waldenirb

Home · Newsletter

The data security plan in a Walden IRB application: storage, access, de-identification, destruction

The data security plan is the part of a Walden IRB application where a general answer is a wrong answer. The board is not asking whether you intend to be careful; Walden's handbook requires the application to explain how data will be stored and destroyed, audio recordings included — and federal criteria oblige the board to confirm those provisions are adequate. A plan that names the device, the protection, the people who may open it, where identities separate from responses, and when the files cease to exist answers every question in one pass. A plan that says "data will be kept securely" invites the board to ask all five.

Josephine Hale, DNP, APRN · 2026-08-23

Walden's IRB expects the data security plan to name the storage location, the protection on it, the access list, the de-identification step, the retention period after final approval, and the destruction method — for every form the data takes, recordings and transcripts included.

What is the Walden IRB actually reading the data security plan for?

Two texts sit behind the board's questions. The first is federal: Walden's IRB operates under the Federal Policy for the Protection of Human Subjects, 45 CFR 46, and among the criteria the board must satisfy before approving any study is §46.111(a)(7) — that, when appropriate, the study makes "adequate provisions to protect the privacy" of participants and to keep their data confidential. The board cannot find those provisions adequate if the application does not say what they are. The second is Walden's own: the handbook's description of what an ethics submission must contain lists, alongside recruitment and consent, an explanation of how collected data will be stored and destroyed — naming audio recordings specifically, the data most often forgotten.

Read together, they explain the board's posture: it is not auditing your hard drive. It checks that every promise the consent document makes about confidentiality has a mechanism somewhere in the plan — a location, a lock, a list, a date. Where the promise has no mechanism, the reply letter asks for one.

Where may the data live, and what counts as naming the storage?

Naming the storage means the sentence survives a reader who cannot ask follow-up questions. "A password-protected computer" is close but not there; whose computer, protected how, and what happens to the copy the survey platform keeps? A plan the board does not need to query typically states, for each form the data takes:

Whether a particular cloud service, survey tool, or transcription arrangement is acceptable for a given design shifts between terms; Walden's current handbook and IRB portal govern. Describe the tool you will actually use, so the board rules on the real plan, not a placeholder.

Who may open the data — and who is on the access list whether you write them down or not?

The access list is where Walden differs most from the generic advice candidates arrive with. At many institutions "only the researcher will have access" is the safe sentence. At Walden it is inaccurate, because Walden's handbook builds committee oversight into the data itself: a doctoral candidate's raw dataset, final dataset, and analysis process must be electronically available to the committee, the candidate keeps a log of recruitment and every data-management step, and the IRB and committee may review the raw data or the log at any time. The handbook is equally specific about outsiders: beyond university staff, only a committee-approved transcriber may touch the raw dataset, and a transcriber signs a confidentiality agreement with you before hearing a word of a recording. One exclusion is modern: Walden's conduct rules bar entering capstone data or participants' identities into open AI tools, — an AI transcription shortcut is an access-list breach, not a convenience.

The honest access list for a typical capstone reads: you; the committee, electronically; any named transcription arrangement, under its signed confidentiality agreement. Writing that list out does not weaken the file; it shows the board you know who is actually inside the study. It also has to agree with the consent document: if the consent form tells participants that responses are seen only by you, and the plan grants a transcriber access, the file contradicts itself, and the board will say so politely. The same version-matching discipline covered in the consent form requirements applies here sentence by sentence.

What does de-identification mean in this plan — and when does HIPAA enter?

The board reads "anonymous" and "confidential" as different claims, and the plan must know which one it is making. Anonymous means identities were never collected and cannot be reconstructed — a survey with no names, no emails, no link. Confidential means identities exist somewhere and the plan controls them — usually codes, with the key kept separate. A plan that promises anonymity while collecting email addresses for follow-up has made the wrong claim, and the correction ripples through consent and recruitment alike.

