a program worth studying?

GMHRC helps researchers and mobile healthcare programs find each other and plan work that is useful to both.