NIH Controlled-Access Data
Overview
The National Institutes of Health (NIH) provides researchers access to certain research data through controlled-access repositories. Unlike publicly available research data, controlled-access data may only be accessed and used by approved researchers for authorized research purposes and in accordance with applicable NIH and repository requirements.
Researchers approved to use NIH controlled-access data may be required to comply with specific requirements for accessing, using, storing, protecting, and sharing the data. These requirements may include administrative, physical, and technical safeguards and may vary depending on the repository, dataset, and applicable terms of access.
The Office of Research Security (ORS) serves as the University's administrative lead and point of contact for NIH controlled-access data. ORS assists researchers with applicable data access requirements, identifies research information protection and cybersecurity requirements, and coordinates with Research Computing & Informatics (RCI), the Information Security Office, and other University offices, as appropriate, to support compliant access and use of controlled-access data.
What Is NIH Controlled-Access Data?
NIH controlled-access data is research data for which access is limited to approved researchers and approved research uses.
Controlled access may be used when data cannot appropriately be made publicly available because of participant privacy, consent, confidentiality, data-use limitations, or other applicable requirements.
NIH controlled-access repositories include the Database of Genotypes and Phenotypes (dbGaP) and other NIH repositories or systems that require researchers to obtain authorization before accessing data.
Controlled-access data should not be treated in the same manner as publicly available research data. Researchers must comply with the requirements established for the specific data they are authorized to access.
Before Requesting or Receiving Data
Researchers should identify applicable data access and safeguarding requirements before controlled-access data are received, downloaded, accessed, stored, or used.
Depending on the repository and dataset, researchers may need to consider:
- Data access terms and conditions.
- Approved research uses.
- Data Use Certifications, Data Use Agreements, or similar requirements.
- Restrictions on who may access the data.
- Restrictions on sharing or transferring data.
- Requirements for storing or processing the data.
- Cybersecurity or information protection requirements.
- Restrictions on cloud, computing, or storage environments.
- Requirements for reporting incidents or unauthorized access.
- Requirements for retaining, returning, or destroying data.
Requirements should be evaluated for the specific repository and dataset rather than assuming that the same safeguards apply to all NIH controlled-access data.
Access & Authorized Users
Access to NIH controlled-access data is generally limited to individuals authorized under the applicable data access request and repository requirements.
Researchers should:
- Limit access to approved project personnel.
- Ensure personnel understand applicable data-use and safeguarding requirements.
- Review access when personnel join, leave, or change roles on the project.
- Avoid sharing credentials or providing access to individuals who have not been appropriately authorized.
- Follow applicable requirements before transferring, sharing, or providing collaborators access to controlled-access data.
Changes in project personnel, research use, collaborators, or other circumstances may require additional review or approval.
Protecting NIH Controlled-Access Data
Researchers must protect controlled-access data in accordance with the requirements applicable to the specific repository, dataset, and approved research use.
Depending on those requirements, safeguards may address:
- User authentication and access controls.
- Storage and computing environments.
- Encryption or secure transmission.
- Endpoint and device security.
- Physical protection of systems or devices.
- Restrictions on downloading or copying data.
- Backup and recovery.
- Incident reporting.
- Data retention or destruction.
- Other administrative, physical, or technical safeguards.
The appropriate safeguards should be determined from the applicable NIH and repository requirements before the data are received or accessed.
Research Computing & Storage
University-supported computing and storage resources should be used as appropriate for the requirements applicable to the controlled-access data.
A computing or storage environment appropriate for ordinary research information may not necessarily satisfy requirements applicable to NIH controlled-access data.
ORS serves as the administrative point of contact and assists researchers in identifying the NIH, repository, data access, research information protection, and cybersecurity requirements that apply. Research Computing & Informatics (RCI), the Information Security Office, and other University technology organizations may assist with identifying and implementing computing, storage, and technical solutions that meet those requirements.
Researchers should contact ORS before receiving or accessing NIH controlled-access data to ensure applicable requirements have been identified and, when necessary, appropriate University resources have been coordinated.
Changes During the Research
Requirements should be reconsidered when circumstances affecting the approved use or protection of the data change.
Examples may include:
- Adding or removing project personnel.
- Adding collaborators.
- Changing the approved research use.
- Moving data to a different computing or storage environment.
- Sharing or transferring data.
- Changing institutions.
- Receiving updated repository or data-provider requirements.
Researchers should follow applicable NIH and repository procedures for changes requiring notification, amendment, or additional approval.
How ORS Can Help
ORS serves as the University's administrative lead and point of contact for NIH controlled-access data and assists researchers by:
- Providing guidance on the University's process for NIH controlled-access data.
- Reviewing applicable NIH, repository, data access, and safeguarding requirements.
- Identifying research information protection and cybersecurity requirements.
- Determining whether baseline safeguards are sufficient or additional project-specific safeguards are required.
- Identifying when a Data Protection Plan or other project-specific safeguards may be necessary.
- Coordinating with Research Computing & Informatics (RCI), the Information Security Office, and other University offices, as appropriate.
- Providing guidance when project personnel, research uses, computing environments, or other circumstances change.
ORS does not replace NIH or repository approval processes. Researchers remain responsible for complying with the terms governing their approved access and use of controlled-access data.
Related Guidance
| Reference Guide | Description |
|---|---|
| Research Information Classification | Learn how to identify the type of research information involved and determine the requirements that may apply. |
| Research Information Protection | Learn how administrative, physical, and technical safeguards are identified and applied to protect research information. |
| Research Cybersecurity Baseline | Review baseline cybersecurity practices that support University research activities. |
| Research Physical Security Baseline | Review baseline physical security practices supporting protection of research information, equipment, and research environments. |
Need Assistance?
If you are planning to request, receive, access, store, or use NIH controlled-access data and are uncertain what research information protection or cybersecurity requirements apply, contact the Office of Research Security before receiving or accessing the data.
ORS will assist in identifying applicable requirements and coordinate with the appropriate University offices when additional safeguards or specialized research computing resources are required.