capellairb Book a review

Home · Articles

The data security plan in a Capella IRB application: naming storage, access, de-identification and destruction

The board is not asking whether your data will be safe. It is asking where each copy will sit, who can open it, what separates a name from an answer, how long Capella requires you to keep it, and on what date it is destroyed. A plan that says "data will be stored securely on a password-protected computer" has answered none of those. The plans that pass read like an inventory: every form of the data, from recording to transcript to code list to findings, with a location, a holder and an end.

Harriet Crowley, PhD · 2026-08-23

Name storage for every form of data, who can access it, the step that separates identifiers from responses and where the key lives, the retention period Capella requires, and the destruction method and date. Then make the consent form and application say the same.

What is the board actually asking when it asks about data security?

The regulatory question is 45 CFR 46.111(a)(7): the IRB must find that "there are adequate provisions to protect the privacy of subjects and to maintain the confidentiality of data." Capella's Research Integrity SOPs translate that into the board's working test. The IRB must ensure that recruitment, screening, enrolment and data collection protect privacy and confidentiality "and that plans are in place to manage, store, and destroy the data once it has been collected." The same section tells you not to collect identifying information unless it is essential to the design, and not to disclose identifying information about participants or research sites in the report of findings.

So the plan is a description of custody. It follows the data through its life: the moment it is created (a recording, a survey response, a chart extract), every place it is copied or transformed (a transcript, a spreadsheet, a coded file, a pseudonymised quote in a chapter), every person who touches it, and the day it ceases to exist. Capella's application prompts for parts of this in more than one place, and Capella's current IRB portal governs the exact fields; what the board reads for is the same regardless of where the boxes sit.

What must the plan name?

The plans that do not come back name seven things, each concretely enough that a reviewer could check it.

  1. Storage, per form of data. The device or service for recordings, for transcripts, for raw survey exports, for the analysis file, and for paper (signed consent forms, field notes). "My laptop" is not a location; "an encrypted folder on a single password-protected laptop used only by me, backed up to one named cloud account protected by two-factor authentication" is.
  2. Access, by name or role. Who can open each store: you, your mentor if the design requires it, a transcriptionist, a second coder. Capella provides a confidentiality agreement template on its iGuide for research assistants, and anyone outside the named researcher who handles identifiable data should sign it and the signed agreement should be in the file.
  3. What identifiers you collect, and why each is essential. Names and emails for scheduling, a signature on the consent form, a voice on a recording, a face on a video. If an identifier is not needed, the plan says you will not collect it; if it is, the plan says what it is for and when it is removed.
  4. The de-identification step and the key. When the code replaces the name (at transcription, at export), where the code list that links code to person is kept, and that it is kept separately from the data with access limited to you. The plan says whether the study is confidential or anonymous in Capella's definitions: confidential means only you can link responses to people; anonymous means no identifiers are collected and you could not link them if you tried. Mixing those words is a common return.
  5. Transmission and third parties. The video platform used for interviews, the survey tool, the transcription service, and email. Capella's guidance asks that the current privacy link for any conferencing platform appear in the consent form's confidentiality section, and any platform's terms should not contradict your promises. If a site will only release records under a data-use agreement, the SOPs require that agreement to go through the IRB Office for Capella's legal review, because some data-handling terms Capella cannot sign.
  6. Retention. Capella's Policy 3.03.01 requires researchers to "maintain all research materials for seven years after completion of a study," and the SOPs repeat the minimum. Research materials, in the policy's own list, include signed consent forms, digital and paper surveys, audio recordings, transcripts, data files and all communications with participants.
  7. Destruction, by method and trigger. How each form is destroyed (recordings deleted and the deletion verified, paper shredded, cloud copies purged) and what starts the clock. Also what happens earlier to identifiable material that no longer has a purpose, such as deleting recordings once transcripts are verified, if that is your design.

How does de-identification actually work in a doctoral study?

