Requirements on Privacy in Clinical Trials

Been thinking a lot recently of privacy in regard to clinical trials. As you do, I started with gathering some requirements together. Here is what I have:

Brief Standard IdentifierDescription of Industry StandardRegulation/Guidance/ Source
Subject Identification in Data SystemsThe business has SOPs to ensure that data collection instruments and databases utilize an unambiguous subject identification code that allows identification and linkage of all the data reported for each subject. Data tools and systems do not contain personally identifiable information, except the unique subject identification code to link data across the study.GCDMP – Data Privacy; ICH 5.5.5
Patient Diaries ReviewThe business has and utilizes SOPs to ensure that the Investigator site personnel review paper-based patient diaries prior to sending the diaries to Data Management to confirm that no personal identification information is present.MHRA 8.2.7
Confidentiality of Subject RecordsThe business utilizes formal procedures and practices to ensure that the confidentiality of records that could identify subjects is protected in accordance with the applicable regulatory requirement(s).ICH 2.11
Informed Consent Prior to Data CollectionThe business has a process to establish expectations with the site and confirm that informed consent is obtained from every subject prior to clinical trial participation and prior to processing clinical data. The process should provide direction for withdrawal and revocation of consents.ICH 2.9, 4.8.8, 6.5.3 21 CFR 50
Privacy and Personal Data Protection PolicyThe business has a Privacy and Personal Data Protection Policy and a Chief Privacy Officer/ Data Protection Officer to ensure compliance with EU GDPR and other country, local, and Independent Ethics Committee-required privacy, and data protection practices.US HIPAA EU 1995 Data Protection Directive 1995/45/EC EU GDPR 2016/679 Japan 2016 Act on the Protection of Personal Information- US Privacy Act
Privacy and Personal Data Protection Documented PracticesThe business has documented procedures, standards, documentation requirements, and responsibilities for defining and ensuring confidentiality, protection, and security of personal data (including but not limited to employee, client, investigator, and patient data) and applying Privacy by Design requirements into procedures that include: definitions of personally-identifying information descriptions of personal information collected the purposes for which it is collected the lawful basis (in the EU) for its collection/use the types of persons to whom it will be released the countries to which it may be transferred privacy and security safeguards the rights of individuals with respect to their personal information compliance monitoringUS HIPAA EU Data Protection Directive 1995/45/EC EU GDPR 2016/679 Japan’s Law Concerning the Protection of Personal Information – 2005; Japan Act on the Protection of Personal Information- 2016
 The business has documented procedures, standards, documentation requirements, and responsibilities for conducting Privacy Impact Assessments, including when they are implemented, or documentation regarding why they are not applicable.EU Data Protection Directive 1995/45/EC EU GDPR 2016/679
Personal Data Processing, De-identification and PseudonymizationThe business has documented procedures, standards, documentation requirements, and responsibilities for enhancing privacy and protecting personal data, both at the time of determining the means for processing data and at the time of actual processing, by adherence to the data minimization principle (i.e., ensuring that only data needed for a clinical trial are collected from clinical trial subjects’ records), encryption at rest and during transit, de-identification and pseudonymization.   Where pseudonymization is deployed, the business has appropriate technical (e.g., encryption, hashing, or tokenization) and organizational (e.g., agreements, policies, privacy by design) measures in place to separate pseudonymous data from identification keys.EU GDPR 2016/679
Personal Data Capture and Data Flow ProceduresThe business has written procedures for documenting the data flow for the organization/for individual projects. The data flow comprises what personal data the organization holds, where it came from, and with whom they share it.EU Data Protection Directive 1995/45/EC EU GDPR 2016/679
Individual Privacy Notice or ConsentEnsuring that individuals are informed of all required privacy provisions in Privacy Notice or Consent, including: their right to confirm if and how their data are processed, including the right to object to (or limit use of) processing and the right of erasure; plans for data retention; the right to receive a copy of their personal data and to have them transmitted to other organizations; and the complaint process.US HIPAA EU Data Protection Directive 1995/45/EC EU GDPR 2016/679
Support for Personal Data Subject RequestsReceiving, processing, and responding to Personal Data Subject Requests submitted by Data Subjects per their rights under GDPR, and/or assisting the Client to fulfill Client’s obligation to do so: right of access right to rectification restriction of processing erasure (“right to be forgotten”)data portability objection to the processing, or the right not to be subject to automated individual decision makingEU GDPR 2016/679 Directive 1995/45/EC
Privacy and Personal Data Breach ProceduresDetecting, reporting, and investigating personal data breaches, and communicating confirmed data breaches to impacted parties within timelines dictated by applicable regulations (72 hours for regulatory authority reporting) and agreements. Sponsor will be notified of any data breach in association with sponsor projects, including breaches at subcontracted vendors, according to pre-defined timing.EU Data Protection Directive 1995/45/EC EU GDPR 2016/679
Privacy and Personal Data Protection TrainingThe business trains all individuals who have access to personal data on the policy and practices that ensure confidentiality, protection, and security of personal data.EU Data Protection Directive 1995/45/EC EU GDPR 2016/679

