Working with NIH Controlled-Access Data
Overview
The National Institutes of Health (NIH) maintains controlled-access data repositories that provide approved researchers with access to genomic, clinical, biomedical, imaging, and other sensitive research data. Unlike publicly available datasets, access to these repositories requires approval and compliance with applicable data use, security, and repository requirements.
NIH controlled-access data must be protected in accordance with the requirements applicable to the repository, data access agreement, and research project. NIH has established security standards for users of NIH Controlled-Access Data Repositories, and an appropriate research computing environment may be required to satisfy those requirements.
At Stony Brook University, the Office of Research Security (ORS) serves as the administrative lead for researcher access to the University's approved secure research computing environment and coordinates with the appropriate University offices to support projects involving NIH controlled-access data.
Researchers planning to request or use NIH controlled-access data should contact ORS early in the planning process.
Contact ORS Before You
Contact ORS before you:
- Request access to NIH controlled-access data.
- Submit a Data Access Request, execute a Data Use Certification (DUC), or enter into another NIH controlled-access data agreement.
- Receive NIH controlled-access data.
- Store NIH controlled-access data in a new computing or storage environment.
- Provide collaborators or other project personnel access to NIH controlled-access data.
- Are uncertain whether NIH security, information protection, or other institutional requirements apply.
Key Considerations
NIH controlled-access repositories provide approved researchers access to sensitive research datasets that are not publicly available.
Examples include genomic, clinical, biomedical, imaging, and other controlled-access datasets maintained through NIH-supported repositories.
Access is granted only after approval through the applicable NIH data access process and acceptance of the associated data use requirements.
NIH controlled-access data must be protected in accordance with the security requirements applicable to the repository and data access agreement. For NIH Controlled-Access Data Repositories subject to the current NIH requirements, users must follow the NIH Security Best Practices for Users of Controlled-Access Data as specified in applicable new or renewed agreements.
Stony Brook University provides an approved secure research computing environment for projects requiring enhanced information protection. ORS serves as the administrative lead for researcher access to this environment and coordinates the onboarding process with the appropriate University offices.
Researchers should contact ORS before requesting NIH controlled-access data so that applicable security requirements and the appropriate computing environment can be identified before access is approved.
Access to controlled-access genomic data subject to the NIH Genomic Data Sharing Policy generally requires a Data Use Certification (DUC). Other NIH controlled-access repositories may use different data access agreements or terms.
These agreements establish project-specific requirements governing:
- Approved research use
- Authorized users
- Data access
- Information protection
- Data sharing
- Publications
- Data retention
- Reporting requirements
- Data security and unauthorized release reporting
- Project renewal and close-out
Researchers should understand these requirements before requesting access to controlled-access data.
Access to NIH controlled-access data is limited to individuals authorized under the applicable data access request, agreement, and repository requirements.
Researchers should contact ORS before:
- Adding project personnel.
- Providing access to students, trainees, contractors, or collaborators.
- Modifying the approved research team.
- Requesting access for additional users within the secure research computing environment.
External collaborators may need separate NIH approval through their own institution, depending on the applicable repository and data access requirements.
Researchers should consult ORS before:
- Moving controlled-access data to another computing environment.
- Changing institutions.
- Adding collaborators.
- Expanding the scope of the approved research.
- Using the data for a different research project.
- Renewing or closing out an approved project.
Changes to an approved project may require additional institutional coordination or NIH approval.
Related Guidance
| Related Guidance | Description |
|---|---|
| Secure Research Computing | Guidance for research requiring secure research computing environments, specialized storage, controlled access, or sponsor-required cybersecurity safeguards. |
| Data Protection Plans | Guidance for developing, implementing, and maintaining sponsor-, contractual-, or institutionally required Data Protection Plans. |
| Sharing Research Information | Guidance for sharing research information, data, software, technology, technical information, presentations, publications, or other research outputs with collaborators, sponsors, companies, government agencies, or other third parties. |
| Sponsor & Agreement Requirements | Guidance for reviewing and complying with research security, export control, information protection, publication, and other project-specific requirements contained in sponsor solicitations, award terms, and research agreements. |
| NIH Controlled-Access Data | Learn about requirements for accessing, using, storing, and protecting controlled-access data obtained through NIH repositories. |
Frequently Asked Questions
What is NIH controlled-access data?
NIH controlled-access data are research datasets made available through NIH-managed repositories that require approval before researchers may access or use the data.
Do all NIH datasets require controlled access?
No.
Many NIH datasets are publicly available. This guidance applies only to datasets available through NIH controlled-access repositories or other repositories with controlled-access requirements.
Do I need to use the University's secure research computing environment?
It depends on the applicable NIH security requirements, data access agreement, and research project. NIH Controlled-Access Data Repository users may be required to follow NIH Security Best Practices, and the University's approved secure research computing environment may be necessary to satisfy those requirements. Contact ORS before requesting access so the appropriate environment can be identified.
Can I add members of my research team after access has been approved?
Possibly.
Additional users may require institutional coordination and, depending on the repository, updates to the approved access documentation.
Researchers should contact ORS before requesting access for additional project personnel.
Can I move NIH controlled-access data to another computing environment?
Not without first determining whether the new environment satisfies applicable NIH and institutional requirements.
Researchers should contact ORS before transferring NIH controlled-access data.
Need Assistance?
Contact ORS early when planning research involving NIH controlled-access data so applicable data access, security, computing, and institutional requirements can be identified before data are requested or received. ORS coordinates the administrative process for access to the University's approved secure research computing environment when required.