A minimum key length of 128 bits must be used for any data that is transmitted electronically. The core data security procedures for protection of human subject research data are available from the IRB Health Sciences and Behavioral Sciences (HSBS) IRB application process data security guidelines.

Data that are collected from human participants over computer networks and are transmitted over the internet must be in encrypted format. Data should be downloaded from local devices to a secure UM server as soon as possible after collection.

Researchers conducting web-based research should be careful not to make guarantees of confidentiality or anonymity, as the security of online transmissions is not guaranteed. Use of on-line survey software should be administered by a professionally trained person with knowledge in computer and internet security.

Data must be transmitted in a secure format. Data collection and storage devices must be password protected with a strong password. Computer- and internet-based methods of collecting, storing, utilizing, and transmitting data in research involving human participants are developing at a rapid rate.

Data are considered de-identified when any direct or indirect identifiers or codes linking the data to the individual subject's identify are destroyed. IRB-HSBS recommends that research teams consistently follow the core data security controls, whether or not the research involves the collection of personally-identifiable data.

The UConn Office of Institutional Research & Effectiveness (OIRE) has obtained a license from Qualtrics as an on-line data collection tool. For most research, standard security measures like whole disk encryption and secure socket layer (SSL) (commonly used for secure websites) will suffice. Principal investigators (PIs) and their study teams may be required to outline the data management and security procedures in the eResearch IRB application for IRB review.

All laptops, iPads, tablets, portable media such as USB drives, or devices that are used to collect or store personal identifiable information (PII) for research purposes must use encryption. Data has a link between the data and the individual who provided it. If a server is used for data storage, personal identifying information should be kept separate from the data, and data should be stored in encrypted format. Social security numbers are not permitted to be used as an identifier.

Use of SurveyMonkey, PsychSurveys, and other online survey tools is permitted for minimal risk studies that do not involve the collection of sensitive data. If research includes sensitive identifiable data, outside consultants or vendors should be required to sign a confidentiality agreement. No guarantees can be made regarding the interception of data sent via the internet by any third parties.

This helps insure that any data intercepted during transmission cannot be decoded and that individual responses cannot be traced back to an individual respondent. Storing human subject data securely with the appropriate level of anonymity, confidentiality, or de-identification is a key factor in ensuring a low risk threshold for the participants, the researchers, and the university. Access to identifiable data should be limited to members of the study team.

At the end of the survey, there should be two buttons: one to allow participants to discard the data and the other to submit it for inclusion in the study. Computer- and internet-based methods of collecting, storing, utilizing, and transmitting data in research involving human participants are developing rapidly. The research team is obligated to protect the data from disclosure outside the research according to the terms of the research protocol and the informed consent document.

 Methods to reduce the risk of inadvertent disclosure include: Storing the subject's name and/or other identifiers separately from the research data. The core controls for minimum data security for human subject research data define the key terms "anonymous", "confidential", and "de-identified" as it relates to the collection and maintenance of that data. If it is necessary to use portable devices for initial collection of identifiers, the data files should be encrypted and the identifiers moved to a secure system as soon as possible.

UITS and Research Compliance Services encourage the use of FileLocker, Office 365, encrypted email, encrypted USB drive, or secure FTP to transmit sensitive data containing PII. For example, a study participant who is a member of a minority ethnic group might be identifiable from even a large data pool. For questions regarding IRB data management requirements, contact: IRB Health Sciences and Behavioral Sciences, Phone: (734) 936-0933.

Knowing the correct use of these terms can help you determine the appropriate data management and security procedures for your project. Data are anonymous if no one, not even the researcher, can connect the data to the individual who provided it. Note that coding the data does not make that data anonymous.

 This outlines the sections of the eResearch IRB application where data management and security procedures should be described. Release of data is one risk categorization factor for a human subjects study, and influences the data management and security procedures to protect that data and the subjects. The subject's name and other identifiers can be replaced with a unique code and this code used to refer to the subject data.