aspenirb

The data security plan Aspen’s IRB reads: storage, access, de-identification and destruction, named

Aspen’s application asks six plain questions about your data. Answer them with named nouns — this drive, this account, this person, this date — and the section passes without comment. Answer them with the phrase “kept secure” and you have written a finding, because that phrase answers none of the six.

Miriam Kessler, DNP, APRN · filed 2026-08-23

In short. The application asks what data you collect, how it is collected, where it is stored, who may reach it, how it is protected, and how and when it is destroyed. Name each answer. Sensitive data, including protected health information, requires a fuller plan.

What exactly does Aspen ask?

The handbook’s Data Collection, Storage and Protection section sets out the questions in a single sentence: on the application you will explain the data you are seeking to collect, how it will be collected, where it will be stored, who will have access to it, how it will be protected, and how and when it will be destroyed.

It then states the object of the exercise, which is narrower than “security” in the everyday sense. The measures aim first at confidentiality — that information capable of identifying a participant is reached only by appropriate people, for appropriate reasons. That is also how the criteria for approval are written: the board cannot approve anything without finding adequate provisions in place for participants’ privacy and for keeping the data confidential.

Six questions, one purpose. Four of them are where files actually fail.

Four answers, in the vague version and in the named one
The answerWhat a vague version saysWhat a named version says
Storage“Data will be stored securely.”The named location for each artefact — recordings, transcripts, the extract, the identifier log — and where each one is not kept.
Access“Only the researcher will have access.”Every person who can reach the data by name or role, what each may reach, and how that access is authenticated.
De-identification“Data will be de-identified.”Which identifiers are removed, at what point in the workflow, whether a re-identification code exists, and where its key lives.
Destruction“Data will be destroyed afterwards.”What is destroyed, by what method for each medium, and the event that triggers it.

Notice what the right-hand column shares: every entry is checkable. A board cannot verify a promise, but it can read a plan and see whether the pieces fit — the whole basis of reviewing a file rather than trusting one.

How should identifiers and the linking log be handled?

Aspen gives a specific technique rather than a principle. The best protection, the handbook says, is to code the data so that only you can link it back to individual participants — and then to keep the log that cross-references the participant identification number with the name in a separate location from the data itself. Where the data is electronic, the log with the identifiers belongs on a separate server or computer system.

That instruction is doing more than tidiness. It means a single compromise cannot yield both halves. A plan that describes a coded dataset but leaves the key in the same folder has not separated anything; it has renamed a column.

The federal framing behind the same idea is at 45 CFR 164.514(c), which permits a code that allows re-identification only where the code is not derived from or related to information about the individual and cannot otherwise be translated to identify them, and where nobody is told how the re-identification works. Initials and dates of birth fail that test. Sequence numbers assigned from a list, held apart, do not.

When is data de-identified, and when is it merely coded?

The handbook is honest that de-identification is the ideal and not always available: stripping identifiers can sometimes destroy the analytic value of the data, so it is not always possible. Where that is the case, it notes that the board may ask that the data be de-identified as soon as analysis is complete and the project has been accepted by the university. In other words, the plan may include a date on which coded data becomes de-identified data, and saying so is stronger than staying silent.

Where the data is health information, the standard has a printed test. The Safe Harbor method at 164.514(b)(2) treats information as de-identified when eighteen categories of identifier — covering the person, their relatives, employers and household members — are removed and the holder knows of nothing left that could still name them:

  • Names.
  • Geographic subdivisions smaller than a state, including street address, city, county, precinct and postal code, with a narrow exception for the initial three digits of a postal code in sufficiently populous areas.
  • All elements of dates except year where they relate directly to a person — birth, admission, discharge, death — and all ages above eighty-nine, which are aggregated into a single upper category.
  • Telephone numbers, and fax numbers.
  • Electronic mail addresses.
  • Social security numbers.
  • Medical record numbers, health plan beneficiary numbers and account numbers.
  • Certificate and licence numbers.
  • Vehicle identifiers and serial numbers, including registration plates.
  • Device identifiers and serial numbers.
  • Web addresses and internet protocol addresses.
  • Biometric identifiers, including fingerprints and voiceprints.
  • Full-face photographic images and comparable images.
  • Any remaining unique number, characteristic or code that singles a person out, aside from a permitted re-identification code.

The alternative route is expert determination: a person with appropriate knowledge of accepted statistical and scientific methods concludes that the risk of identification is very small and documents the methods and the result. Both routes are available; neither is a phrase you can simply assert.

The last bullet is the one that trips a nursing file. A small unit, a rare diagnosis and a date can identify a person with no name anywhere in the file, which is why the geography and date rules are written as tightly as they are.

When does the plan have to escalate?

When the data is sensitive. Aspen defines that by consequence rather than by category: data is sensitive where disclosure of identifying information could have adverse consequences for participants or damage their financial standing, employability, insurability, educational advancement or reputation, or expose them to criminal or civil liability. Illegal activity and protected health information are the examples given.

Where that applies, the handbook says the plan should be comprehensive and lists what it must include at minimum: authentication of those with appropriate access, such as suitable password protection; an appropriate firewall for the computer system; anti-virus and anti-spyware software; encryption of the data files; and a secure location for the computer systems and servers themselves. It adds that the plan should address how the risks of storing data on laptops and flash drives will be mitigated.

That last point echoes a warning made earlier in the same section: take care with flash drives and external drives, which can be lost or stolen, and consider cloud storage protected by a password or two-step authentication instead. A plan that names a portable device without naming what protects it has raised a question the board will ask back.

Where does HIPAA come in?

Aspen’s HIPAA section draws the trigger broadly and simply: it applies where medical records — electronic, archival, paper or otherwise — are used at any point during the project, and where it applies, a HIPAA Authorization Form is submitted with the protocol. Where no medical records are used, it does not apply.

“At any point” is the operative phrase. A chart consulted only to determine eligibility is still a medical record used during the work, even if nothing from it reaches the final dataset. Screening touches records as surely as extraction does, and screening data is data.

How does the plan connect to the rest of the file?

It is quoted in three other places, and all three have to agree with it.

The consent states how far records that identify a person will be kept confidential — one of the basic elements at 46.116(b) — so what the participant is told must match what the application describes. The site permission letter states what data is permitted to leave and on what terms; where it is silent on data, the application’s answers have nothing standing behind them. And the recruitment and screening materials generate their own records, including from people who never enrol, which the plan is expected to cover.

After approval, changes to the arrangement go back. The Change Request Form covers a change to any aspect of an approved project, and moving where data is held or who can reach it is exactly that kind of change.

Reading those four documents against one another is the specific cross-read we run before anything is filed — described in full on how it works — and it is where the vague answer usually shows itself, because vagueness cannot contradict anything until something concrete is placed beside it.

What to do next

Write the plan as an inventory rather than a paragraph. List every artefact the project will create — recordings, transcripts, the extract, the consent forms, the identifier log, the screening responses — and give each one a location, an access list, an identifier state and an end. Where a row reads “secure” instead of a noun, that row is the finding. If you would rather have a reviewer’s reading of it, send the draft with the plan and the consent; the findings come back in writing, at no cost and with nothing attached.

Four answers, named. Send the file as it stands and we will tell you which of them your application actually gives.

Request the free application review

Independent consultants, unaffiliated with Aspen University. The data and its findings stay yours; the determination is always the board’s. Also filed: the attachment-by-attachment checklist and the three rulers a consent is measured against.

Sources

Requirements change. Confirm anything specific against Aspen’s current handbook or IRB portal before you file.