The Problem
Research collaboration and HIPAA compliance are in constant tension
Academic medical centers share PHI with research partners, grant agencies, and affiliated institutions constantly. Each data-sharing agreement creates new exposure. Traditional security models cannot track or restrict data once it leaves your systems.
IRB-approved data sharing does not guarantee that partners handle PHI correctly after receipt.
De-identified datasets can be re-identified when combined with data from collaborating institutions.
Researchers often work from personal devices or off-campus networks that fall outside institutional controls.
A breach involving research PHI can jeopardize NIH funding, accreditation, and patient trust simultaneously.