The Health Insurance Portability and Accountability Act (HIPAA) is a complex regulation that affects many researchers at the University of Kentucky (UK). HIPAA is designed to protect the use and disclosure of individually identifiable health information, also known as Protected Health Information (PHI).
You may need IRB approval to create, access, store, use, or disclose PHI if you are employed outside the Covered Entity (CE) and obtaining PHI from a UK CE department, or you are employed by a UK CE department and collecting PHI from subjects.
- If HIPAA Authorization is required for your research, you must use the UK Informed Consent/HIPAA Combined Template as a guide to develop your consent/authorization document; the template can be found under "All Templates" in the APPLICATION LINKS menu on the left in your E-IRB application.
Note: If you are obtaining PHI from another institution, you must use that institution's HIPAA forms and comply with its HIPAA requirements.
*You must understand that you could face criminal and/or civil liabilities for non-compliance.
This webpage contains information to help you comply with these regulations. This information is subject to change as the regulations continue to be interpreted and policies are developed; please check back often.