Research sometimes asks people to share information they would not normally discuss with a stranger. A study may collect details about substance use, mental health, sexual behavior, genetic information, immigration status, or other personal experiences. When researchers collect this type of information, confidentiality is more than a line in a consent form. It is an important part of protecting participants and maintaining their trust.
That trust can affect the quality of the research. People may hesitate to participate when they fear that personal information could reach employers, family members, government agencies, law enforcement, or others. Even those who agree to participate may hold back information if they are unsure about how their data will be protected. Research on sensitive topics has long shown that privacy and confidentiality concerns can influence participation and reporting (Tourangeau & Yan, 2007). Researchers therefore need to think about confidentiality before recruitment and data collection begin.
For studies involving identifiable, sensitive information, a Certificate of Confidentiality (CoC) can provide an added layer of protection. Under federal law, Certificates can protect covered research information from certain forms of compelled disclosure (42 U.S.C. § 241(d)). NIH policy provides Certificates automatically for qualifying NIH-funded research and explains how these protections apply to identifiable, sensitive information (National Institutes of Health [NIH], 2017).
A Certificate, however, does not replace good research practices. Researchers still need appropriate consent procedures, secure data practices, staff preparation, and Institutional Review Board (IRB) review when required. The IRB has an important role in assessing participant protections and the way confidentiality is explained in study materials. Researchers who are new to these responsibilities may benefit from IRB training before working with sensitive participant information.
So, what does a CoC actually protect? When does a study receive one, and what are its limits? Understanding those questions early can help researchers build confidentiality protections into the study from the start rather than trying to address them after data collection has begun.
1. What Is a CoC, and When Does It Apply?

Before planning around a CoC, researchers need to know what it is and whether their study falls within its scope. This is especially important because not every project handles information in the same way. Funding source, identifiability, and the type of information collected can all affect how Certificate protections apply.
What Exactly Is a CoC?
A CoC is a legal protection for identifiable, sensitive information collected or used in certain research. Its authority comes from Section 301(d) of the Public Health Service Act, as amended by the 21st Century Cures Act (42 U.S.C. § 241(d)). The basic purpose is straightforward: to help protect research participants from certain disclosures of their identifiable, sensitive information. This protection matters because researchers can sometimes receive requests or legal demands for participant information. A Certificate places legal limits on when covered information may be disclosed.
It is important to separate this protection from IRB approval. A Certificate does not approve a study, and receiving one does not mean that a study has completed all applicable ethical or regulatory requirements. When a project involves human participants, researchers may still need an IRB review under the rules that apply to their institution, funding, and research activities (Protection of Human Subjects, 2018).
Which NIH-Funded Studies Receive Protection?
For NIH-funded research, the process changed significantly after implementation of the 21st Century Cures Act. NIH policy states that Certificates are issued automatically for NIH-funded research that collects or uses identifiable, sensitive information and began or was ongoing on or after December 13, 2016 (National Institutes of Health [NIH], 2017). In other words, qualifying NIH-funded investigators generally do not submit a separate application to obtain the Certificate.
Researchers still need to determine whether their work meets the policy requirements and understand the responsibilities that come with the protection. For students and early-career investigators, human-subject research training can be useful here because it helps researchers understand how confidentiality requirements fit alongside informed consent and other participant protections. Good IRB training for students should teach researchers to identify these issues during protocol development rather than waiting until recruitment begins.
What Counts as Identifiable, Sensitive Information?
The word “identifiable” can confuse. Under the Certificate statute, identifiable, sensitive information includes information about an individual that is gathered or used during biomedical, behavioral, clinical, or other research when the individual is identified, or there is at least a very small risk that some combination of the information, a request for the information, and other available data could identify that person (42 U.S.C. § 241(d)). That definition means researchers should not assume that removing a participant’s name automatically resolves every confidentiality concern. The information collected, how it is stored, and whether it can reasonably be linked back to a person all deserve attention.
