herzingirbthe entire IRB process, handled end to end

the data security plan

Four blanks, and what it takes to fill them.

Both Herzing applications carry the same data security question, in the same words, and it names four things: where the data will be stored, how that location or computer system is secured, how long the data is kept, and how old data is destroyed. It also says "physical and electronic" out loud, which is the half most plans forget. Nothing here is discretionary prose — every clause is a commitment the rest of the folder has to match.

Annika Brandstetter, DNP, APRN · filed 2026-08-23

Name the storage for paper and for files, the protection on each, a retention period, and a destruction method. Then check that the consent paragraph, the personnel list and the three-year undertaking on the same form all say the same thing.

What exactly does Herzing's form ask for?

Herzing puts the identical prompt on the Research Protocol Application and on the Healthcare Improvement or Innovation Project Application: describe the data security plan for both physical and electronic data that includes protected or identifying personal information, and include where the data will be stored, the security of the location or computer system, the length of retention of the data, and the method of disposition of old data.

Two things about that sentence are worth pausing on. First, it is one of the few passages that survived unchanged when Herzing revised these forms — the superseded edition of the improvement application carries the same wording. Where names, aim-statement guidance and even the signature count have shifted between editions, this question has not, which makes it the most stable pocket in the folder and a reasonable place to invest effort.

Second, it is not the only place confidentiality appears. The Research Protocol Application's submission checklist asks separately for attached information describing how a participant's privacy will be maintained and how confidentiality will be guaranteed. That is a document, not a sentence, and it sits alongside the plan rather than inside it. The Methodology box adds a third strand by asking you to identify all personnel involved and outline their qualifications — which is, in practice, your access list.

Underneath all of it sits the finding the board has to make. Among the criteria in 45 CFR 46.111 is that there be adequate provisions to protect participants' privacy and to keep data confidential. A plan is how you show those provisions exist.

How do you fill the four blanks?

Write each one as a fact rather than an intention. "Will be stored securely" is an intention. "Kept in a locked cabinet in room 214, to which the principal investigator and the project faculty hold keys" is a fact, and a reviewer can weigh it.

The blanks Herzing's form names, and what an answer must carry
The blankWhat the sentence has to nameAn answer that fails
Where physical data livesThe building or room, the furniture it is locked in, and who holds the key"Paper records will be kept in a safe place." Whose safe place?
Where electronic data livesThe named system or service, whose account it sits under, and whether any copy leaves it"On my laptop." A device is not a storage plan, and laptops travel
How each is securedLock and access control for the physical; encryption, authentication and account control for the electronic"Password protected." Which password, protecting what, held by whom?
How long the data is keptA stated period with a starting point — and one that does not contradict the consent document"Until the project ends," when the same form commits you to keeping consents for longer
How old data is destroyedThe method, per medium, and who carries it out"Deleted." Dragging a folder to the wastebasket is not destruction

Then read the plan against the consent paragraph promising confidentiality. Those two passages are the same promise addressed to two audiences, and a reviewer who finds them disagreeing has found a real problem rather than a typographical one. The consent documents pocket sets out what that paragraph must say.

Who is allowed to touch the data?

There is no access box on the form, so the answer has to be built out of the personnel line in Methodology and the plan itself. Three habits keep it defensible.

Name roles rather than a crowd. The principal investigator, the project faculty, and a named analyst if one exists — each with what they may reach. A transcription service, a survey platform or a statistician handling raw files belongs on that list too; anyone who processes the data is inside the plan, not outside it.

Separate the key from the lock. If identifiers are replaced with codes, the file linking code to person is the most sensitive object in the project, and it should live somewhere the working dataset does not — a different system, a different access list, its own destruction date.

Treat the roster as a live document. The Research Protocol Application's acknowledgements are explicit that any additions or changes go to the board for written approval before they are implemented, and the Bylaws hold approved work under continuing oversight, re-evaluated at least annually. Adding a colleague to the analysis mid-project is a change to the plan, not an administrative detail.

