Skip to content

Pennsieve Data Access Rules

Shared with the CNT

This procedure runs on infrastructure the lab and the CNT operate together. The CNT manual keeps its own copy; changes to the shared steps are agreed with the CNT.

What this page tells you

If a patient consented to data sharing, data can go on Pennsieve Discover with keys kept. If not (e.g., RADAR), use controlled access with a data request form, fully anonymize and destroy keys, or contact the IRB when more than PIs/PMs need the key.

Before patient data goes on Pennsieve, determine whether the patient consented to sharing their data.

If yes:

  • The data can go on Pennsieve Discover.
  • Keep the keys to link the data with metadata.

If no:

  • There are three ways to handle patient data on Pennsieve when the patient did not consent to sharing their data (for example, the RADAR study):
    1. Controlled access
      1. Have those who want to access the data submit a data request form for the specific dataset.
      2. The keys are restricted to a few members of the lab.
    2. Fully anonymized
      1. Once on Pennsieve, the data has to be fully anonymized.
      2. The keys must be destroyed, and the metadata cannot be linked back to patients.
    3. IRB
      1. If more than the PIs and project managers need the key to a dataset (students and others), contact the IRB.

For reference, the flowchart is shown below:
Flowchart of patient consent to data sharing path