Study Guide

CHRC Study Guide: Research Compliance Decision-Making

Build CHRC exam judgment across oversight boundaries, HIPAA research pathways, research billing, and event classification, with worked scenarios, a decision…

Updated September 202611 min readStudy GuideAllied Health Exam
Emily Carter — Editorial profile

Editorial profile

Emily Carter

Allied Health Exam Editorial Team

Core CHRC study decisions: (1) Determine whether an activity is human subjects research, FDA-regulated investigation, QI, or neither before applying any other rule. (2) Identify the governing framework — Common Rule, FDA regulations, both, or neither — because consent and IRB expectations differ. (3) Choose among the four HIPAA pathways (authorization, waiver, limited data set, de-identified data) based on the actual data need. (4) Classify each billing item as routine care or research-only by mapping it to the consent and budget. (5) Classify events as deviations, serious/continuing noncompliance, or unanticipated problems before reporting. Practice each with written rationales and self-scored rubrics.

Why the 'Is This Human Subjects Research?' Call Drives Everything Else

Before applying any rule, decide whether the activity is human subjects research, an FDA-regulated clinical investigation, quality improvement, or program evaluation. Each label routes the activity to different oversight, consent, privacy, and documentation obligations.

In U.S. research compliance practice, research generally means a systematic investigation designed to develop or contribute to generalizable knowledge, and a human subject means a living individual about whom an investigator obtains data or with whom an investigator interacts or intervenes. Quality improvement, by contrast, is designed to improve a local process. The two can look identical: a chart review of hospital readmissions performed by a hospital team to refine its own discharge workflow is QI, while an external investigator using similar data to build a publishable risk model is research.

Train the determination as a short sequence of questions: What is the intent? Will conclusions extend beyond this institution? Is there a protocol and a defined analysis plan? Is the activity funded as research? Intent to publish alone is not decisive, but a combination of signals usually is. Write the reasoning, not just the label, because downstream questions — whether IRB review is required, which HIPAA pathway applies, what documentation must exist — all inherit their answers from this first call. If the determination is wrong, every later compliance decision in the scenario is built on the wrong base.

  • Research signal: protocol, generalizable aim, external funding, dissemination of findings beyond the institution.
  • QI signal: local improvement goal, existing operational data, changes tested within one program.
  • Exercise cue: for any vignette, state the label and the two facts that most support it.

Common Rule Versus FDA Oversight: Which Rulebook Governs Your Protocol

A study can fall under HHS Common Rule oversight, FDA clinical investigation rules, both, or neither. Identifying the governing framework first tells you which consent content, IRB expectations, and record-keeping standards apply to the scenario.

The Common Rule is the federal policy for protection of human subjects that applies to research conducted or supported by federal departments and agencies, and to institutions that have committed to apply it across their research. FDA regulations govern clinical investigations of drugs, biologics, and devices when results are submitted to, or held for submission to, the agency. A federally funded drug trial can be dual-governed, which means consent elements, IRB requirements, and emergency-use expectations may differ between the two frameworks even though both involve IRB review.

Practice sorting any protocol into four boxes: Common Rule only, FDA only, both, or neither. An unfunded interview study at an institution that has not committed to the Common Rule may fall in the fourth box, yet the institution's own policy still governs it. A device feasibility study feeding an investigational device exemption submission lands in the FDA box. When you review a scenario, name the framework before answering anything else, then check which framework's consent and IRB rules the question is actually asking about. This habit turns two overlapping rulebooks into one clear routing step.

HIPAA in Research: Four Pathways and the Documentation Each Requires

Research uses of protected health information run through one of four pathways: individual authorization, an IRB or Privacy Board waiver, a limited data set with a data use agreement, or de-identified data. Each path has distinct criteria and paperwork.

Authorization is the subject's signed permission for a defined research use, revocable, and typically folded into the research consent process. A waiver requires documented findings that the research involves no more than minimal privacy risk, that the research is not practicable without the waiver, and that privacy protections are in place. A limited data set strips direct identifiers but keeps dates and coarse geography, and requires a data use agreement. De-identified data under the Safe Harbor method or expert determination is no longer PHI at all. Additional narrow pathways, such as reviews preparatory to research, exist for specific purposes.

