aspenirb

Secondary data and old records — the line where a spreadsheet turns into human-subjects work

Nothing about a project that touches no living person feels like it should need a board. But the line is not drawn at contact; it is drawn at traceability. If the person analysing the rows could get back to a name, the file is carrying identifiable private information, and everything downstream — the category, the consent question, the paperwork the hospital wants — follows from that.

Miriam Kessler, DNP, APRN · filed 2026-08-23

In short. Old records count as human-subjects work when whoever analyses them could trace a row back to a person. Aspen expects the application regardless; the board settles the category, and no export may be pulled before its letter arrives.

Where exactly is the line drawn?

Federal language puts it at traceability rather than at contact. Read § 46.102 the plain way and what makes somebody a subject is not being met but being knowable: research that obtains or works on private information belonging to a living person, where identity could readily be worked out, is research on human subjects. The regulation supplies its own worked example of private information — a clinical record, handed over for one purpose by somebody who never expected it published.

Aspen’s handbook reaches the same border from the intent side: what matters is the purpose, not whether anything is ever published. If the point is to produce something that travels beyond the unit the rows came from, the activity is behaving like research. So the test is short. Is this an organised inquiry meant to generalise — and when you open the extract, can you get from a row to a person?

What the test is not: how old the rows are, whether you met anyone, or what the cover page calls the project. Boards read the design rather than the label, and the category you claim has to survive the description of the dataset three pages later.

Coded is not the same as anonymous — so who holds the key?

Most record-based files come apart on this one word. In OHRP’s vocabulary, material is coded when direct identifiers have been swapped for a number or symbol and a key exists somewhere capable of undoing the swap. Anonymous means there is nothing to undo. The reviewer’s question is never “did you code it?” but “who can reach the key, and under what instrument?”

OHRP’s 2008 guidance treats coded material as falling outside the human-subjects definition only when two things hold together. The material was not gathered for this particular project through contact with living people; and identity genuinely cannot be established by the analyst — because the key-holder has signed something forbidding release, say, or a repository operates under board-approved rules to that effect. Weigh how much that instrument carries. Without a written barrier, keeping names in another folder is an intention, and intentions are not controls.

Two consequences follow, and both are common findings. Where you personally open identifiable charts and log the rows under codes of your own invention, the code walks straight back to a person — so the secondary-research exemption, which asks that identity not be readily ascertainable, that nobody be contacted and that nobody be re-identified, is not a description of what you did. And if identity reaches you by accident mid-project, the work becomes human-subjects work from that moment. The board should hear that from you rather than read it afterwards.

Which of these four extracts are you actually holding?

Reviewers work from the description in the application, not from its title page. Find your row honestly: a file claiming one line here while describing another elsewhere is the mismatch that comes back as a written query.

The same rows, read twice — once for the Common Rule, once for the Privacy Rule
What is in your handsCommon Rule verdictPrivacy Rule verdict, source being coveredWhat your application has to show
You open the charts yourself and log findings under codes of your ownHuman-subjects work; your code is a route back, so the secondary-research exemption does not fitProtected health information — needing authorisation, a board waiver, or the limited-set routeWhy identifiers were needed, where the key lives, who may reach it, when it is destroyed
A person at the site abstracts the rows for you; the key stays behind, under a signed instrumentCan sit outside the definition on OHRP’s conditions — though Aspen’s board makes that call, not youHealth information still, if dates or other listed identifiers travel with the extractThe instrument itself, what the abstractor did, and that the key never crosses to you
An extract stripped of the eighteen listed identifiersNo longer identifiable private information; filed anyway, toward a written determinationDe-identified by the safe-harbour method, so the Privacy Rule no longer bitesWhich person removed them and by which method, and that free-text notes were cleaned too
A public dataset that is identifiable on its faceExempt territory for secondary research on publicly available materialGenerally outside the Privacy Rule, depending where it came fromProof that the source is genuinely open, plus whatever terms govern its use

One misreading sinks more record files than any other. Safe harbour, the method described at § 164.514(b), is literal about what has to come out: not only names and record numbers, but geography below state level, every part of a date apart from the year, biometrics, and any remaining unique code. An extract still carrying admission dates and a ward label has not been de-identified, however thoroughly the names were deleted. That extract has a proper name of its own — a limited set — and a limited set arrives with an agreement attached.

