Appendix D — Data Governance Policy

Status: Authoritative · Owner: PI + Data Stewards · Review: Annually (and whenever a DUA/IRB changes)

D.1 1. Principle

Access is a privilege tied to training, approval, and need. We collect the minimum, protect it rigorously, and honor every agreement that permits our use.

D.2 2. Authorization (required before any data access)

  • Current CITI training appropriate to role.
  • Named on the approved IRB protocol for the project (human-subjects data).
  • IRB-of-record confirmed per project (placeholder — varies by institution/partnership).
  • Relevant Data Use Agreement (DUA) reviewed and understood.

D.3 3. Dataset-specific rules

Each dataset (PR DoH/ASES claims & pharmacy; BioLINCC; BioData Catalyst; All of Us; MESA; Framingham; AsthmaNet; NHANES; surveillance data) carries its own DUA, access tier, analysis-environment requirement, and citation/acknowledgment text. The Data Steward owns compliance and completes the Data-Use & Access Checklist with each analyst.

D.4 4. De-identification & HIPAA-adjacent handling

  • Never attempt re-identification of any individual.
  • Apply de-identification standards; respect small-cell suppression, especially in equity-stratified analyses.
  • Treat claims/pharmacy/clinical data with PHI-level caution even when technically outside HIPAA.

D.5 5. Access control & secure storage

  • Least privilege access.
  • No restricted/identifiable data in chat, email, personal devices/drives, or public repos.
  • Controlled-tier analysis stays inside the approved environment; no egress unless explicitly permitted.
  • No secrets in code (env vars + .gitignore).
  • Encryption/backups per institutional policy.

D.6 6. Privacy of people

  • No photos/videos of research participants — ever.
  • Group-member imagery requires consent before capture; public posting requires PI approval.
  • Protect community-partner and participant privacy in all outputs.

D.7 7. Responsible conduct

  • No fabrication, falsification, or plagiarism.
  • Reproducible documentation of analyses.
  • COI disclosure per institutional policy.
  • Compliance with sponsor and dataset publication/sharing terms.

D.8 8. Incident response

On any suspected breach, access error, consent problem, or integrity concern: stop, notify the PI and Data Steward immediately, and document factually. Report-early, no-blame. Hiding a problem is the only unrecoverable error.