NIH Controlled-Access Data

Overview

The National Institutes of Health (NIH) provides researchers access to certain research data through controlled-access repositories. Unlike publicly available research data, controlled-access data may only be accessed and used by approved researchers for authorized research purposes and in accordance with applicable NIH and repository requirements.

Researchers approved to use NIH controlled-access data may be required to comply with specific requirements for accessing, using, storing, protecting, and sharing the data. These requirements may include administrative, physical, and technical safeguards and may vary depending on the repository, dataset, and applicable terms of access.

The Office of Research Security (ORS) serves as the University's administrative lead and point of contact for NIH controlled-access data. ORS assists researchers in identifying applicable data access, research information protection, and cybersecurity requirements and coordinates with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, and other appropriate University offices to support implementation.

CONTACT ORS


What Is NIH Controlled-Access Data?

NIH controlled-access data is research data for which access is limited to approved researchers and approved research uses.

Controlled access may be used when data cannot appropriately be made publicly available because of participant privacy, consent, confidentiality, data-use limitations, or other applicable requirements.

NIH controlled-access repositories include the Database of Genotypes and Phenotypes (dbGaP) and other NIH repositories or systems that require researchers to obtain authorization before accessing data.

Controlled-access data should not be treated in the same manner as publicly available research data. Researchers must comply with the requirements established for the specific data they are authorized to access.


Before Requesting or Receiving Data

Researchers should identify applicable data access and safeguarding requirements before controlled-access data are received, downloaded, accessed, stored, or used.

Depending on the repository and dataset, researchers may need to consider:

  • Data access terms and conditions.
  • Approved research uses.
  • Data Use Certifications, Data Use Agreements, or similar requirements.
  • Restrictions on who may access the data.
  • Restrictions on sharing or transferring data.
  • Requirements for storing or processing the data.
  • Cybersecurity or information protection requirements.
  • Restrictions on cloud, computing, or storage environments.
  • Requirements for reporting incidents or unauthorized access.
  • Requirements for retaining, returning, or destroying data.

Requirements should be evaluated for the specific repository and dataset rather than assuming that the same safeguards apply to all NIH controlled-access data.


Access & Authorized Users

Access to NIH controlled-access data is generally limited to individuals authorized under the applicable data access request and repository requirements.

Researchers should:

  • Limit access to approved project personnel.
  • Ensure personnel understand applicable data-use and safeguarding requirements.
  • Review access when personnel join, leave, or change roles on the project.
  • Avoid sharing credentials or providing access to individuals who have not been appropriately authorized.
  • Follow applicable requirements before transferring, sharing, or providing collaborators access to controlled-access data.

Changes in project personnel, research use, collaborators, or other circumstances may require additional review or approval.


Protecting NIH Controlled-Access Data

Researchers must protect controlled-access data in accordance with the requirements applicable to the specific repository, dataset, and approved research use.

Depending on those requirements, safeguards may address:

  • User authentication and access controls.
  • Storage and computing environments.
  • Encryption or secure transmission.
  • Endpoint and device security.
  • Physical protection of systems or devices.
  • Restrictions on downloading or copying data.
  • Backup and recovery.
  • Incident reporting.
  • Data retention or destruction.
  • Other administrative, physical, or technical safeguards.

The appropriate safeguards should be determined from the applicable NIH and repository requirements before the data are received or accessed.

NIH controlled-access data may also be subject to applicable University information classification and protection requirements. Researchers should follow both the requirements established by NIH or the applicable repository and applicable University requirements.


Research Computing & Storage

NIH controlled-access data should be stored, processed, and accessed using University-supported resources appropriate for the requirements applicable to the specific repository, dataset, and approved research use.

A computing, storage, cloud, or collaboration environment appropriate for ordinary research information may not satisfy requirements applicable to NIH controlled-access data.

ORS serves as the administrative point of contact and assists researchers in identifying applicable NIH, repository, data access, research information protection, and cybersecurity requirements. Research Computing & Informatics (RCI), DoIT and/or SBM-IT, and other appropriate University technology organizations provide technical expertise, services, and support within their respective areas of responsibility to identify and implement computing, storage, cybersecurity, and other technical solutions appropriate for those requirements.

ORS coordinates with the appropriate University technology offices when NIH controlled-access data require specialized safeguards or technical environments.

Researchers should contact ORS before receiving or accessing NIH controlled-access data to ensure applicable requirements have been identified and, when necessary, appropriate University resources have been coordinated.


Changes During the Research

Requirements should be reconsidered when circumstances affecting the approved use or protection of the data change.

Examples may include:

  • Adding or removing project personnel.
  • Adding collaborators.
  • Changing the approved research use.
  • Moving data to a different computing or storage environment.
  • Sharing or transferring data.
  • Changing institutions.
  • Receiving updated repository or data-provider requirements.

Researchers should follow applicable NIH and repository procedures for changes requiring notification, amendment, or additional approval.


How ORS Can Help

ORS serves as the University's administrative lead and point of contact for NIH controlled-access data and assists researchers by:

  • Providing guidance on the University's process for NIH controlled-access data.
  • Reviewing applicable NIH, repository, data access, and safeguarding requirements.
  • Identifying applicable research information protection and cybersecurity requirements.
  • Determining whether baseline safeguards are sufficient or additional project-specific safeguards are required.
  • Identifying when a Data Protection Plan or other project-specific safeguarding documentation may be necessary.
  • Coordinating with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, and other appropriate University offices.
  • Providing guidance when project personnel, approved research uses, computing environments, collaborators, or other relevant circumstances change.

ORS does not replace NIH or repository approval processes. Researchers remain responsible for complying with the terms governing their approved access and use of controlled-access data.


Related Guidance

Reference Guide Description
Research Information Classification Learn how to identify the type of research information involved and determine the requirements that may apply.
Research Information Protection Learn how administrative, physical, and technical safeguards are identified and applied to protect research information.
Research Cybersecurity Baseline Review baseline cybersecurity practices that support University research activities.
Research Physical Security Baseline Review baseline physical security practices supporting protection of research information, equipment, and research environments.
Data Protection Plans Guidance for developing and maintaining project-specific plans documenting sponsor, data-provider, contractual, or institutional information protection requirements.
Secure Research Computing Guidance for research requiring specialized computing, storage, access controls, or other project-specific cybersecurity safeguards.

Need Assistance?

If you are planning to request, receive, access, store, or use NIH controlled-access data, contact the Office of Research Security before receiving or accessing the data if you are uncertain what data access, research information protection, cybersecurity, or institutional requirements apply.

ORS will assist in identifying applicable requirements and coordinate with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, and other appropriate University offices when additional safeguards or specialized computing, storage, or technical resources are required.

Contact ORS