Studies involving substance use, sexual behavior, mental health, genetic data, or other highly personal subjects are clear examples where disclosure could concern participants. Yet the legal test is not simply whether a topic feels private. Researchers should assess whether the study collects or uses identifiable, sensitive information as defined by the applicable law and policy.
What About Research That Is Not Funded by NIH?
A study does not necessarily have to receive NIH funding for Certificate protection to be possible. The NIH may issue Certificates for eligible research that is not federally funded. NIH maintains a process for investigators conducting eligible non-NIH-funded research to request a Certificate (NIH, 2025). This issue can arise in university research, privately funded projects, or doctoral studies. Researchers working outside their home institution may encounter an external IRB as part of the oversight arrangement.
Those arrangements should not be confused with the Certificate itself. The review body evaluates the research under applicable requirements, while the Certificate provides a particular form of confidentiality protection. Researchers who need to find an IRB should first determine what oversight their institution or research setting requires. Choosing a human subject review board or obtaining IRB services does not, by itself, determine whether Certificate protections apply.
Does the Protection End When the Study Ends?
One useful feature of a Certificate is that its protection is not limited to the active data-collection period. For information covered by a Certificate, protection generally continues after the research or NIH funding ends (NIH, 2017). This matters for studies that retain identifiable information for later analysis or permitted research uses. Researchers should therefore think beyond the immediate study schedule. Decisions about long-term storage, access, and permitted sharing can remain important after recruitment closes.
Knowing whether a study falls under Certificate protection is only the first part of the issue. Researchers need to understand exactly what that protection does when someone requests research information, and when disclosure may still occur. The next section examines those boundaries and explains why a Certificate should never be presented as an absolute promise of secrecy.
2. What a Certificate Protects, and Where Its Protection Stops

A CoC offers meaningful protection, but researchers need to be careful about how they describe it. It does not mean that participant information can never be disclosed. Instead, federal law sets out specific protections against disclosure while identifying situations in which disclosure is allowed. Knowing where those boundaries fall helps researchers give participants accurate information and respond properly if a request for research records arrives.
Protection Against Compelled Disclosure
One of the main protections of a Certificate concerns compelled disclosure. Under federal law, a person covered by a Certificate generally may not disclose or provide the name of a research participant or information that could identify that person in federal, state, or local civil, criminal, administrative, legislative, or other proceedings (42 U.S.C. § 241(d)). This protection can become especially important if a researcher receives a subpoena or another legal demand seeking covered research information. The Certificate creates a legal basis for protecting identifiable, sensitive information from disclosure in those proceedings.
For researchers, the practical lesson is simple: a legal demand for records should not be treated like an ordinary data request. The research team should follow institutional procedures and seek appropriate guidance before responding. An IRB may be an important institutional contact for questions about the approved protocol, although legal counsel may be needed when interpreting or responding to a subpoena.
Researchers Cannot Simply Choose to Disclose Protected Information
The protection is not limited to situations where a court orders researchers to provide information. The statute restricts voluntary disclosure of covered identifiable, sensitive information, subject to specific exceptions (42 U.S.C. § 241(d)). That point matters in day-to-day research. Investigators should know who has access to protected information, why access is needed, and what rules apply when information is shared.
Staff who complete appropriate IRB training are better prepared to recognize that confidentiality is an ongoing research responsibility rather than a task completed when a consent form is signed. Researchers should pay similar attention when working across organizations. If a study uses an external IRB, for example, the research team still needs clear internal procedures for handling protected data and responding to disclosure questions. Oversight arrangements do not remove the investigator’s responsibilities under the Certificate.
A Certificate Is Not the Same as HIPAA Protection

Certificates can be confused with other privacy rules. The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, for example, establishes requirements for protected health information handled by covered entities and their business associates. Whether HIPAA applies depends on the organizations and information involved (U.S. Department of Health and Human Services [HHS], 2003). A Certificate serves a different purpose. It provides statutory protection against certain disclosures of identifiable, sensitive research information. Depending on the study, both sets of requirements may matter.
