Compliance

Can You Use EHR Data for Research? HIPAA Authorization, De-identification and IRB (2027)

Using EHR data for research under HIPAA: authorization, IRB waivers, limited data sets, Safe Harbor's 18 identifiers, preparatory reviews and the Common Rule.

Back to Intelligence
Share This Dispatch

Clinics that hold years of records are often asked whether that data can support a study. The short answer is yes, but only through specific routes. Using EHR data for research under HIPAA means choosing one of the paths the Privacy Rule sets out, documenting it, and sharing no more than the path allows. This guide walks through each path in plain terms, with links to the regulation itself.

Quick Answer

Yes, a HIPAA covered entity can use or disclose patient information for research, but only through a recognized path. The main ones are the individual's written authorization, a waiver or alteration of authorization approved by an IRB or Privacy Board, a limited data set shared under a data use agreement, and de-identified data (by Safe Harbor or Expert Determination). Two narrower paths cover reviews preparatory to research and research on decedents' information. Confirm the path with your IRB or privacy officer before any data leaves the chart.

Research-ready records, kept in one place

ClinikEHR offers de-identified data export, research consent and HIPAA authorization via ClinikForms, participant tracking and an audit log kept for seven years.
Get Started Free →
★★★★★4.9/5 Rating
No credit card required to start

Note: This guide is educational, not legal advice. HIPAA sits alongside other rules, including the Common Rule, FDA regulations and state law. Confirm your plans with your IRB, privacy officer or counsel. For the software side, see the best EHR and research data software for clinical research sites.

Does HIPAA Allow Research Use of Patient Records?

HIPAA's Privacy Rule applies to covered entities, which include health care providers that conduct standard electronic transactions, and to their business associates. It doesn't ban research. It sets conditions under which protected health information (PHI) can be used inside the organization or disclosed to a researcher outside it.

Research is treated differently from treatment, payment and health care operations. A clinic may use PHI to treat a patient without asking permission, but using the same record to answer a research question needs a separate basis. The Privacy Rule lists those bases in two places: individual authorizations in 45 CFR § 164.508, and research uses and disclosures without authorization in 45 CFR § 164.512(i). De-identification and limited data sets sit in 45 CFR § 164.514 (all Cornell LII, checked September 2026).

HHS publishes guidance on each of these in its HIPAA research pages and its de-identification guidance. Read them alongside this summary; they are the official explanation.

One more point shapes everything below. HIPAA protects the data; the Common Rule and FDA rules protect research participants. A single study can be subject to all of them at once, and meeting one doesn't mean you have met the others.

Which Path Fits Your Project?

Start with the table, then read the section for the path that looks right. Your IRB or privacy officer makes the final call.

Your projectLikely HIPAA pathWhat you need
Prospective study enrolling consenting participantsIndividual authorizationA signed authorization, often combined with the research consent
Retrospective chart review where contacting everyone is impracticableIRB or Privacy Board waiverDocumented waiver approval meeting the three criteria
Dataset with dates and town or ZIP, but no direct identifiersLimited data setA data use agreement with the recipient
Data with no identifiers at allDe-identified dataSafe Harbor removal of 18 identifiers, or an expert determination
Checking whether enough eligible patients exist before writing a protocolReview preparatory to researchThe researcher's written representations; no PHI leaves the clinic
Study of deceased patients' recordsDecedents' informationRepresentations plus documentation of death on request

How Does Individual Authorization Work?

The most direct path is to ask the patient. A HIPAA authorization is a signed document giving permission for specific uses or disclosures of their information. The regulation requires core elements, including a description of the information, who may use or disclose it, who may receive it, the purpose, an expiration date or event, and the individual's signature and date (45 CFR § 164.508, checked September 2026). It also requires statements about the right to revoke and whether treatment can be conditioned on signing.

Three research-specific rules make authorization practical:

  • Expiration can be open-ended. For research, the regulation says the statement "end of the research study," "none," or similar language is sufficient as the expiration.
  • It can be combined with consent. An authorization for a research study may be combined with other written permission for the same or another study, including the consent to take part.
  • Research-related treatment can be conditioned on it. A provider may make research-related treatment depend on the participant signing the authorization, an exception to the general rule against conditioning treatment.