How de-identified is de-identified?

The word does a great deal of work in applications and rarely means the same thing twice. Three states are worth distinguishing plainly, because the board reads them differently:

  • Identifiable. Names, record numbers or anything that points at a person are present. Everything in the plan applies at full strength.
  • Coded. Direct identifiers are replaced by a code, and a key exists somewhere. The data is not de-identified while that key exists — it is protected. Say where the key lives and when it dies.
  • De-identified. No key, and no reasonable route back to a person. This is a higher bar than removing names.

Where the data comes from a healthcare organisation's records, the HIPAA standard gives that bar a definite shape. One route is a formal expert determination that the risk of re-identification is very small, documented by the person who made it. The other, the safe-harbour route, requires removing an enumerated set of identifier types — among them names, most geography finer than a state, all date elements other than year, ages above eighty-nine, telephone and fax numbers, email addresses, social security numbers, medical record, health-plan and account numbers, licence, vehicle and device identifiers, web and IP addresses, biometrics, and full-face images — with a residual condition that you must not actually know of a way the remainder could still identify someone. A middle option, the limited data set, keeps certain dates and coarse geography and travels only under a data use agreement.

Then there is the problem no regulation lists. A dataset drawn from one small unit can identify people through combinations that look innocent on their own: role, shift, tenure, a single unusual outcome. Before promising anonymity in a consent document, look at the smallest cell your analysis will produce and ask whether a colleague could name the person in it.

Which clocks are running, and do they agree?

Three periods live in a Herzing folder, and plans get returned when they contradict each other rather than when any one of them is wrong.

  1. The data retention you set. Your own figure, written into the form's third blank and repeated in the consent document.
  2. The consent documents you undertake to keep. The Research Protocol Application's acknowledgements commit you to holding all informed consent documents for three years following the completion date of the project.
  3. The board's own record-keeping. Federal rules hold research records for at least three years after the research is finished, which is the university's obligation rather than yours, but it is the reason your file does not vanish when your project does.

A plan that promises to destroy everything the moment data collection ends contradicts the second of those three on the same form you are signing. Say instead what is destroyed when, and what is kept, and where the kept material lives.

What does destruction actually mean?

Per medium, and honestly. Paper is cross-cut shredded, not recycled. Files are removed from the live system and from every copy — which means naming the copies: the sync client on a home machine, the export that went into a statistics package, the attachment sitting in a sent-items folder, the platform's own backups and their retention behaviour, the audio still on a recorder, the photograph of a whiteboard taken on a personal phone. Recordings deserve their own line, because the transcript usually outlives the audio and only one of the two tends to appear in the plan.

Say who performs the destruction and how it is recorded. A plan that names an action, a date and a person is a plan. A plan that names only an intention is a sentence.

What to do next

Take the plan you have and read it against three other things: the confidentiality paragraph in your consent document, the personnel named in your Methodology box, and the retention undertaking further down the application. If all four agree, the pocket is sound. If they do not, that disagreement is what comes back. Start with the free application review and send us whatever is already written. Back comes a written reading of which of the four blanks is unfilled, whether your de-identification claim holds at the smallest cell, and whether the clocks agree. If you would rather hand the pocket over, building it is part of how the practice works, and the application checklist shows what sits beside it. The data stays yours; so does every decision about what happens to it. The board's determination is the board's.

Sources

Herzing revises its IRB forms and pages without notice; where this article and Herzing's current IRB handbook or portal disagree, the current material governs. This practice is independent and is not affiliated with Herzing University.

Hand us the folder as it stands — we carry the whole IRB process from there.

The determination and plan, every document in every pocket, the site letter drafted for the site's signature, the submission itself, and every reply the board sends back until the approval is in your hands. The project, the data and the findings stay yours; the board's decision stays its own. It starts with the free application review — and if the folder is ready to file as it is, we will say exactly that.

Evelyn is at the desk. Which pocket is giving you trouble?