Applies to: Agreement V3.0 (§4.4) · SMART IRB SOPs (section 16)
Version 3.0 puts the Relying Institution that is a HIPAA Covered Entity in charge of its own HIPAA compliance. Under Versions 1.0 and 2.0 the Agreement presumed that the Reviewing IRB would make HIPAA determinations on the Relying Institution's behalf unless it opted out. Under Version 3.0 the Covered Entity performs every task required for its own HIPAA compliance, and the Reviewing IRB steps in only where the Relying Institution has not supplied its own authorization or waiver.
Why. Many Relying Institutions are Covered Entities and may not use or disclose PHI for research unless a HIPAA pathway is satisfied — individual authorization, a waiver or alteration of authorization approved by an IRB or Privacy Board, a Limited Data Set under a Data Use Agreement, or another provision. HIPAA compliance is the Covered Entity's legal responsibility, and nothing in the Agreement shifts it.
What the Agreement provides (§4.4)
| Topic | Rule |
|---|---|
| Telling the Reviewing IRB | A Relying Institution that is a Covered Entity says so when it cedes review. |
| Authorization forms (§4.4.1) | The Relying Institution may use its own authorization form or section. If it does not provide one, the Reviewing IRB provides one that meets 45 CFR 164.508. The Relying Institution must flag any Local or Other Consideration that requires the authorization to be separate from the consent form; otherwise the Reviewing IRB may merge them. The Reviewing IRB is not obliged to review a form the Relying Institution provides (unless it will be merged into the consent), and is never responsible for that form's HIPAA compliance. |
| Waivers and alterations (§4.4.2) | The Relying Institution may obtain its own waiver or alteration of authorization and document that to the Reviewing IRB. If it does not, the Reviewing IRB reviews the waiver request under 45 CFR 164.512(i). The Relying Institution must flag any Local or Other Consideration that would prevent a waiver at its site. |
| Reviewing IRBs that do not handle HIPAA (§4.4.3) | A Reviewing IRB or Reviewing IRB Institution that, by policy or practice, does not provide authorization forms or review waiver requests — some federal institutions and non-Covered-Entity IRBs, for example — tells the Relying Institution so, and the Relying Institution satisfies those obligations itself. |
| Everything else | Accounting of disclosures, breach response, minimum-necessary determinations, and all other HIPAA duties stay with the Covered Entity. |
What the SOPs add (section 16). The SMART IRB SOPs, which apply by default, set the working procedure: the Relying Institution that is a Covered Entity makes its own waiver and alteration determinations, and provides its own authorization language, unless the Reviewing IRB and Relying Institution agree that the Reviewing IRB will do so. A Reviewing IRB that makes waiver determinations will not approve release of directly identifiable data outside the Covered Entity without consulting the Relying Institution's Point of Contact, and until the institutions agree on an approach the Relying Site Study Team cannot carry out the activity the waiver would cover. Potential breaches of PHI are addressed in the same section.
How to document your arrangement. Note in the Implementation Checklist or the Letter of Acknowledgment whether the Relying Institution will handle HIPAA itself (the SOP default) or the Reviewing IRB will provide authorization language and review waivers on its behalf. Consortium-wide HIPAA arrangements can be recorded once in the Implementation Checklist.
See also - Can a non-Covered Entity serve as Reviewing IRB for a Covered Entity? - Default vs. flexible implementation - Local Considerations and Other Considerations
Comments
0 comments
Article is closed for comments.