NIH Confidentiality Certificates Add Layer of Privacy Protection Post-Dobbs
Time 2 Minute Read

Following the ruling in Dobbs, the National Institutes of Health’s (“NIH’s”) certificates of confidentiality offer an important layer of privacy protection to reproductive health research data. The Public Health Service Act created the certificates of confidentiality program, which prohibits the disclosure of identifiable, sensitive research data “in any Federal, State, or local civil, criminal, administrative, legislative, or other proceeding” without the research subject’s consent. These certificates add a layer of protection to abortion and fertility data collected as part of NIH research.

NIH certificates of confidentiality apply only to human subjects research data and protect that information only if the data can be combined with other information to uncover an individual’s identity. Only studies that (1) collect identifiable and sensitive information, (2) are cleared by an institutional review board, and (3) comply with the Common Rule (45 C.F.R. 46) can use certificates of confidentiality. 

Although the certificates generally protect the underlying information from compelled disclosures, the Public Health Service Act permits (but does not require) disclosure if such disclosure is required by federal, state, or local law, including but not limited to laws requiring the reporting of communicable diseases or child abuse. It is unclear, however, post-Dobbs, whether these certificates would protect reproductive health care information against disclosure under state laws that mandate disclosure of such information.

You May Also Be Interested In

Time 2 Minute Read

The Supreme Judicial Court of Massachusetts, the state’s highest appellate court, recently held that website operators’ use of third-party tracking software, including Meta Pixel and Google Analytics, is not prohibited under the state’s Wiretap Act.

Time 5 Minute Read

On October 31, 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights announced two settlements over medical providers’ failures to comply with the HIPAA Security Rule, one with Plastic Surgery Associates of South Dakota and one with Bryan County Ambulance Authority.  The settlements mark the sixth and seventh OCR enforcement actions related to ransomware attacks with the latter being the first enforcement action in OCR’s Risk Analysis Initiative.

Time 2 Minute Read

On November 1, 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights and the Assistant Secretary for Technology Policy announced the release of a new version of the Security Risk Assessment Tool.

Time 2 Minute Read

On September 26, 2024, the U.S. Department of Health and Human Services Office for Civil Rights entered into a resolution agreement and corrective action plan with Cascade Eye and Skin Centers, P.C. following a ransomware attack that impacted approximately 291,000 files containing electronic PHI.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page