03 · What You Need to Know
The Decision Should Follow Risk, Not the Word "Breach"
Some breaches can be contained without interrupting the study
Suppose a researcher accidentally sends one pseudonymized file to the wrong internal recipient. The recipient immediately reports the mistake, confirms deletion, no identifiers were involved, the transfer system itself remains secure, and the incident does not affect ongoing data collection.
The organization may still need to document and assess the breach, but stopping recruitment or suspending unrelated study procedures may add little protection.
The existence of a breach therefore does not mechanically produce a study suspension.
Other breaches reveal a continuing risk to new participants
Now suppose every new survey response is automatically stored in a publicly accessible folder because of a configuration error. Fixing yesterday's exposure does not protect tomorrow's participants unless the underlying configuration is corrected.
Continuing data collection would knowingly add new personal data to an environment whose safety is uncertain.
In that situation, temporarily pausing the affected collection process may be an appropriate containment measure while the vulnerability is corrected, validated, and reviewed.
The key question is whether the activity can continue within the approved risk profile
Research ethics depends partly on whether participant risks remain reasonable and adequately controlled.
OHRP guidance on unanticipated problems explains that an incident may require corrective action where it suggests that research places participants or others at greater risk than previously known or recognized. Possible corrective actions include protocol changes, additional monitoring, suspension of enrollment of new participants, suspension of research procedures in currently enrolled participants, and revisions to informed consent.
The important concept is not that every confidentiality breach requires suspension. It is that newly recognized risk can require changes to research activity when existing protections are no longer adequate.
Research ethics committees can have authority to suspend research
Under U.S. HHS human-subject protections, an IRB has authority to suspend or terminate approval of research that is not being conducted in accordance with IRB requirements or that has been associated with unexpected serious harm to participants.
The 2024 Declaration of Helsinki similarly states that research ethics committees must have authority to monitor research, recommend changes, withdraw approval, and suspend ongoing research.
These frameworks apply to particular research contexts and should not be generalized into a universal legal rule for every study. They do illustrate an important ethical principle: continuing approval depends on continued acceptability of participant protections.
A "pause" does not have to mean shutting down everything
Research studies contain multiple activities. Recruitment, consent, intervention delivery, surveys, interviews, record extraction, laboratory processing, data entry, analysis, data transfer, and follow-up may use different systems and create different risks.
A breach affecting one component may justify pausing only that component.
| Problem |
Possible targeted pause |
Activity that might continue |
| Online survey is exposing new responses |
Pause new survey collection and recruitment into that workflow |
Analysis of already secured data may continue if authorized |
| External collaborator's access account is compromised |
Suspend that collaborator's access and transfers |
Local study procedures may continue if unaffected |
| Participant contact database is exposed |
Pause activities requiring the compromised contact system |
Unrelated laboratory or analytical work may continue where safe |
| Ransomware affects the primary research environment |
Pause processing through affected systems |
Only activities confirmed independent and safe should continue |
A targeted pause can protect participants without unnecessarily disrupting scientifically and ethically unaffected work.
Recruitment deserves particular attention
Recruiting new participants while an unresolved breach continues can enlarge the number of people exposed to the same risk.
Ask whether new participants would enter the compromised system, whether the consent information still accurately describes confidentiality protections, and whether the newly discovered risk would reasonably affect someone's decision to participate.
OHRP guidance identifies suspension of enrollment as one possible corrective response to an unanticipated problem and also identifies revision of informed consent materials where newly recognized risks need to be communicated.
The consent process may need revision before recruitment resumes
A serious confidentiality incident can reveal that the study's actual privacy risks differ materially from what participants were told.
If the underlying system or procedure is changed, participant information may need to be updated. If the incident reveals a newly recognized material risk, the ethics committee may need to determine whether future participants should receive additional information and whether previously enrolled participants need to be informed.
Under HHS guidance, IRB procedures should include consideration of whether informed consent materials require revision following unanticipated problems or serious noncompliance.
