capellairb Book a review

Home · Articles

Retrospective chart reviews and existing data at Capella: when it's human-subjects research and what the IRB needs

A retrospective chart review is human-subjects research the moment you obtain, use, or analyze identifiable private information about living people, and a medical record is the textbook example of private information. At Capella the question of whether it "counts" is never yours to settle alone: every doctoral project goes through the IRB, and an existing-data project goes through on the Records Based Research Application. What decides the shape of the file is who holds the identifiers, whether the records come from a HIPAA covered entity, and whether the organisation that owns the data wants a data-use agreement that only Capella can sign.

Elise Marchetti, DNP, APRN · 2026-08-23

Existing data is still human-subjects research if you can readily identify the people in it. Capella reviews every doctoral project either way. Your file must show who strips identifiers, what HIPAA path the source uses, and who signs any data-use agreement.

Is a retrospective chart review "human-subjects research" at all?

The federal definition turns on identifiability, not on whether you ever meet a patient. Under 45 CFR 46.102(e)(1), a human subject is a living individual about whom an investigator "obtains, uses, studies, analyzes, or generates identifiable private information." Private information expressly includes information "provided for specific purposes by an individual and that the individual can reasonably expect will not be made public (e.g., a medical record)." Capella's own Human Research Protections policy (3.03.01) carries the same definitions and adds the institutional rule: IRB approval is required before any research-related interaction with participants and/or their data.

So the honest determination runs in two steps. First: are you obtaining identifiable private information? If you, the researcher, open the chart and can read the name or medical record number, yes. If someone else pulls the records and hands you a dataset with no identifiers and no way back to them, the federal answer may be that the work does not involve human subjects at all. OHRP's guidance on coded private information says research with coded data is not human-subjects research when the data were not collected for your project and you cannot readily ascertain identity, for example because "the investigators and the holder of the key enter into an agreement prohibiting the release of the key to the investigators under any circumstances." The same guidance recommends that investigators "not be given the authority to make an independent determination" about this; the institution decides.

Second: at Capella, that decision sits with the board. The Research Integrity SOPs require every doctoral project to obtain IRB approval or a determination of Not Human Subjects Research, and the NHSR determination is made by an IRB specialist after an administrative review that still checks site permission. A chart review never skips the IRB; it takes a shorter path through it. The review paths themselves are described in our guide to exempt, expedited and full-board review at Capella.

Identifiable, coded, or de-identified — which one is your dataset really?

This is the question the board will answer from your application whether or not you answer it clearly, so answer it clearly. The four situations below behave differently under the Common Rule and under HIPAA, and a file that claims one while describing another is a file that comes back.

Your situationCommon Rule readingHIPAA reading (if the source is a covered entity)What the board will ask
You open identifiable charts yourself, then record data under a code you assignHuman-subjects research. OHRP notes that recording identifiable data "in a coded manner" still enables identification through the code, so the secondary-research exemption does not apply on its ownProtected health information; needs authorization, an IRB or privacy board waiver, or a limited data set under a data-use agreementWhy you need identifiers at all; how long the key exists; who else can see it; when it is destroyed
A site employee (an "honest broker") abstracts the data and gives you a coded file; the key stays with the site under a written agreementMay not be human-subjects research under OHRP's coded-information guidance; Capella's IRB makes that determination, not youStill PHI if it keeps dates or other HIPAA identifiers; a limited data set needs a data-use agreementThe agreement text; the broker's role; confirmation you will never receive or reconstruct the key
You receive a dataset with all eighteen HIPAA identifiers removed (safe harbor)Not identifiable private information; at Capella still submitted, typically toward NHSR or exempt under 46.104(d)(4)(ii)De-identified; outside the Privacy RuleWho de-identified it and how; that no dates, record numbers or free-text notes survived
Publicly available identifiable dataExempt under 46.104(d)(4)(i)Usually not PHI; depends on the sourceProof of public availability; the terms of use

One distinction trips more files than any other. HIPAA's safe-harbor list is specific: names, geographic units smaller than a state, all elements of dates except year, record and account numbers, and "any other unique identifying number, characteristic, or code," among others. A spreadsheet that keeps admission dates and a unit name is not de-identified under HIPAA even if every name is gone. Call it what it is, a limited data set, and plan for the agreement that comes with it.

What does HIPAA add when the records come from a covered entity?