The trap is matching pathway to actual data need rather than to convenience. If the analysis requires dates of service, Safe Harbor de-identification is unavailable; if the team plans to contact subjects, a waiver limited to chart screening may not cover recruitment contact. Documentation differs just as sharply: signed authorizations live with consent records, while a waiver lives in board minutes and approval letters stating the required findings. On any scenario, first name the data elements needed, then select the narrowest pathway that supports them, then check that the matching document actually exists in the file.

PathwayFits whenCore documentationWatch for
AuthorizationSubjects can and do sign; contact is plannedSigned authorization within the consent recordScope of use described too narrowly
IRB/Privacy Board waiverAccess to PHI is not practicable with consent; minimal privacy riskDocumented waiver criteria findings and approval letterAssuming one waiver covers every later activity
Limited data setDates or locations are needed; direct identifiers are notExecuted data use agreementTreating the LDS as fully de-identified
De-identified dataNo dates, locations, or direct identifiers are neededSafe Harbor checklist or expert determination recordRe-identification risk in small cohorts

Worked Scenario: Recruitment Contact Under a Screening Waiver

A waiver permits the specific use and disclosure of PHI described in the approved request. Recruitment contact is a separate use of PHI, so the coordinator must confirm the waiver's scope covers recruitment before any letter goes out.

Scenario: a research coordinator at a clinic receives IRB approval of a waiver allowing the team to screen the EHR for patients meeting inclusion criteria for a depression study. The team then asks her to mail study invitations directly to matched patients, assuming the existing approval covers it. The plausible mistake is treating 'we have a waiver' as a blanket permission for every downstream use of the identified list. The better decision is to read the approval language: if the waiver covers screening only, recruitment contact needs its own approved pathway — a separate waiver that expressly covers recruitment, or authorization obtained through treating providers.

Why it matters: mailing invitations using PHI gathered under a screening-only waiver would be a disclosure outside an approved pathway, which is precisely the kind of privacy event a research compliance function exists to prevent. The transferable lesson is scope-reading. Map each approval letter to the specific activity it authorizes, and whenever a new activity appears — contact, data sharing, chart access by a new collaborator — re-run the pathway analysis instead of extending an old approval by assumption. In practice, keep a one-line log pairing each approval document with the exact activity it covers.

Research Billing: Separating Routine Care Costs From Study Costs

Billing compliance turns on classifying every item and service as routine care or research-only, then routing each claim accordingly. The consent, the study budget, and the visit calendar are the three documents that make the classification checkable.

Routine costs are items and services the subject would receive regardless of the study: conventional care for the condition, clinically indicated monitoring, and, under Medicare's framework for certain investigational device exemption studies and qualifying trials, the investigational item itself under defined conditions. Research-only items — extra imaging performed solely for endpoints, pharmacokinetic draws, data collection visits — belong to the study account. Misclassification cuts both ways: billing payers for research-only items creates false claims exposure, while billing nothing for genuinely covered routine care can misstate the study's actual costs.

Scenario: a trial adds an ECG at every visit for safety monitoring specified only in the protocol, and the billing office bills the subject's insurer for each one. The plausible mistake is treating every ECG as clinically indicated care because the test itself is ordinary. The better decision is to map the protocol calendar against the consent and the budget, flag the ECGs as research-only, and route them to the study account going forward while correcting the prior claims. Why it matters: a repeated misrouted claim is not a one-time error but a pattern, and research billing compliance runs on exactly this reconciliation between protocol calendar, consent language, and claim.

Deviations, Unanticipated Problems, and Noncompliance: Sort Before You Report

Not every lapse triggers the same report. Compare the event against the approved protocol and consent, assess risk and scope, then classify it: minor deviation, serious or continuing noncompliance, or unanticipated problem involving risk to subjects.

