Client and Data Confidentiality
Data-Driven staff and contractors who work with PHI have undergone training and are certified in the Office for Human Research Protections' Human Research Protection Foundational Training.
Data-Driven work is conducted in a password-protected Cloud storage environment with 256-bit encryption for files at rest and SSL/TLS protocols for files in transit. Core security includes Two-Factor Authentication (2FA), application-level controls, and enterprise-grade permissions to prevent unauthorized access.
Wherever possible Data-Driven works with data that has no personal identifiable information (PII). In situations where PII are necessary for the conduct of a project (e.g., reaching out to participants for a survey or interview), Data-Driven replaces PII with a random code in all files containing health and other confidential participant information and holds the key in a separate password-protected file in secure Cloud storage.
All Data-Driven staff and contractors have Non-Disclosure Agreements (NDA's) on file for the protection of clients. Data-Driven is available to sign custom NDAs that address specific client needs.