Capella's SOPs put it plainly: researchers working with protected health information from other institutions that are covered entities must comply with the Privacy Rule and the Security Rule, and must obtain appropriate consent if accessing identifiable PHI. The Privacy Rule gives a hospital or clinic a short list of lawful ways to let a researcher use its records:

  1. Authorization from each patient, which is rarely practical for a retrospective review.
  2. A waiver of authorization approved by an IRB or privacy board. Under 45 CFR 164.512(i), the waiving board must find, among other things, "an adequate plan to protect the identifiers from improper use and disclosure," "an adequate plan to destroy the identifiers at the earliest opportunity," and that the research "could not practicably be conducted without the waiver." In most chart reviews it is the site's own IRB or privacy board that grants this; describe in your Capella application which board granted it and attach the letter.
  3. A limited data set under a data-use agreement, 45 CFR 164.514(e). Direct identifiers are removed, dates and limited geography may stay, and the recipient signs an agreement not to re-identify or contact anyone and to report any unauthorised use.
  4. De-identified data under safe harbor or expert determination, which takes the data outside the Privacy Rule entirely.
  5. Review preparatory to research, which lets you look at records to design the study and count eligible charts, provided no PHI leaves the covered entity. This is how a feasibility count is done lawfully before the project exists; it is not a licence to start collecting.

The board at Capella does not administer HIPAA for the hospital; it asks whether your plan is coherent. A file that says "de-identified" in one paragraph and "we will link to readmissions by MRN" in the next has described two different studies.

Who signs the data-use agreement, and why you must start there

This is where chart-review files stall, and it is entirely foreseeable. Capella's policy is explicit: researchers, mentors, faculty and staff "cannot sign a research-related contract or agreement on behalf of Capella University." Any agreement naming Capella as a party, or asking a mentor or chair to accept conditions, must go to the IRB Office, which coordinates review by Capella's legal department. The SOPs add that some data-use agreements Capella cannot sign because of their data-handling terms, and that an agreement requiring only your signature still has to be given to the IRB as part of the application, signed or not, because the board will not approve a study whose agreement contains terms contrary to Capella's policies or that put participants at risk.

So ask the data owner early what paperwork they require, and read the draft for who it names. If it names Capella, route it through the IRB Office before you rely on it, because the legal review runs on its own track and may end in a refusal to sign. If the template is researcher-only, have the board read it before submission. We draft and carry these agreements as part of the file; what nobody can do is sign for the university.

Which Capella form, and what the file has to carry

Capella's IRBManager instructions are unambiguous: choose the New Records Based Research Application only if "all of the data you will be analysing for your study has been collected by others." If you will collect anything new, even a short survey alongside the chart data, you must use the standard application, and Capella warns that choosing the wrong one delays approval. A records-based file that will clear screening carries:

  1. The SMR-approved research plan, uploaded before any study questions are answered, with variables, date range and sample that the application then quotes exactly.
  2. The data abstraction tool or variable list, every field named, and a statement of which fields are identifiers and when they are removed.
  3. A site permission letter on letterhead, signed by an authorised official, that names the records and the activity it permits. "May conduct research here" is not permission to pull charts; the letter must say the data, as our site-permission-letter article explains in detail.
  4. Any site IRB or privacy board letter, including the HIPAA waiver if one was granted, and any data-use agreement, with the Capella legal-review status stated.
  5. A data-security plan that names storage, the access list, the de-identification step, who holds any key, and the destruction date for identifiers and for the dataset.
  6. Current CITI certificates.

What makes records-based files come back?

Almost never the science. The returns we see are file problems: the variable list grew after Scientific Merit Review and no longer matches the stamped plan; a dataset described as de-identified still contains encounter dates; the site letter authorises "a quality project" and never mentions records; the honest-broker arrangement is implied but no one is named; the data-use agreement is attached unsigned with no note that legal review was requested; the destruction plan covers the spreadsheet but not the key. Each is visible before submission, which is the whole argument for reading the file the way the board will. How we handle the whole process, from determination to approval letter, describes that reading.

What to do next

If your project uses existing records, the determination has to be honest before a document is drafted: identifiable or not, HIPAA path, agreement and signatory. Send us where the project stands and a consultant will read it the way Capella's board will and write back with what the file needs. The research stays yours; the board's decision is its own. Request the free application review, or read the questions we are asked most about the Capella IRB.

Sources

Bring your application before the board sees it.

A consultation costs you nothing and reads your file the way a reviewer will — where it stands on the route, what it's missing, and what would come back. Then, if you want, we take the entire process from there — every document, the submission, every reply — until approval.

Book the free review

Independent consultants · every week, Capella files · your research stays yours

Dana Whitlock, MSN, RN Application desk online