What does the Privacy Rule add on top?

Aspen’s handbook states the trigger plainly: HIPAA is in play wherever medical records are used at any point in the work, and an authorisation form travels in with the protocol when it is. The Privacy Rule leaves a hospital a short menu of lawful routes; name the one you are using rather than leave a reviewer guessing:

  1. Authorisation from each individual — honest, and rarely workable across a whole look-back population.
  2. A waiver, whole or partial, granted by a board under the research provision at 45 CFR 164.512(i), documented with the findings that board made. In practice the site’s own board or privacy board issues this, and its letter belongs in your file.
  3. The limited-set route under § 164.514(e): direct identifiers come off, dates and coarse geography may stay, and the recipient signs a data-use agreement promising not to re-identify anyone, not to make contact, and to report any use outside its terms.
  4. Fully de-identified material, by safe harbour or by an expert’s determination, at which point the Privacy Rule stops applying.
  5. The preparatory review, which permits a look at records to shape a protocol and gauge how many cases would qualify, provided none of that material leaves the covered entity. Counting first is lawful this way — and it is not permission to begin.

Aspen’s board is not policing the hospital’s Privacy Rule obligations for it. The board is reading your description for internal consistency. Where one paragraph promises an anonymous extract and a later one describes matching readmissions on a record number, the file has described two incompatible projects, and nobody reading it can tell which one is real.

Who gets to decide — you, your chair, or the board?

The board, and the sources agree unusually cleanly here. OHRP recommends that institutions designate who is authorised to determine whether coded material amounts to human-subjects research, and expressly recommends that investigators not hold that authority themselves. Aspen’s handbook arrives at the same rule from the institutional side: the review level is set by the IRB chair or a designee, and not by the candidate, the faculty chair, committee members, other faculty, administrators or collaborators at the site.

Hence the unglamorous rule governing every records project: nothing before the letter. Aspen’s handbook holds recruitment, data access, collection and implementation all behind IRB approval, and a quick preliminary export to see whether the numbers are even there is data access. Where a count is genuinely needed to shape the design, the lawful path is the preparatory review above, run by the covered entity and described honestly afterwards. Our companion piece on exempt, expedited and full board review covers how the claim is weighed once the file is in.

What a records file has to carry

Aspen’s application asks what you will collect, how, where it will live, who may reach it, how it is protected and how and when it goes. For a project with no participants in the room, answer those with the dataset in mind:

  • The variables, the window and the population, settled in the plan and quoted from it word for word rather than recalled.
  • A named account of who touches identifiers and at which step, plus where the linking log sits. Aspen asks for that log to be kept apart from the data, and on separate equipment where the data is electronic.
  • The permission that lets rows leave the building: a letter naming the records and who may handle them, together with whatever agreement the data owner requires. Who may sign one is covered in our piece on the site permission letter.
  • Where the site runs a board of its own, its determination or waiver letter — and, ordinarily, its review before Aspen’s. See how two boards read one file.
  • Security answers named rather than gestured at: storage, access, de-identification, destruction. Sensitive material earns the fuller plan Aspen describes — authentication, firewall, anti-virus, encryption, and where the equipment sits.
  • Human-subjects training certificates, current, uploaded with the application as the handbook requires.

What to do next

A records project stands or falls on two sentences: what you will be holding, and who could undo the coding. Write those first, because every later answer inherits them — then have them read the way a reviewer will read them, before the reviewer does.

Send the dataset description as it stands. We read it the way Aspen’s board will and write the findings first, free of charge.

Request the free application review

After that, the IRB process end to end can be ours to carry — category settled, documents built, submission filed, replies answered. Your project, data and findings remain yours, and the determination remains the board’s. Start at how it works, or the questions answered first.

Sources