We work with your IRB or IT Organization


Audited: The UCSF IT Security Team has audited our data center and has done a through technical walk-through to ensure that Protected Health Information (PHI) is stored securely. We have documentation that can be shared with your IT organization or Institutional Review Board (IRB) about our security architecture.

HIPAA Requirements and Security

Clinical Research Security Profile

Each Institution and Project may have varying security profile requirements. Using QuesGen, the Security Profile can be modified to support your Institution's needs.

Every data modification is tracked for every database, and for HIPAA compliance, data views can also be logged. Users can trace the history of a data element from its inception to the current value in all cases. All deletions are also logged so that data tampering is not possible

PHI Elements Automatically Identified

' PHI Elements automatically identified

At QuesGen, patient data security is of the utmost importance. We have developed our tools to allow maximum flexibility to run your study while ensuring that Protected Health Information (PHI) is never compromised.

Most systems that you would consider for managing your data would have a mechanism for granting or revoking the ability to see PHI to users. Using QuesGen, the system will apply an algorthm to each data element to determine if it should be considered PHI. Once the system makes its determination, the default values can be overridden for any elements that were incorrectly identified. This can save hours in the system setup.