Authorization is not the same thing as informed consent under the Common Rule or FDA rules. Consent covers the risks, benefits and procedures of taking part; authorization covers the use of health information. Many sites combine them in one document, but the combined form must satisfy both sets of requirements. Our guide to electronic informed consent for research covers the consent side in more depth.

When Can an IRB or Privacy Board Waive Authorization?

Asking every patient isn't always possible, particularly for retrospective studies of thousands of records. An IRB or a Privacy Board can approve a waiver, or an alteration that removes some required elements, of the authorization requirement (45 CFR § 164.512(i), checked September 2026).

The covered entity must get documentation that the board found three criteria met:

  1. No more than minimal risk to privacy, based on at least an adequate plan to protect identifiers from improper use and disclosure, a plan to destroy identifiers at the earliest opportunity unless there is a health or research reason to keep them, and written assurances that the PHI won't be reused or disclosed to anyone else except as the rule allows.
  2. The research could not practicably be conducted without the waiver or alteration.
  3. The research could not practicably be conducted without access to and use of the PHI.

A Privacy Board is an alternative to an IRB for this purpose. The regulation requires members with varying backgrounds and relevant competence, at least one member not affiliated with the covered entity, and no member reviewing a project in which they have a conflict of interest.

Minimum necessary applies here. The Privacy Rule generally requires a covered entity to limit uses and disclosures to the minimum necessary for the purpose, and a disclosure under a waiver is not one of the exceptions. Share only the fields the approved protocol needs.

What Is a Limited Data Set?

A limited data set sits between fully identified and de-identified data. It strips direct identifiers such as names, street addresses, phone and fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate and license numbers, vehicle and device identifiers, web URLs, IP addresses, biometric identifiers and full-face photographs (45 CFR § 164.514(e), checked September 2026). It may keep town or city, state and ZIP code, and dates such as admission or service dates, which is why researchers often prefer it.

A limited data set may be used or disclosed only for research, public health or health care operations, and only under a data use agreement with the recipient. That agreement must, among other things, limit use and disclosure to what it permits, require appropriate safeguards, require the recipient to report any use or disclosure the agreement doesn't allow, extend the same terms to the recipient's agents, and bar the recipient from identifying or contacting the individuals.

The data use agreement is the clinic's main protection. Keep a signed copy, note which fields were shared and when, and diary the date the agreement says the data will be returned or destroyed.

What Counts as De-identified Data?

Health information that has been properly de-identified is no longer PHI, so the Privacy Rule's research conditions stop applying to it. The regulation offers two methods (45 CFR § 164.514(b), checked September 2026).

Safe Harbor removes 18 kinds of identifiers of the individual and of their relatives, employers and household members, and requires that the covered entity has no actual knowledge that what remains could identify the person, alone or combined with other information.

#Identifier to remove under Safe Harbor
1Names
2Geographic subdivisions smaller than a state, including street address, city, county, precinct, ZIP code and equivalent geocodes; the first three digits of a ZIP code may stay if that three-digit area holds more than 20,000 people, otherwise they become 000
3All elements of dates (except year) directly related to the individual, such as birth, admission, discharge and death dates; all ages over 89, and dates showing such an age, are grouped as 90 or older
4Telephone numbers
5Fax numbers
6Email addresses
7Social Security numbers
8Medical record numbers
9Health plan beneficiary numbers
10Account numbers
11Certificate and license numbers
12Vehicle identifiers and serial numbers, including license plates
13Device identifiers and serial numbers
14Web URLs
15IP addresses
16Biometric identifiers, including finger and voice prints
17Full-face photographs and comparable images
18Any other unique identifying number, characteristic or code, except a permitted re-identification code

Expert Determination is the alternative. A person with appropriate statistical and scientific knowledge applies accepted methods and determines that the risk is very small that the information could be used, alone or with other reasonably available information, by an anticipated recipient to identify an individual, and documents the methods and results. It lets a dataset keep detail Safe Harbor would strip, such as more precise dates, when the expert concludes the risk is still very small.

A clinic may assign a re-identification code so it can link records back later. The code must not be derived from information about the individual, must not be translatable to identify them, and the clinic may not disclose the mechanism for re-identification.

In practice, free text is the hard part. Clinical notes often contain names, dates and places in ordinary sentences, so a de-identified export built from structured fields is far easier to defend than one built from notes.

What Are Reviews Preparatory to Research?

