Core CHRC study decisions: (1) Determine whether an activity is human subjects research, FDA-regulated investigation, QI, or neither before applying any other rule. (2) Identify the governing framework — Common Rule, FDA regulations, both, or neither — because consent and IRB expectations differ. (3) Choose among the four HIPAA pathways (authorization, waiver, limited data set, de-identified data) based on the actual data need. (4) Classify each billing item as routine care or research-only by mapping it to the consent and budget. (5) Classify events as deviations, serious/continuing noncompliance, or unanticipated problems before reporting. Practice each with written rationales and self-scored rubrics.
Why the 'Is This Human Subjects Research?' Call Drives Everything Else
Before applying any rule, decide whether the activity is human subjects research, an FDA-regulated clinical investigation, quality improvement, or program evaluation. Each label routes the activity to different oversight, consent, privacy, and documentation obligations.
In U.S. research compliance practice, research generally means a systematic investigation designed to develop or contribute to generalizable knowledge, and a human subject means a living individual about whom an investigator obtains data or with whom an investigator interacts or intervenes. Quality improvement, by contrast, is designed to improve a local process. The two can look identical: a chart review of hospital readmissions performed by a hospital team to refine its own discharge workflow is QI, while an external investigator using similar data to build a publishable risk model is research.
Train the determination as a short sequence of questions: What is the intent? Will conclusions extend beyond this institution? Is there a protocol and a defined analysis plan? Is the activity funded as research? Intent to publish alone is not decisive, but a combination of signals usually is. Write the reasoning, not just the label, because downstream questions — whether IRB review is required, which HIPAA pathway applies, what documentation must exist — all inherit their answers from this first call. If the determination is wrong, every later compliance decision in the scenario is built on the wrong base.
- Research signal: protocol, generalizable aim, external funding, dissemination of findings beyond the institution.
- QI signal: local improvement goal, existing operational data, changes tested within one program.
- Exercise cue: for any vignette, state the label and the two facts that most support it.
Common Rule Versus FDA Oversight: Which Rulebook Governs Your Protocol
A study can fall under HHS Common Rule oversight, FDA clinical investigation rules, both, or neither. Identifying the governing framework first tells you which consent content, IRB expectations, and record-keeping standards apply to the scenario.
The Common Rule is the federal policy for protection of human subjects that applies to research conducted or supported by federal departments and agencies, and to institutions that have committed to apply it across their research. FDA regulations govern clinical investigations of drugs, biologics, and devices when results are submitted to, or held for submission to, the agency. A federally funded drug trial can be dual-governed, which means consent elements, IRB requirements, and emergency-use expectations may differ between the two frameworks even though both involve IRB review.
Practice sorting any protocol into four boxes: Common Rule only, FDA only, both, or neither. An unfunded interview study at an institution that has not committed to the Common Rule may fall in the fourth box, yet the institution's own policy still governs it. A device feasibility study feeding an investigational device exemption submission lands in the FDA box. When you review a scenario, name the framework before answering anything else, then check which framework's consent and IRB rules the question is actually asking about. This habit turns two overlapping rulebooks into one clear routing step.
HIPAA in Research: Four Pathways and the Documentation Each Requires
Research uses of protected health information run through one of four pathways: individual authorization, an IRB or Privacy Board waiver, a limited data set with a data use agreement, or de-identified data. Each path has distinct criteria and paperwork.
Authorization is the subject's signed permission for a defined research use, revocable, and typically folded into the research consent process. A waiver requires documented findings that the research involves no more than minimal privacy risk, that the research is not practicable without the waiver, and that privacy protections are in place. A limited data set strips direct identifiers but keeps dates and coarse geography, and requires a data use agreement. De-identified data under the Safe Harbor method or expert determination is no longer PHI at all. Additional narrow pathways, such as reviews preparatory to research, exist for specific purposes.
The trap is matching pathway to actual data need rather than to convenience. If the analysis requires dates of service, Safe Harbor de-identification is unavailable; if the team plans to contact subjects, a waiver limited to chart screening may not cover recruitment contact. Documentation differs just as sharply: signed authorizations live with consent records, while a waiver lives in board minutes and approval letters stating the required findings. On any scenario, first name the data elements needed, then select the narrowest pathway that supports them, then check that the matching document actually exists in the file.
| Pathway | Fits when | Core documentation | Watch for |
|---|---|---|---|
| Authorization | Subjects can and do sign; contact is planned | Signed authorization within the consent record | Scope of use described too narrowly |
| IRB/Privacy Board waiver | Access to PHI is not practicable with consent; minimal privacy risk | Documented waiver criteria findings and approval letter | Assuming one waiver covers every later activity |
| Limited data set | Dates or locations are needed; direct identifiers are not | Executed data use agreement | Treating the LDS as fully de-identified |
| De-identified data | No dates, locations, or direct identifiers are needed | Safe Harbor checklist or expert determination record | Re-identification risk in small cohorts |
Worked Scenario: Recruitment Contact Under a Screening Waiver
A waiver permits the specific use and disclosure of PHI described in the approved request. Recruitment contact is a separate use of PHI, so the coordinator must confirm the waiver's scope covers recruitment before any letter goes out.
