CRS CRS Research Data Management & Security 1 — Questions and Answers
Question 1: What does HIPAA stand for, and why is it relevant to research data?
- Health Information Privacy and Accountability Act
- Health Insurance Portability and Accountability Act (Correct answer)
- Human Identifiable Patient Assurance Act
- Healthcare Information Protection and Access Act
Correct answer: Health Insurance Portability and Accountability Act
HIPAA (Health Insurance Portability and Accountability Act) includes a Privacy Rule that governs the use and disclosure of individually identifiable health information in research.
Question 2: Under HIPAA, a de-identified dataset is one from which:
- All data has been encrypted
- All 18 specified identifiers have been removed (Correct answer)
- Only the PI can access the data
- The data is stored in an offline system
Correct answer: All 18 specified identifiers have been removed
HIPAA defines de-identification as the removal of all 18 specified identifiers that could link health information back to an individual.
Question 3: What is a Data Management Plan (DMP) in research?
- A plan for performing statistical analyses
- A formal document describing how research data will be collected, stored, secured, and shared (Correct answer)
- A budget for purchasing data analysis software
- A required attachment to every IRB submission
Correct answer: A formal document describing how research data will be collected, stored, secured, and shared
A DMP is a formal document describing how research data will be managed throughout a study's lifecycle, including collection, storage, security, and long-term sharing.
Question 4: Which of the following is a best practice for securing sensitive research data?
- Storing data on personal USB drives for portability
- Using encryption and role-based access controls (Correct answer)
- Sharing login credentials among all team members for convenience
- Keeping raw data in email attachments for easy sharing
Correct answer: Using encryption and role-based access controls
Encrypting sensitive data and implementing role-based access controls are fundamental security practices that protect against unauthorized access.
Question 5: What is the primary purpose of a Data Use Agreement (DUA) in research?
- To authorize IRB review of a study protocol
- To specify the permitted uses and protections governing a shared dataset (Correct answer)
- To approve a study's funding from a federal agency
- To document participant consent for data collection
Correct answer: To specify the permitted uses and protections governing a shared dataset
A DUA is a legal contract between data providers and recipients that defines permitted uses, required protections, and limitations when sharing research datasets.
Question 6: The FAIR data principles in research stand for:
- Fast, Accurate, Integrated, Reliable
- Findable, Accessible, Interoperable, Reusable (Correct answer)
- Formatted, Archived, Indexed, Reviewed
- Funded, Approved, Institutional, Regulated
Correct answer: Findable, Accessible, Interoperable, Reusable
The FAIR principles guide researchers to make data Findable, Accessible, Interoperable, and Reusable to maximize scientific benefit and data utility.
What does HIPAA stand for, and why is it relevant to research data?