Before writing a protocol, a researcher often needs to know whether a clinic has enough eligible patients. The Privacy Rule allows this without authorization if the covered entity obtains the researcher's representations that the use is solely to review PHI as necessary to prepare a research protocol or for similar purposes, that no PHI will be removed from the covered entity during the review, and that the PHI sought is necessary for the research purposes (45 CFR § 164.512(i)(1)(ii), checked September 2026).

This path is for feasibility, not for collecting a dataset. Counts and aggregate figures are the usual output. If the researcher later wants to contact patients or take data away, another path, usually authorization or a waiver, has to apply.

Can You Research Decedents' Information?

Yes, through a separate path. The covered entity obtains the researcher's representations that the use or disclosure is sought solely for research on the PHI of decedents and is necessary for the research, and, if the covered entity asks, documentation of the death of those individuals (45 CFR § 164.512(i)(1)(iii), checked September 2026).

HIPAA continues to protect a person's health information for a period after death, so this path is not a loophole. It simply replaces the authorization that the individual can no longer give. State law may add its own conditions, so check your state's rules.

How Does the Common Rule Fit With HIPAA?

The Common Rule is the federal policy for the protection of human research subjects, codified for HHS at 45 CFR part 46. It applies to research involving human subjects conducted, supported or otherwise subject to regulation by a federal department or agency that has adopted it (45 CFR § 46.101, checked September 2026). Many institutions also apply its standards to research that isn't federally funded.

At a high level, the Common Rule is about participants: IRB review, informed consent and its documentation, and protections for vulnerable groups. HIPAA is about information: when PHI may be used or disclosed. The two overlap in three places that matter to a clinic:

  • The same IRB can act for both. An IRB reviewing a study under the Common Rule can also approve a HIPAA waiver of authorization, if its documentation meets the Privacy Rule's criteria.
  • Consent and authorization can share a form. As described above, the HIPAA authorization can be combined with the research consent, but it must still contain every HIPAA element.
  • Exemptions don't carry over automatically. A study the IRB finds exempt from parts of the Common Rule may still need a HIPAA path for any PHI it uses.

FDA-regulated studies add another layer: FDA's own informed consent rules at 21 CFR part 50 and, for electronic records and signatures, 21 CFR part 11. The IRB will tell you which apply.

What Should a Clinic Do Before Sharing Records?

Use this as a working checklist. It doesn't replace your IRB's or privacy officer's own procedures.

  1. Name who approves. Decide who in the clinic signs off on research requests: usually the privacy officer, with the IRB or Privacy Board for waivers. Nobody else releases data.
  2. Identify the path. Match the project to one path in the table above, and get the matching document: signed authorizations, waiver documentation, a data use agreement, a de-identification method, or the researcher's written representations.
  3. Apply minimum necessary. For waivers, limited data sets and preparatory reviews, share only what the protocol needs. The minimum necessary standard doesn't apply to disclosures made under a valid authorization (45 CFR § 164.502(b), checked September 2026), but the authorization itself defines what may be shared.
  4. Log the disclosure. Record what was shared, with whom, under which path and on what date. Disclosures under an authorization or as a limited data set are excluded from a patient's accounting of disclosures, but disclosures under a waiver generally must be accounted for; there is a simplified option for research involving 50 or more people (45 CFR § 164.528, checked September 2026).
  5. Use a BAA where it applies. A vendor handling PHI on the clinic's behalf, for example to host or de-identify data, is a business associate and needs a BAA. A researcher receiving data for their own study usually is not.
  6. Keep the paperwork with the study. File approvals, agreements and consent versions where you can find them at an audit.
  7. Diary the end. Note when data must be returned or destroyed, and when authorizations expire.

Where Does the EHR Help?

Good software doesn't decide the legal path, but it makes each path easier to follow and to prove.

  • De-identified export. Pull structured data with identifiers left out, so staff aren't editing spreadsheets by hand.
  • Consent and authorization on the record. Store the signed research consent and HIPAA authorization with the participant's chart, with a record of who signed, when and which version.
  • Cohort tracking. Keep a list of who is enrolled in which study, so the team can see at a glance whose data may be used and on what basis.
  • Audit trail. Record who viewed, changed or exported records, so a question about a disclosure can be answered from the log rather than from memory.
  • Access control. Limit a participant's record to the study team where that is appropriate.

How Does ClinikEHR Handle Research Data?