Scenario: a research coordinator at a clinic receives IRB approval of a waiver allowing the team to screen the EHR for patients meeting inclusion criteria for a depression study. The team then asks her to mail study invitations directly to matched patients, assuming the existing approval covers it. The plausible mistake is treating 'we have a waiver' as a blanket permission for every downstream use of the identified list. The better decision is to read the approval language: if the waiver covers screening only, recruitment contact needs its own approved pathway — a separate waiver that expressly covers recruitment, or authorization obtained through treating providers.
Why it matters: mailing invitations using PHI gathered under a screening-only waiver would be a disclosure outside an approved pathway, which is precisely the kind of privacy event a research compliance function exists to prevent. The transferable lesson is scope-reading. Map each approval letter to the specific activity it authorizes, and whenever a new activity appears — contact, data sharing, chart access by a new collaborator — re-run the pathway analysis instead of extending an old approval by assumption. In practice, keep a one-line log pairing each approval document with the exact activity it covers.
Research Billing: Separating Routine Care Costs From Study Costs
Billing compliance turns on classifying every item and service as routine care or research-only, then routing each claim accordingly. The consent, the study budget, and the visit calendar are the three documents that make the classification checkable.
Routine costs are items and services the subject would receive regardless of the study: conventional care for the condition, clinically indicated monitoring, and, under Medicare's framework for certain investigational device exemption studies and qualifying trials, the investigational item itself under defined conditions. Research-only items — extra imaging performed solely for endpoints, pharmacokinetic draws, data collection visits — belong to the study account. Misclassification cuts both ways: billing payers for research-only items creates false claims exposure, while billing nothing for genuinely covered routine care can misstate the study's actual costs.
Scenario: a trial adds an ECG at every visit for safety monitoring specified only in the protocol, and the billing office bills the subject's insurer for each one. The plausible mistake is treating every ECG as clinically indicated care because the test itself is ordinary. The better decision is to map the protocol calendar against the consent and the budget, flag the ECGs as research-only, and route them to the study account going forward while correcting the prior claims. Why it matters: a repeated misrouted claim is not a one-time error but a pattern, and research billing compliance runs on exactly this reconciliation between protocol calendar, consent language, and claim.
Deviations, Unanticipated Problems, and Noncompliance: Sort Before You Report
Not every lapse triggers the same report. Compare the event against the approved protocol and consent, assess risk and scope, then classify it: minor deviation, serious or continuing noncompliance, or unanticipated problem involving risk to subjects.
Work with three working definitions. A protocol deviation is a departure from the approved protocol; some are minor and handled with a corrective action plan. Noncompliance is a failure to follow regulations or IRB requirements, and it rises in seriousness when it is serious or continuing. An unanticipated problem is an event that is unexpected given the protocol and subject population, related or possibly related to participation, and suggests greater risk than previously recognized. Keep this distinct from a proposed change: a prospective modification needs an approved amendment before implementation, whereas the common principle for apparent immediate hazards to subjects is that they may be acted on to eliminate the hazard, with prompt reporting.
Practical exercise: write five short event vignettes — a missed consent re-signature, a visit out of window by two days, an unblinded coordinator dosing error, a proposed new lab schedule, a subject injury not described in the consent. Classify each and justify it against the three unanticipated-problem elements. Expected observations: the dosing error satisfies all three elements; the out-of-window visit is a minor deviation needing a corrective plan; the new lab schedule is an amendment, not a deviation. Self-check rubric: one point each for citing the defining elements, proposing the right mechanism (amendment, report, corrective plan), and naming the reporting timeline category. Twelve out of fifteen is a strong learning milestone, not a pass prediction.
A Preparation Sequence Built on Decision Points, Plus Readiness Checks
Organize preparation around the six recurring decisions — activity determination, governing framework, HIPAA pathway, consent adequacy, billing classification, event classification — and rehearse each with short scenarios scored against your own rubric.
A realistic, adaptable sequence: block one, determinations and oversight frameworks, including the four-box framework exercise above. Block two, HIPAA pathways and informed consent, pairing each pathway with its documentation. Block three, research billing classification and conflict-of-interest management — disclosure, review, and management plans — tracing one COI scenario from disclosure through an approved management plan. Block four, reportable events and documentation, then mixed case sets drawing from all six published domains. Daily, regardless of pacing, write a one-paragraph rationale for one scenario. Compress or stretch the blocks to fit your calendar, but keep the order, because later decisions depend on earlier ones.
Readiness checks before you sit the exam: you can label an activity as research, QI, or neither, with two supporting facts, in under a minute; you can place any protocol into one of the four oversight boxes; you can recite the three waiver findings and match each HIPAA pathway to its document without notes; you can classify five event vignettes correctly against your own answer key; you can split a trial visit calendar into routine and research-only items and say which document proves each label. Treat these as learning milestones rather than predictions of any score. For administrative details such as eligibility, format, and fees, go directly to the Compliance Certification Board at ccbcertify.org rather than relying on third-party summaries.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
