The data security plan in a Chamberlain application: named storage, named access, on both files
Almost every returned data security section fails the same way: it is written in adjectives. Records are held safely, the laptop has a password, everything stays private. Not one of those phrases gives a reviewer something checkable, or gives a facility something it could agree to. A plan that survives both readings does something plainer — it names the items, the places, the people and the endpoint, and it says the same thing in the school's file as it does in the facility's.
Name every data item, where it is held, who can reach it, and when it is destroyed. Replace adjectives with specifics, keep identifiers off personal devices, and make the plan, the consent and the permission letter agree.
What are the boards actually asking?
Chamberlain's application for initial review gathers information about objectives and procedures, risks and benefits, recruitment, data collection methods and tools, consent procedures, and how researchers will ensure privacy of subjects and confidentiality of data. That last clause is the data security plan, and it is phrased as two separate duties. Privacy concerns the person — whether they can control who observes them and what is asked of them. Confidentiality concerns the information — what happens to it after they have handed it over. A plan that only discusses file storage has answered half the question.
The federal criterion behind it is 45 CFR 46.111(a)(7), which asks a board to find, where appropriate, that provisions guarding participant privacy and holding data confidential are adequate. That word is deliberately relative: adequate to the sensitivity of what you hold. A tally of hand-hygiene observations with no names attached needs less machinery than a set of interview recordings about workplace error, and a reviewer is judging fit rather than volume.
The practicum site's council asks the same question with more at stake, because the records are its records and the exposure is its exposure. It will want to know whether anything identifiable leaves its systems, what happens on your laptop, whether a third party ever sees the material, and what agreement governs any of it. Those are answerable questions, and answering them concretely is most of the work.
What does a plan that reads well contain?
Seven items, each answered with a noun rather than an adjective. If you can complete this inventory, you have a plan; if any line reads "securely", you do not yet.
| The item | What "named" looks like | The version that gets queried |
|---|---|---|
| What you collect | Each variable listed, marked identifiable, coded, or anonymous | "Demographic and outcome data" |
| Where it lives | The named institutional storage, and the device it is entered on | "A secure cloud folder" |
| Who can reach it | Every person by role, including anyone at the facility | "Only the research team" |
| How identifiers are handled | Whether a code list exists, who holds it, where it sits apart from the data | "Data will be de-identified" |
| How it moves | The route from the facility to storage, and whether identifiers travel | Silence — the commonest gap of all |
| Third parties | Transcription, survey platforms, translators, each with its agreement | A platform named in the methods and absent from the plan |
| When it ends | The retention point, the disposal method, who performs it | "Destroyed at the end of the project" |
The discipline that makes this quick is to write the plan from the protocol rather than alongside it. Take the methods section, list every point at which information changes hands or changes location, and answer the seven questions at each point. Anything you cannot answer is a decision you have not yet made, which is better discovered now than in a revision request.
What does the health information rulebook add?
If you touch patient records, a second framework applies, and knowing its vocabulary changes how you write. Under the HIPAA rules at 45 CFR 164.514(b), information is de-identified either by expert determination — a qualified person applying accepted statistical methods and documenting them — or by the safe harbour route, which removes eighteen categories of identifier including names, geographic detail below state level, all date elements other than year, contact details, record and account numbers, biometrics, and full-face images, along with any other unique identifying number or characteristic.
Two consequences matter for a practice project. First, a code that lets you re-link records is permitted under 164.514(c), but only if the code is not derived from anything about the person and is not shared or used for another purpose — which is precisely why the code list must sit somewhere the data does not. Second, if you need dates or fuller geography, you are likely working with a limited data set under 164.514(e), and that route runs through a data use agreement between institutions. A data use agreement is negotiated, not asserted, and it is a reason to raise the question with the facility early rather than late.
Say which of these three states your material is in — identifiable, coded, or de-identified — and use the word consistently thereafter. Describing a coded interview set as "anonymous" is the single most common contradiction we correct, and both boards catch it, because an anonymous data set cannot be linked back to withdraw someone's contribution.
Where may the data actually live?
The safe default is institutional storage on both sides, and personal equipment kept out of it. Identifiable material belonging to a facility is best left inside that facility's systems; where analysis must happen elsewhere, the material that travels should be the coded or de-identified version, with the key retained at the site. Recordings, paper consent forms and field notes are the awkward cases, because they are identifiable by nature and physically portable — say where they are held, in what locked container or named account, and for how much of the project they exist at all.
Facilities frequently impose conditions beyond anything the school requires: privacy training before access, use of a facility account rather than a personal one, a prohibition on removable media, or a rule that nothing identifiable leaves the network. Chamberlain's handbook already signals that facilities set requirements of their own for anyone working on site, listing privacy training among the conditions a placement may attach. Ask for those conditions in writing, then write them into the plan, so that the plan describes what the facility has actually agreed to rather than what you hope it will permit.
Why must the plan match the other documents?
Because the data security plan is the document most likely to contradict its neighbours, and contradictions are visible to any careful reader. The consent form makes promises about confidentiality; the permission letter implies what the facility will and will not receive; the protocol describes tools and platforms. When those three disagree with the plan, a reviewer cannot tell which one is true, and asking is the only responsible response.
The pairs worth checking before filing are short and specific. Does the consent's confidentiality section describe the same storage and the same access list? Does its withdrawal statement match what the plan says happens to already-collected material? Does the permission letter agree with the plan about whether the facility receives anything identifiable? Is every platform in the methods section also in the plan, with its agreement? Does the plan's disposal point match what participants were told? Anything both files must state identically should be drafted once and copied across, never typed twice — the version discipline set out in the consent requirements article applies here without change.
Chamberlain's treatment of a breach underlines why this is worth an hour. Its examples of promptly reportable non-compliance include a breach of confidentiality, and its amendment route governs changes to an approved protocol before they are implemented. Quietly drifting from your own plan is not a tidy-up item; it is the situation those reporting rules exist for. Where the plan gets drafted within the wider route is set out on the how-it-works page.
What to do next
Does your data security section run to a couple of sentences? Does the consent promise something the plan never states? Either way it is a paper problem, and paper problems are cheapest to repair before a board opens the file. Book the free application review, attaching the plan, the consent and your methods. A consultant will name the item from the inventory above that is absent or contradicted, and set out how a reviewer would put it. Should the plan already hold together, that is the answer you get, and nothing goes to either board without your say-so. Scope of the review is described in the FAQ; the application checklist inventories what both submissions carry.
Sources
- Chamberlain University, Institutional Review Board — the initial review application's coverage of privacy and confidentiality, amendment rules, and reportable non-compliance including breach of confidentiality — chamberlain.edu/chamberlain-university-institutional-review-board
- Chamberlain University, DNP Project & Practicum Handbook — conditions a practicum facility may attach, including privacy training — chamberlain.edu/media/3691/dnp-project-practicum-handbook.pdf
- 45 CFR 46.111 — approval criteria; see (a)(7) on privacy and confidentiality provisions — law.cornell.edu · section 46.111
- US Department of Health and Human Services, Office for Civil Rights — guidance on de-identification under the Privacy Rule, explaining the expert determination and safe harbour methods — hhs.gov · de-identification guidance
- 45 CFR 164.514 — de-identification by expert determination or safe harbour, re-identification codes at (c), and the limited data set with its data use agreement at (e) — law.cornell.edu · section 164.514
Storage options and application fields change. Where this article and Chamberlain's current handbook or IRB portal differ, the handbook and portal govern. This practice is independent of Chamberlain University and is not affiliated with it.