International Worker’s Day

Sunday is May 1st, International Worker’s Day. Last year I wrote “Drive Out Fear on International Workers Day“, which is definitely as true today as when I wrote it.

May 1st is International Worker’s Day

This weekend I’m snuggling up with Breaking Things at Work by Gavin Miller, and hope to have a review for Sunday, as well as some thoughts on just why the Luddites were right about why folks hate their jobs, and if there are lessons to learn in this new phase we are entering into of virtual and hybrid work.

Here’s a great interview with Gavin Miller from On The Media

“Lessons from the Luddites” from On the Media (10Dec2021)

Impact of Virtual Communication on Creativity

A very interesting study in Nature this week on “Virtual communication curbs creative idea generation.” And while I don’t think the results will surprise many, I do think we are not close to settling the question. This is a fairly good-sized study, with a good methodology, but I think more research is needed in the area. I’m thinking we will see a few more studies around the topic.

The results suggest that there is a unique cognitive advantage to in-person collaboration, but the authors do acknowledge there are a whole lot of other factors in play.

This is the big question for many. How do we get the benefits of in-person while maintaining the flexibility and benefits folks are used to. I think, for those work environments where virtual work is possible, the answer is going to be to structure times to maximize the tangible benefits of office-based work, including:

  • “Serendipitous collaboration,” a term coined by Dana Sitar in Inc. to describe informal interactions that result in innovative ideas, problem-solving, and new approaches. For me this includes plopping in a coworker’s office for a quick problem-solving session (maybe with a little healthy venting on the side). Speedy, efficient interactions that simply don’t happen in a remote environment — and that build a sense of camaraderie and teamwork.
  • More productive meetings. Even though we’re becoming more skillful at remote meetings, there are just certain meetings that benefit from in-person..
  • Connection and loyalty are difficult to promote in employees working remotely. The sense of team is not the same when team members see each other online as opposed to seeing them and speaking with them multiple times a day.
  • High-functioning teams have outstanding communication and shared experiences — both of which are difficult to manufacture long distance. Creating a relaxed, and informal environment, diffusing tension, and engaging in an extensive discussion where every team member is heard are all much easier to do in person than virtually.

Businesses operate thanks to human ideas and energy. People are the power behind every business; successful businesses find that fulfilled, happy employees drive fresh ideas, work harder to accomplish goals, and remain loyal to their employers.

The human element (and the need for and value of human connection) can’t be overstated as an ingredient for success and growth. I think we’re entering a new phase, and there are a lot of questions to be answered. What I hope is that bad decisions won’t become enshrined because of cost-cutting or just organization laziness. That approach already gave us horrible open offices.

