Data-Type Guidance

Data-Type Guidance

Guidance for Specific Data Types

Additional recommendations on top of the cookbook basics, find your data type for the controls that apply.


The protections required depend on the type of data you handle. The guidance below supplements, and never replaces, sponsor, regulatory, IRB, or contractual requirements. Engage Research IT and Information Security early for anything regulated.

Find Your Data Type 8 Categories

Research involving PHI must comply with applicable HIPAA requirements.

  • Follow HIPAA administrative, physical, and technical safeguards.
  • Use approved systems for storing and processing PHI.
  • Ensure workstations and laptops meet HIPAA security requirements.
  • Limit access to authorized personnel.
  • Follow approved procedures for device and media handling.
  • Use encryption whenever required.

CUI requires protections consistent with NIST 800-171 and sponsor requirements.

  • Engage Information Security and Research IT as early as possible.
  • Complete any required CUI review process during proposal development.
  • Store and process CUI only within approved environments.
  • Follow all applicable NIST 800-171 requirements.
  • Obtain approval before implementing new tools, workflows, or collaborations involving CUI.

If a project operates within an approved SSP:

  • Store, process, and analyze data only within the approved system boundary.
  • Do not move data to personal devices or unapproved cloud services.
  • Do not use unapproved collaboration tools.
  • Coordinate with Research IT before changes that affect storage, processing, access, or sharing.
  • Update the SSP when required.

PII requires safeguards to prevent unauthorized disclosure.

  • Restrict access to authorized personnel.
  • Use encrypted devices and storage.
  • Avoid downloading data to unmanaged systems.
  • Use approved methods for sharing information.

Human subjects research data should be protected throughout the project lifecycle.

  • Follow the approved IRB protocol.
  • Store data only in approved systems.
  • Use individual user accounts.
  • Encrypt devices used to access or store research data.
  • Restrict access to approved study personnel.
  • Report suspected data exposure immediately.

Even when data are de-identified, contractual obligations may still apply.

  • Review the DUA for security and confidentiality requirements.
  • Store data only in approved locations.
  • Encrypt devices used to access or store the data.
  • Use individual user accounts.
  • Follow any breach notification requirements in the agreement.
  • Report incidents immediately.

Although lower risk, de-identified research data should still be protected.

  • Use approved storage systems.
  • Encrypt devices storing research data.
  • Use individual user accounts.
  • Maintain secure and updated devices.
  • Follow sponsor and institutional requirements.
  • Report suspected incidents promptly.

Publicly available data should still be handled responsibly.

  • Follow licensing and terms-of-use requirements.
  • Use approved storage systems when appropriate.
  • Maintain basic cybersecurity protections.
  • Properly document data sources and provenance.
  • Report security incidents affecting research systems.