Most Capella studies are small, and small is the difficulty. Removing a name does not de-identify an interview with the only night-shift charge nurse on a named unit. Two references help. The HIPAA Privacy Rule's safe-harbour list at 45 CFR 164.514(b)(2) enumerates the eighteen identifiers that must go for health information to count as de-identified (names, geographic units smaller than a state, all date elements except year, phone and fax numbers, email addresses, record and account numbers, device identifiers, web addresses, IP addresses, biometrics, full-face photographs, and "any other unique identifying number, characteristic, or code"), and it also requires that you have no actual knowledge that what remains could identify someone. The same rule at 164.514(c) sets the standard for a re-identification code: it may not be derived from information about the person, and the mechanism for re-identification is not disclosed. A participant's initials, or their birth month, is not a code.

Whether or not your data are health information, that list is the checklist the board will recognise. The second reference is Capella's own rule that neither participants nor sites are identified in the findings. In practice that means pseudonyms for people and for organisations, roles described at a level that does not single anyone out, and quotes checked for the detail that would name the speaker to a colleague. The plan states that this will be done and who will do it. Where the data are identifiable clinical records, the plan also says whether you receive them de-identified from the site's own staff or de-identify them yourself, and where that happens.

Who else touches the data, and what does the plan say about them?

Every additional pair of hands is a line in the plan. Transcriptionists receive recordings, which are identifiable by voice and content; a signed confidentiality agreement, transfer by a named secure method and deletion on their side on a stated trigger are what the board expects to read. Mentors and committee members typically see de-identified material only, and the plan says so. Second coders see coded transcripts. Survey platforms and conferencing services are third parties with their own retention, and the plan says which you use and what their settings are (recording to the local device rather than to the vendor's cloud, for example). None of this is exotic; it is simply written down, which is the difference between a plan and an assurance.

What does the plan have to agree with?

The data security plan is quoted, in participant language, in the consent form. 45 CFR 46.116(b)(5) requires the consent to describe the extent to which confidentiality will be maintained, and Capella's template gives that its own section. Every promise in that section is a fact in the plan, and they must be the same fact.

Statements that must match between the data security plan and the rest of the file
Plan statesMust agree withUsual mismatch
Interviews are audio-recorded on a named deviceConsent form; research plan; recruitment scriptConsent never mentions recording
Recordings deleted after transcripts are verifiedConsent form's confidentiality sectionConsent promises deletion "at the end of the study"
Records kept for the period Capella requires, then destroyedConsent form; applicationConsent quotes a different period or none
Only the researcher can link codes to namesConsent form ("confidential" wording); access listConsent says "anonymous" for an interview study
Transcriptionist under a signed confidentiality agreementAccess list; uploaded agreementThird party named in plan, absent from consent and file
Site receives no identifiable resultsSite permission letter; consent formLetter implies the site will see who participated
Data from withdrawn participants are destroyed or retainedConsent form's withdrawal statementThe two documents answer differently

The consent form requirements article walks the rest of that matching exercise, and the site permission letter article covers what the letter should say about records and identifiers.

What gets the plan returned?

Thinness, almost always. On this site's route, the fifth most common return is "data security answered too thin": where identifiers live, who holds the key and when it is all destroyed, answered in one sentence. The fix is never more adjectives; it is the inventory above. A second pattern is contradiction, the consent promising anonymity the design cannot deliver, or the plan naming a cloud service the consent never mentions. A third is silence about a third party or a platform the methods chapter clearly uses. Each of these is visible before filing, and each is a file problem rather than a research problem. The how-it-works page shows where the plan is built inside the whole process; in practice we draft it from the research plan, then rewrite the consent's confidentiality section from the plan rather than the other way round, so the two can only agree. The data, the study and the findings remain yours; the board's decision is its own.

What to do next

If your plan currently fits in a sentence, or your consent form makes a promise the plan does not spell out, that is the file problem to fix before it is filed. Request the free application review and send the plan, the consent and the methods section; a consultant will tell you which of the seven items is missing or contradicted and what the reviewer would write. If the plan is complete, you will hear that, and nothing is filed until you say so. The FAQ covers what the review does and does not include.

Sources

Capella's application fields and portal guidance change; where this article and Capella's current handbook or IRB portal differ, the portal governs. This practice is independent of Capella University.

Bring your application before the board sees it.

A consultation costs you nothing and reads your file the way a reviewer will — where it stands on the route, what it's missing, and what would come back. Then, if you want, we take the entire process from there — every document, the submission, every reply — until approval.

Book the free review

Independent consultants · every week, Capella files · your research stays yours

Dana Whitlock, MSN, RN Application desk online