chamberlainirb

Home · Newsletter

Chart reviews and existing data in a Chamberlain project: whose data it is, and which board rules on it

A records project feels like the safe one. Nobody is recruited, nothing is done to a patient, and the numbers already exist. That is exactly why it stalls: the chart is not yours. It is held by the facility, about a patient, under rules the facility answers for — and the fact that you may open it every shift as part of your job says nothing about whether you may open it as an investigator.

Abigail Ferraro, MSN, RN · 2026-08-23

In short

A records project is human-subjects work whenever identity can be worked out from what you hold. Chamberlain rules on how your file describes the data; the practicum site rules on whether an extract leaves its systems at all, and by which route.

Whose records are these, before they are ever your data?

Start with custody, because everything else follows from it. A medical record is held by the facility as custodian and describes a patient who never agreed to be in your project. You may have credentialed access for treatment, and you may have written in that chart yourself. None of that is access for a project: the role you occupy when you open it changes what the record legally is, and a login issued for care is not a licence to abstract.

So a records project has two doors. Chamberlain rules on your file — what you take, from where, who handles identifiers, and whether that account holds together. The practicum site rules on the record room: its board or nursing-research council, with whatever office it keeps for privacy, decides whether an extract reaches you at all and in what form. No school determination opens a facility’s data warehouse.

Is a records project human-subjects work at all?

The Common Rule never asks whether you met anyone. It reaches any living individual about whom an investigator obtains or analyses identifiable private information (45 CFR 46.102). Private information covers what someone shared for a particular purpose and reasonably expects to stay out of public view — a description a chart fits precisely. It becomes identifiable private information once who the person is can readily be worked out by the investigator, or is already attached to the data.

The test is reachability of identity, not contact. Open a chart, read the name, record what you find under a code you assign, and identity is plainly reachable. Have someone else abstract, keep the link behind, and hand you a file you cannot trace back, and no human subject may be involved at all. The Office for Human Research Protections has long treated coded information that way where the analyst genuinely cannot ascertain identity — for instance where key-holder and analyst have a written agreement barring its release. That guidance is pointed about who decides: not you.

On the Chamberlain side, the first document is not the application at all. The current DNP Project & Practicum Handbook routes a project through a Prescreening Review Form filed inside the project and practicum course sequence, stating that “most DNP projects will meet prescreening criteria” for a finding that the project does not constitute human subjects research. A records project is where that expectation gets tested: prescreening turns on identifiable information, not on how quiet the method feels. The handbook also makes you identify whether an IRB is required at the practicum site, and holds that implementation waits on both. Which forms apply, and how they are submitted, is set by Chamberlain’s current handbook or IRB portal, not by what a colleague filed before. Where the label itself is in play, classification and the review path it decides is the companion read.

The same extract, read by two boards

Chamberlain protects a project it will put its name to. The site protects a record system it answers for long after you finish.

What Chamberlain asks of the data
  • That the variable list in the application is the one in every attachment — no extra field surfacing later.
  • Who performs the abstraction: you, a facility analyst, or someone the site appoints.
  • Where the extract lives, on whose equipment, and at what point any link to identity is destroyed.
  • That training records are current and the data-security plan matches the procedures.
What the practicum site asks of the data
  • Under which lawful route the information leaves its systems, and which of its offices cleared that route.
  • Whether its own analyst must run the query instead of you — a common condition that reshapes the plan.
  • What agreement governs the extract afterwards, who is named in it, and who may sign it.
  • Whether the pull reads as improvement work or as research in its judgement, whatever Chamberlain concluded.

A Chamberlain determination is not a key to the record room, and a data-use agreement is not a project file. Both must exist, and both must describe the same extract.

Identifiable, coded, or de-identified — and who holds the key?

Both boards will settle this from your file whether or not you settle it first, so settle it first. Claim one row below and describe another, and the file returns.