ClinikEHR offers four research capabilities. It provides de-identified data export. It handles research informed consent and HIPAA authorization via ClinikForms, with e-signature, a certificate of completion and the signed document stored on the participant's record. It supports participant and cohort tracking. And it supports 21 CFR Part 11 requirements for audit trails and electronic signatures; ask us for validation documentation.

The export gives you the data; your project decides the standard. Before sharing a de-identified dataset, confirm with your IRB or privacy officer that the fields you exported meet Safe Harbor or an expert determination, whichever your project relies on.

Around those capabilities, the general EHR functions do the logging:

  • The audit log records every view, change, export, print and sign-in, on every plan, kept for seven years and readable by owners and managers (help center: the audit log).
  • Restrict to assigned staff keeps a client's record to named team members on every plan; the access log and disclosure accounting with CSV export come with Essential and up (client privacy). Whether a given research disclosure belongs in a patient's accounting depends on the path, so check with your privacy officer.
  • ClinikForms attaches a certificate of completion to every signed document. Signature questions in forms are on every plan; sending an uploaded document for signature starts on Essential (forms and e-signatures).
  • Bettar Platforms, Inc., the company behind ClinikEHR, signs a business associate agreement with every customer (HIPAA).

ClinikEHR is not an EDC or a CTMS. For case report forms, randomization, monitoring and safety reporting, use a dedicated tool alongside it; our research software guide explains how the pieces fit. Plans and prices are on the pricing page.

Frequently Asked Questions

Can a clinic use patient records for research without consent?

Sometimes. HIPAA allows research use without an individual's authorization under an IRB or Privacy Board waiver, as a limited data set with a data use agreement, as de-identified data, for reviews preparatory to research, or for research on decedents. Confirm the path with your IRB or privacy officer.

What are the 18 HIPAA identifiers?

They are the identifiers Safe Harbor requires you to remove: names, small geographic areas, date elements other than year, phone and fax numbers, email addresses, Social Security numbers, medical record, health plan and account numbers, certificate and license numbers, vehicle and device identifiers, URLs, IP addresses, biometrics, full-face photos, and any other unique identifying code.

Is a limited data set the same as de-identified data?

No. A limited data set can keep dates and town, state or ZIP code, so it is still PHI and needs a data use agreement. De-identified data has had all 18 Safe Harbor identifiers removed, or passed an expert determination, and is no longer PHI.

Is a HIPAA authorization the same as informed consent?

No. Informed consent covers taking part in the research; a HIPAA authorization covers the use and disclosure of health information. They can be combined in one document if it meets both sets of requirements.

Does minimum necessary apply to research?

It applies to disclosures under a waiver, limited data sets and preparatory reviews. It does not apply to disclosures made under a valid authorization, although the authorization itself limits what may be shared.

Can ClinikEHR export de-identified data?

Yes. ClinikEHR provides de-identified data export. Confirm with your IRB or privacy officer that the exported fields meet the standard your project relies on, Safe Harbor or an expert determination.

Conclusion

EHR data can support research, but only through a path the Privacy Rule recognizes: authorization, an IRB or Privacy Board waiver, a limited data set with a data use agreement, de-identified data, a preparatory review or research on decedents. Pick the path before anything leaves the chart, share only what that path allows, and keep a record you could hand to an auditor. The Common Rule and FDA rules may apply on top, so involve your IRB early.

Key takeaways:

  • HIPAA allows research use of PHI through specific, documented paths
  • Safe Harbor de-identification removes 18 identifiers; Expert Determination is the alternative
  • A limited data set is still PHI and needs a data use agreement
  • Authorization and informed consent are different, but can share a form
  • Log every disclosure and confirm the path with your IRB or privacy officer

Consent, authorization and audit trail in one record

ClinikEHR stores research consent and HIPAA authorization signed via ClinikForms on the participant's record, with de-identified export and an audit log kept for seven years.
Get Started Free →
★★★★★4.9/5 Rating
No credit card required to start

Related Articles

Stay in the loop

Subscribe to our newsletter for the latest updates on healthcare technology, HIPAA compliance, and exclusive content delivered straight to your inbox.

Weekly updates
Healthcare insights
HIPAA updates
Subscribe to our Newsletter
Join over 100,000 healthcare professionals

We respect your privacy. Unsubscribe at any time.