Researchers should therefore avoid assuming that compliance with one automatically satisfies the other. The same distinction applies to IRB approval. Approval indicates that the required review process has been completed and that the board has determined that applicable criteria for approval are met. It does not turn a Certificate into a general data-security system, nor does a Certificate replace the protections considered during ethical review.
Legal Protection Still Needs Practical Data Protection
Even strong legal protections cannot make up for weak data practices. Researchers still need sensible controls over identifiable information. Depending on the study, these may include limiting data access, separating identifiers from research records, encrypting files, setting retention procedures, and training research staff.
These practices reflect a broader principle in human-participant research: confidentiality should be protected through more than one safeguard. Federal regulations require adequate provisions to protect participant privacy and maintain data confidentiality when appropriate (Protection of Human Subjects, 2018). A Certificate can strengthen that framework, but it does not replace it.
This distinction is especially important for doctoral researchers who may be handling sensitive information for the first time. Human-subject research training can help investigators understand their ethical and regulatory duties, while an independent IRB may provide review in settings where an appropriate institutional board is not available. Neither resource changes what a Certificate protects, but both can support better decisions about participant safeguards. Once researchers understand the limits of a Certificate, the next question is how to put that knowledge into practice. Section 3 turns on how to build CoC requirements in your study and the steps investigators can take before the first participant is enrolled.
3. Building CoC Requirements into Your Research Plan

Knowing that a CoC applies is useful. Building its requirements into the actual study is what makes that knowledge practical. Researchers should address confidentiality while developing the protocol, consent materials, data-management procedures, and staff responsibilities. Doing this early makes it easier to spot gaps before participants begin sharing sensitive information.
Start by Mapping the Information You Will Collect
A good starting point is to list the information the study will collect, where it will come from, and whether it can be connected to an individual. This exercise should cover more than names and contact details. Researchers may collect dates, locations, medical information, audio recordings, genetic information, or combinations of variables that could potentially identify someone.
Next, researchers should map where each type of information will go. Will data remain on an institutional server? Will researchers use cloud-based software? Will interviews be sent to a transcription provider? Will collaborators at another university receive study files?
These questions help researchers see how sensitive information moves through the project. They support the regulatory requirement to make adequate provisions for protecting participant privacy and maintaining confidentiality when appropriate (Protection of Human Subjects, 2018).
Make the Consent Form Match the Study
Consent materials should tell participants what they need to know without making promises the research team cannot keep. For studies covered by a Certificate, the consent process should explain the confidentiality protection and relevant limits in language participants can understand. NIH provides sample language that researchers can consider when preparing consent forms for studies covered by a Certificate (National Institutes of Health [NIH], 2017).
Researchers should adapt their materials to the actual study rather than inserting standard wording without checking whether it accurately describes their procedures. This is one area where IRB services can be useful when researchers need support preparing materials for ethical review. The final wording should remain consistent with the protocol, applicable institutional requirements, and the way information will actually be handled.
Plan for Collaborators and Data Sharing
Confidentiality planning becomes especially important when more than one institution is involved. Under the Certificate statute, recipients of protected information generally become subject to the applicable disclosure restrictions when that information is disclosed to them for permitted research purposes (42 U.S.C. § 241(d)). Researchers should therefore identify collaborators and data recipients before sharing begins. Agreements between institutions can clarify what information will be transferred, who can access it, how it can be used, and how it should be protected.
Multi-site research may involve reliance arrangements in which one IRB conducts review for participating institutions. In other settings, researchers may work with an external IRB. These arrangements concern research oversight and should be planned alongside, rather than substituted for, the research team’s responsibilities for protected information. Researchers using repositories or planning secondary research should consider what will happen to the information later. A data-sharing plan should match participant permissions, Certificate requirements, applicable regulations, and any institutional restrictions.