When the data begins life as health records, the vocabulary sharpens, because the site holding them answers to HIPAA. The Privacy Rule's Safe Harbor standard at 45 CFR 164.514(b)(2) lists eighteen identifiers that must be gone before health information counts as de-identified — names; geography smaller than a state; dates more specific than the year; contact, record, and account numbers; device and web identifiers; biometrics; full-face images; and any other unique identifying number or code. Two of those trip chart-review plans constantly: dates (a service date is an identifier; the year alone is not) and "any other unique code" (a re-identification code is only permissible if it is not derived from the identifiers and the key is not disclosed — 45 CFR 164.514(c)). A plan for records-based work should say who strips the identifiers, on which side of the transfer, and in which form the data crosses to you; the site's requirements travel with the records — one more reason the letter of cooperation and any data use agreement are drafted against the same plan.

How long is the data kept, and what does destruction actually mean?

Retention is the one number in this plan Walden publishes. The handbook currently requires the dataset to be kept in a confidential, secure manner for five years beyond the university's final (CAO) approval of the completed work, unless the IRB indicates otherwise — the current handbook's wording governs. (The board can approve exceptions through the application — sensitive recordings destroyed right after transcription, for instance.) Two consequences follow. The destruction date is not a calendar date but an event — a fixed period after final approval — and the plan should describe it that way. And "I will delete everything when the study ends" is a sentence the board must return: it contradicts the retention the university itself requires.

Destruction is named per medium: files erased from the named devices and accounts, recordings deleted, paper shredded, the code key with them. The plan reads cleanest when each row of data has all five answers in one place:

One row per form of data — the five answers the board looks for
The data, in the form it takesStored where, protected howWho may open itIdentities handled howKept until, destroyed how
Interview audioEncrypted device under your control; platform copy deleted after downloadYou; committee electronically; approved transcriber under signed confidentiality agreementNames replaced with codes at transcription; key stored separatelyHandbook retention period, then deleted from every device
TranscriptsEncrypted device; backup in one named locationYou; committee electronicallyCoded; no names in the textSame period; files erased
Survey responsesNamed platform account, then exported to encrypted deviceYou; committee electronicallyAnonymous if no identifiers collected — and the consent document says the sameSame period; platform copy and export both deleted
Signed consent recordsStored apart from responsesYouInherently identifiable — kept separate for that reasonSame period; shredded or erased
Extracted record dataReceived de-identified where the design allows; encrypted deviceYou; committee electronicallySite strips identifiers per the agreement; Safe Harbor list where HIPAA appliesSame period; erased; any code key destroyed by its holder

Why do data security plans come back more than they fail?

A weak plan rarely sinks a Walden file; it delays one. The board's reply asks the plan to name what it left general — and each revision pass is a full pass through the correspondence, so specificity withheld the first time is the classic avoidable return. The other classic is contradiction: a specific plan that disagrees with the consent document about who sees the data, or with the recruitment materials about anonymity. The board reads the whole file as one document; the plan must hold up against every promise made on the other pages. That is the discipline behind how we build the file — one version, every claim matching — and why the plan is written alongside the consent document, not after it. For where the plan sits among the rest of the enclosures, see the application checklist, enclosure by enclosure.

What to do next

If your plan still says "data will be stored securely," you already know the letter that sentence earns. Write the five answers for each form your data takes — location, protection, access, identities, destruction — and check each one against your consent document. Or send us what you have: we read the file as the board will, plan included, and the review is free. Write to the desk, or start with the fifteen short answers on the FAQ.

Sources

The reply envelope

the practice
consultants to Walden doctoral candidates
at the ethics step

To: the candidate whose proposal is signed, whose reviewer has concurred — and whose application hasn't gone in yet.

Request the free application review

We read what you have as the board will and tell you where it stands — including, when it is true, “file it as it stands.” Then we carry the whole process: every document, the submission, every reply, until the approval letter. No cost to begin, no obligation.

Fiona Castellan, DNP, APRN Senior IRB consultant online