How the extract reaches youWhat the site controlsWhat the Chamberlain file must show
You query and abstract yourself, under your own credentialsWhether you may at all, and by which privacy routeWhy identity is needed, who else reaches the key, when it is destroyed
A facility analyst abstracts; the link stays behind under written agreementWho that person is, what may be released, and the agreement’s wordingThat you will never receive, request, or reconstruct the link — stated, not implied
You receive a limited data set: direct identifiers stripped, dates retainedThe data-use agreement, and who may sign for the facilityThat the file calls it a limited data set, not de-identified, everywhere
You receive an extract with every listed identifier removedWho removed them, and by which methodThat no fine-grained date, unit label, or free-text note survived the strip

One row trips more files than the rest. A spreadsheet with names deleted but admission dates and a unit name intact is not de-identified, and calling it that in front of a privacy office is the fastest way to lose the room.

What does HIPAA add once the records belong to a covered entity?

Most practicum sites are covered entities, and the Privacy Rule gives a facility a short, closed list of lawful ways to let a project use its records. Your file does not choose among them; the facility’s privacy office does. Your file names the chosen route and describes it consistently.

  1. Individual authorization from each patient — rarely practical for a retrospective pull.
  2. A waiver of authorization from an IRB or privacy board. That body must find the privacy risk minimal, see a workable plan for guarding identifiers and destroying them once the work no longer needs them, and be satisfied the project could not practicably run otherwise (45 CFR 164.512(i)).
  3. A limited data set, released under a data-use agreement: direct identifiers stripped, dates and coarse geography permitted, the recipient bound against re-identifying or approaching anyone, and obliged to report any use the agreement does not cover (45 CFR 164.514(e)).
  4. De-identified information, by removing the listed identifiers or by expert determination — which takes the extract outside the Privacy Rule.
  5. A review preparatory to research, permitting a look at records to shape a plan or count eligible cases, on representations that nothing leaves the covered entity. That is how a feasibility count is done honestly — not permission to collect.

Neither board administers the Privacy Rule for the other. Each asks whether your account of the data is coherent — and a file calling itself de-identified on one page while linking readmissions by record number on the next has described two projects.

What has to be identical in both files?

Records projects drift most quietly. Keep these consistent, word for word:

  • The variable list, field for field.
  • The boundaries of the pull: which unit, which encounters, which dates.
  • The name of the privacy route, and who cleared it.
  • Where the extract is stored, and when any link to identity is destroyed.
  • What is said about dissemination, and whether the facility is named in it.

Where do records files actually come back from?

  • A de-identification claim that is not one. Dates, unit labels and free-text notes intact.
  • An “existing data” project that is not. If anything is captured after the file opens, the work is no longer purely retrospective and must say so.
  • An agreement nobody present can sign. Neither a project chair, nor a consultant, nor you can bind an institution. Chamberlain’s handbook already requires a clinical affiliation agreement executed by a duly authorized officer; a data-use agreement travels through that same office, not a liaison’s goodwill.
  • Counts that move. The figure in the application, the site’s packet and the analysis plan should be one figure, or an explained difference.

Where an independent desk fits

Chamberlain’s board says of itself that it does not advise on study design or create required documents such as consent forms. That is the gap a desk like ours fills: we settle the classification and the data plan before a page is drafted, build the school’s file, prepare the site’s packet in its own vocabulary, draft the agreement for the office that can sign it, and carry every reply until both approvals are in writing. We are independent consultants, not affiliated with Chamberlain University; each board decides for itself. How it works lays out the route; the FAQ covers what arrives first.

What to do next

Send the variable list and the facility holding the records. We will tell you free of charge which privacy route your pull needs, whose signature it requires, and whether the site will read it as improvement work or as research. Request the free application review. For the sequence, the process step by step puts both tracks in order; site permission versus the site’s IRB covers the distinction records projects trip over most.

Sources

  • 45 CFR 46.102 — who counts as a human subject; when private information is identifiable. Cornell LII
  • 45 CFR 46.104 — exempt categories, including secondary use of existing information. Cornell LII
  • 45 CFR 164.512(i) — the Privacy Rule’s routes for research use. Cornell LII
  • 45 CFR 164.514 — de-identification, limited data sets, data-use agreements. Cornell LII
  • OHRP — guidance on coded private information. hhs.gov/ohrp
  • Chamberlain IRB — forms, templates, and what the board states it does not provide. chamberlain.edu
  • Chamberlain, DNP Project & Practicum Handbook — prescreening, the site IRB gate, affiliation agreements. PDF
Ingrid Solberg, MSN, RN
Application desk
online