Research only

Clinical research sites and contract research organizations

Explore the policy documents and regulatory sources relevant to this industry. Assessment checks for this profile are in development.

Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.

Documents to review

  • Informed consent procedureResearch document type
  • Irb procedureResearch document type
  • Adverse event procedureResearch document type
  • Trial monitoring planResearch document type

Scope questions

Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.

  • Where does the organization operate, and which regulator, license, permit or contract governs the activity?
  • Which business activities, data types and organization roles does the document describe?
  • Do the relevant thresholds or exceptions change which requirements apply?

Unknown answers stay unresolved. Document detection does not answer these questions for you.

A fictional example to explore

This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.

PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.

Regulations and frameworks to explore

These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.

Research only

FDA-regulated clinical research

21 CFR Parts 50, 56, 312, and 812 as applicable

Route by study and organization role: informed consent and IRBs (21 CFR Parts 50/56), investigational drugs (Part 312) and investigational devices (Part 812). A generic clinical-research label does not establish all four regimes; identify sponsor, investigator, IRB and study type first.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Does the clinical investigation involve drugs, biologics or medical devices, and which FDA regime applies?
  • Is an IND, IDE or a defined exemption applicable to this investigation?
  • Are you the sponsor, investigator, sponsor-investigator or another responsible study party?
  • What clinical investigation and participant/IRB protections fall within the applicable FDA rules?
Research only

FDA electronic records and signatures

21 CFR Part 11

Applies to electronic records and signatures within the scope of FDA predicate-rule record requirements and qualifying electronic submissions. It is not a universal rule for every electronic business document. Identify the predicate rule, record/signature use and system before assessing requirements.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Which FDA predicate rule requires these records to be maintained or submitted?
  • Are required records maintained/submitted electronically rather than only paper records or convenience copies?
  • Are electronic signatures used in place of signatures required by the applicable FDA rules?
Research only

HIPAA Security, Privacy, and Breach Notification Rules

45 CFR Parts 160 and 164

Applies to covered entities and business associates handling protected health information. Cloud providers that maintain electronic PHI can be business associates even when data is encrypted and they have no decryption key. Check the actual data/service role and business-associate agreement. A healthcare customer alone does not establish scope. Proposed Security Rule changes must be tracked separately from the currently effective rule.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Are you a HIPAA covered entity, or do you create, receive, maintain or transmit PHI for a covered entity or another business associate?
  • Which protected health information does the service handle, and under whose business-associate agreement?
  • Does your service handle electronic PHI, including encrypted information for which you do not hold the decryption key?
  • What size, complexity, capabilities and risk factors affect implementation of your HIPAA safeguards?
  • For each addressable implementation specification, have you evaluated reasonableness and documented any alternative?