Pausing can itself create participant risks
Stopping research is not always neutral.
In an intervention study, abruptly interrupting a procedure might affect participants' welfare. In longitudinal research, missing time-sensitive follow-up could damage scientific validity. In a clinical context, stopping an intervention without an orderly plan could create greater risk than continuing selected activities under controlled conditions.
Any suspension decision should therefore consider both sides: the risk of continuing and the risk of stopping.
OHRP's current guidance on IRB procedures specifically recommends considering participants already enrolled when research is suspended or terminated, including orderly termination or transfer where appropriate.
Do not confuse containment with formal suspension
A research team may temporarily disable a compromised account, stop uploading files, or take a vulnerable survey offline as an immediate security measure. That is operational containment.
A formal suspension of research approval is a governance action that may be taken by an ethics committee, institutional official, regulator, sponsor, or another authorized body under the relevant framework.
The two can overlap but are not identical. Researchers should take reasonable emergency measures needed to prevent immediate harm within their authority, then promptly seek the required institutional and ethics review.
Emergency changes may sometimes precede formal ethics approval
Research protocols ordinarily should not be changed without the required ethics approval. However, some human-subject protection frameworks recognize that investigators may need to implement changes immediately when necessary to eliminate apparent immediate hazards to participants.
OHRP guidance identifies protocol changes initiated before IRB approval to eliminate apparent immediate hazards as a possible corrective action following an unanticipated problem.
This should not be treated as permission to redesign the study informally after every security incident. Emergency changes should be limited to what is necessary to address the immediate risk and reported through the applicable ethics and institutional procedures promptly.
Privacy notification and study-pause decisions answer different questions
Whether a breach must be reported to a privacy regulator depends on the legal notification threshold. Whether research activities should pause depends on whether continuing those activities remains safe, ethical, compliant, and consistent with the approved protocol.
A breach might fall below the privacy regulator's notification threshold yet reveal a recurring study-system vulnerability that should be fixed before further participants are enrolled.
Conversely, a reportable historical breach might already be fully contained, with no continuing vulnerability affecting current study procedures.
That is why breach notification and study continuation should be assessed separately.
The decision should involve the right institutional functions
A serious breach can require input from privacy, information security, research ethics, the principal investigator, research governance, legal counsel, sponsors, data safety personnel, and collaborating institutions.
No single perspective answers every question. Security personnel can determine whether a vulnerability remains active. Privacy personnel can assess personal-data risk and notification. The research team understands the protocol. The ethics committee evaluates participant protections. Sponsors or regulators may have additional authority.
Coordinated decision-making is especially important when the breach affects a system used across several studies.
What should be fixed before the affected activity resumes?
Resumption should be based on evidence that the relevant risk has been adequately controlled, not merely on the passage of time.
Depending on the incident, that may require patching a system, changing access permissions, resetting credentials, migrating data, replacing a service provider, implementing encryption, revising procedures, retraining staff, reducing collected data, updating agreements, modifying consent materials, or obtaining ethics approval for protocol changes.
The corrective measure should address the actual cause. If the breach occurred because everyone on the project had access to everything, changing one password may not solve the underlying problem.
Someone should explicitly authorize resumption
Where an activity has been paused formally or because of a serious unresolved risk, researchers should know who has authority to determine that it can resume.
Depending on the project, that may involve the PI, institutional privacy or security leadership, research governance, an ethics committee, sponsor, regulator, or a combination of these.
HHS guidance notes that IRB decisions concerning suspension, termination, and subsequent actions should be documented through the appropriate oversight process.
"The system seems fine now" is useful technical information. It is not necessarily the final governance authorization.
Do Not Keep Feeding a Known Vulnerability
If continuing recruitment or data collection would place new participant information into a system reasonably suspected to be insecure, escalate immediately and consider stopping that affected activity until the risk is controlled. Waiting for another disclosure to confirm the first one was serious is not a sensible validation strategy.