Safeguards
HIPAA / Data Protection
This page describes the privacy and security posture BBK RPS applies to sensitive recruitment operations.
Last updated: September 15, 2026Protected workflow boundary
BBK RPS treats participant contact and referral information as sensitive operational data and applies safeguards across access, export, communication, and audit workflows.
BBK RPS administrative intake is separate from clinical screening, informed consent for study participation, and enrollment handled by the Research Site.
Minimum necessary
Authorized users should access only the participant information needed for approved recruitment coordination. Server-side authorization and Site or organization scoping must protect every sensitive read and write.
Audit and exports
- Sensitive views, export requests, status updates, contact actions, and operational handoffs should leave audit evidence.
- Ordinary logs and audit metadata should not copy health details, questionnaire answers, phone numbers, email addresses, consent text, or uploaded file contents.
- Recruiter CSV exports are limited and delivered through secure, temporary, authenticated links.
Participant data rights
HIPAA rights around medical records and clinical study documentation are usually handled by the covered entity or Research Site that maintains those records. BBK RPS helps protect administrative recruitment data within its own platform scope.
Incident handling
Suspected unauthorized access, disclosure, or data mismatch should be reported to BBK RPS promptly so the issue can be reviewed, contained, and documented.