Work with three working definitions. A protocol deviation is a departure from the approved protocol; some are minor and handled with a corrective action plan. Noncompliance is a failure to follow regulations or IRB requirements, and it rises in seriousness when it is serious or continuing. An unanticipated problem is an event that is unexpected given the protocol and subject population, related or possibly related to participation, and suggests greater risk than previously recognized. Keep this distinct from a proposed change: a prospective modification needs an approved amendment before implementation, whereas the common principle for apparent immediate hazards to subjects is that they may be acted on to eliminate the hazard, with prompt reporting.

Practical exercise: write five short event vignettes — a missed consent re-signature, a visit out of window by two days, an unblinded coordinator dosing error, a proposed new lab schedule, a subject injury not described in the consent. Classify each and justify it against the three unanticipated-problem elements. Expected observations: the dosing error satisfies all three elements; the out-of-window visit is a minor deviation needing a corrective plan; the new lab schedule is an amendment, not a deviation. Self-check rubric: one point each for citing the defining elements, proposing the right mechanism (amendment, report, corrective plan), and naming the reporting timeline category. Twelve out of fifteen is a strong learning milestone, not a pass prediction.

A Preparation Sequence Built on Decision Points, Plus Readiness Checks

Organize preparation around the six recurring decisions — activity determination, governing framework, HIPAA pathway, consent adequacy, billing classification, event classification — and rehearse each with short scenarios scored against your own rubric.

A realistic, adaptable sequence: block one, determinations and oversight frameworks, including the four-box framework exercise above. Block two, HIPAA pathways and informed consent, pairing each pathway with its documentation. Block three, research billing classification and conflict-of-interest management — disclosure, review, and management plans — tracing one COI scenario from disclosure through an approved management plan. Block four, reportable events and documentation, then mixed case sets drawing from all six published domains. Daily, regardless of pacing, write a one-paragraph rationale for one scenario. Compress or stretch the blocks to fit your calendar, but keep the order, because later decisions depend on earlier ones.

Readiness checks before you sit the exam: you can label an activity as research, QI, or neither, with two supporting facts, in under a minute; you can place any protocol into one of the four oversight boxes; you can recite the three waiver findings and match each HIPAA pathway to its document without notes; you can classify five event vignettes correctly against your own answer key; you can split a trial visit calendar into routine and research-only items and say which document proves each label. Treat these as learning milestones rather than predictions of any score. For administrative details such as eligibility, format, and fees, go directly to the Compliance Certification Board at ccbcertify.org rather than relying on third-party summaries.

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for Certified in Healthcare Research Compliance (CHRC).

Do I need to memorize exact regulatory citations for the CHRC?
Build working knowledge of the named frameworks — the Common Rule, FDA's human subject and IRB regulations, the HIPAA Privacy Rule's research provisions — and, more importantly, which framework governs a given scenario. Verify the exam's published content outline through the Compliance Certification Board to confirm the scope you should cover.
How can I quickly tell quality improvement from human subjects research?
Ask three questions: Is the intent to improve the local program or to produce generalizable knowledge? Will conclusions extend beyond this institution? Is there a protocol and analysis plan typical of research? One signal alone is rarely decisive, so weigh the pattern and write the reasoning.
When can a HIPAA waiver substitute for individual authorization?
A waiver is available when an IRB or Privacy Board documents that the research involves no more than minimal privacy risk, that it is not practicable without the waiver, and that a privacy protection plan exists. The approval's scope governs: a screening waiver does not automatically authorize recruitment contact or data sharing.
How do I decide whether a trial procedure is research-only for billing?
Map the protocol calendar against the informed consent and the study budget. Items performed solely for study endpoints, extra monitoring not clinically indicated, and data collection visits belong to the study account; conventional care and clinically indicated monitoring are routine. Reconcile routed claims against that mapping periodically.
Should I study drug trials and device studies differently?
Learn the routing rather than product detail: both can be FDA-regulated clinical investigations, and device studies may involve investigational device exemption frameworks that also affect billing. Practice placing scenarios into the four oversight boxes and noting which framework's consent and IRB expectations each question invokes.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.