Defining Values, with Speaking Out as an example

Which espoused values and desired behaviors will best enable an organization to live its quality purpose? There’s been a lot of writing and thought on this, and for this post, I am going to start with ISO 10018-2020 “Quality management — Guidance for people engagement” and develop an example of a value to build in your organization.

ISO 10018-2020 gives 6 areas:

  • Context of the organization and quality culture
  • Leadership
  • Planning and Strategy
  • Knowledge and Awareness
  • Competence
  • Improvement

This list is pretty well aligned to other models, including the Malcolm Baldrige Excellence Framework (NIST), EFQM Excellence Model, SIQ Model for Performance Excellence, and such tools as the PDA Culture of Quality Assessment.

A concept that we find in ISO 10018-2020 (and everywhere else) is the handling of errors, mistakes, everyday problems and ‘niggles’, near misses, critical incidents, and failures; to ensure they are reported and recorded honestly and transparently. That the time is taken for these to be discussed openly and candidly, viewed as opportunities for learning how to prevent their recurrence by improving systems but also as potentially protective of potentially larger and more consequential failures or errors. The team takes the time and effort to engage in ‘second order’ problem-solving. ‘First order’ problem solving is the quick fixing of issues as they appear so as to stop them disrupting normal workflow. ‘Second order’ problem solving involves identifying the root causes of problems and taking action to address these rather than their signs and symptoms. The team takes ownership of mistakes instead of blaming, accusing, or scapegoating individual team members. The team proactively seeks to identify errors and problems it may have missed in its processes or outputs by seeking feedback and asking for help from external stakeholders, e.g. colleagues in other teams, and customers, and also by engaging in frequent experimentation and testing.

We can tackle this in two ways. The first is to define all the points above as a value. The second would be to look at themes for this and the other aspects of robust quality culture and come up with a set of standard values, for example:

  • Accountable
  • Ownership
  • Action Orientated
  • Speak up

Don’t be afraid to take a couple of approaches to get values that really sing in your organization.

Values can be easily written in the following format:

  1. Value: A one or two-word title for each value
  2. Definition: A two or three sentence description that clearly states what this value means in your organization
  3. Desired Behaviors: “I statement” behaviors that simply state activities. The behaviors we choose reinforce the values’ definitions by describing exactly how you want members of the organization to interact.
    • Is this observable behavior? Can we assess someone’s demonstration of this behavior by watching and/or listening to their interactions? By seeing results?
    • Is this behavior measurable? Can we reliably “score” this behavior? Can we rank how individual models or demonstrates this behavior?

For the rest of this post, I am going to focus on how you would write a value statement for Speak Up.

First, ask two questions:

  • Specific to your organization’s work environment, how would you define “Speak Up.”
  • What phrase or sentences describe what you mean by “Speak Up.”

Then broaden by considering how fellow leaders and team members would act to demonstrate “Speak Up”, as you defined it.

  • How would leaders and team members act so that, when you observe them, you would see a demonstration of Speaking Up? Note three or four behaviors that would clearly demonstrate your definition.

Next, answer these questions exclusively from your team member’s perspective:

  • How would employees define Speaking Out?
  • How would their definition differ from yours? Why?
  • What behaviors would employees feel they must model to demonstrate Speaking Out properly?
  • How would their modeled behaviors differ from yours? Why?

This process allows us to create common alignment based on a shared purpose.

By going through this process we may end up with a Value that looks like this:

  1. Value: Speaking Out
  2. Definition: Problems are reported and recorded honestly and transparently. Employees are not afraid to speak up, identify quality issues, or challenge the status quo for improved quality; they believe management will act on their suggestions. 
  3. Desired Behaviors:
    • I hold myself accountable for raising problems and issues to my team promptly.
    • I attack process and problems, not people.
    • I work to anticipate and fend off the possibility of failures occurring.
    • I approach admissions of errors and lack of knowledge/skill with support.