Administrative Header
Project title, requestor name, contact, department, and effective date. These fields enable routing, tracking, and linkage to IRB or contract records for oversight and cost allocation.
A structured form clarifies scope, preserves patient privacy, and documents legal and technical controls needed for compliant analysis under HIPAA and institutional policy.
Typical users complete or authorize this form before any dataset extraction or analytic work begins.
A data analyst or data scientist that completes technical sections: dataset identifiers, variables, extraction logic, statistical methods, and expected outputs. They certify that exported fields are strictly necessary and that de-identification or minimum necessary principles will be applied during analysis.
An institutional privacy or HIPAA officer reviews legal authorizations, ensures a valid legal basis for processing PHI, confirms data use agreements are in place, and records any required patient authorizations or waivers before approving access.
Project title, requestor name, contact, department, and effective date. These fields enable routing, tracking, and linkage to IRB or contract records for oversight and cost allocation.
Precise dataset identifiers, date ranges, inclusion/exclusion criteria, and required tables or registries. Clear scope prevents over-collection and simplifies downstream validation and reproducibility.
Itemized list of fields requested with justification for each (PHI, limited, or de-identified). This supports minimum necessary assessments and steers approvals toward safer alternatives.
High-level methods, outputs, and deliverables including statistical techniques, data linkage steps, and expected reports. This helps privacy reviewers assess re-identification risk from derived datasets.
IRB approval number or exemption, data use agreement references, and any patient authorizations needed. Documenting legal basis prevents unauthorized disclosures and audit findings.
Storage location, access controls, encryption requirements, retention period, and destruction steps. Explicit controls align technical safeguards with HIPAA and institutional policy.
| Field | Configuration |
|---|---|
| Project Metadata | Required text fields with validation and character limits |
| Approvals | Sequential routing to privacy, IRB, and PI |
| Authentication | MFA for approvers and optional SMS verification |
| Audit Trail | Capture timestamps, IP, and signer identity |
Identify integrations, file formats, and authentication needed to support secure eSubmission workflows.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Privacy and technical review within 7 business days
IRB decisions vary; expedited reviews often within 30 days
Covered entity responses to access requests within 30 days (45 CFR §164.524)
Data exports typically delivered within 7–21 days after approvals
Retention counts from effective date entered on the form
A hospital data team requested de-identified encounter data for a quality improvement study
A clinic operations lead requested aggregated visit counts for staffing decisions