Create a Response Plan Before You Need One
Sensitive-data planning should include a clear process for unexpected events. Who should a researcher contact after receiving a subpoena? What happens if information is accidentally sent to the wrong recipient? Who evaluates whether a proposed disclosure is permitted? The answers may involve the principal investigator, privacy or compliance staff, institutional legal counsel, and the IRB, depending on the issue. Establishing these contacts in advance can prevent individual team members from making rushed decisions when a problem occurs. Researchers should document their procedures. Written records can show how access was assigned, how team members were trained, where information was stored, and how confidentiality concerns were handled.
Use a Pre-Study Confidentiality Check
Before recruitment starts, researchers can conduct one final review. Check whether the team has identified all sensitive information, limited access appropriately, prepared accurate consent language, established secure storage procedures, and trained everyone who will handle participant data. The team should confirm that any required IRB approval is in place before beginning activities that require approval. Doctoral researchers who are unfamiliar with the process may benefit from IRB training for students, particularly when their projects involve highly sensitive information or several organizations.
A Certificate works best when it is part of a research plan built around confidentiality from the beginning. With those procedures established, researchers are in a stronger position to protect participants throughout data collection, analysis, sharing, and retention. The final section brings these ideas together and offers a practical way to think about Certificates as one part of responsible research practice.
Conclusion

Research involving sensitive information asks participants to place considerable trust in the people conducting the study. A CoC can help researchers honor that trust by providing an important legal safeguard for identifiable, sensitive research information. But it works best as one part of a wider confidentiality strategy. For doctoral students and other researchers, managing these responsibilities alongside protocol development, recruitment, and data collection can be demanding.
This is where the right guidance can provide a clear path forward. Effective IRB training can help researchers understand their responsibilities and make better-informed decisions before problems arise. Researchers should communicate with their IRB when questions emerge about consent, confidentiality, or participant protections. When review is required, obtaining IRB approval before beginning covered research activities remains an essential part of responsible study preparation.
BeyondBound IRB supports researchers who want expertise and care in handling the process without being left to work through each requirement alone. Our goal is no roadblocks, just support, with direct engagement that helps researchers address questions, prepare their studies, and move through the review process with greater confidence. Rather than offering the same solution for every project, we take a comprehensive, bespoke approach based on the needs of the individual study.
Education matters just as much as review. Through IRB Heart, researchers can strengthen their understanding of human-participant protections and learn how to approach ethical research decisions with confidence. The program is designed to eliminate obstacles created by uncertainty and foster collaboration among researchers who want to understand not only what is required, but why it matters.
A Certificate provides meaningful protection, but good research depends on what investigators do with that protection. If you are preparing a study involving sensitive information, you do not have to sort through the process on your own. Connect with BeyondBound IRB for comprehensive support with your IRB needs, or explore IRB Heart to build the knowledge you need to conduct responsible research with confidence.
References
National Institutes of Health. (2017). NIH policy for issuing Certificates of Confidentiality. U.S. Department of Health and Human Services. https://grants.nih.gov/grants/guide/notice-files/NOT-OD-17-109.html
National Institutes of Health. (2025). Certificates of Confidentiality (CoC): Information for researchers. U.S. Department of Health and Human Services. https://grants.nih.gov/policy-and-compliance/policy-topics/human-subjects/coc
Protection and privacy of identifiable, sensitive information, 42 U.S.C. § 241(d) (2018).
Protection of Human Subjects, 45 C.F.R. § 46 (2018).
Tourangeau, R., & Yan, T. (2007). Sensitive questions in surveys. Psychological Bulletin, 133(5), 859–883. https://doi.org/10.1037/0033-2909.133.5.859
U.S. Department of Health and Human Services. (2003). Summary of the HIPAA Privacy Rule. Office for Civil Rights. https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html

