Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can a Data Breach Become Serious Enough to Require Pausing the Study?

A data breach does not automatically require stopping an entire study. A temporary pause may be appropriate when continuing recruitment, data collection, transfer, or access would expose participants or their information to an unresolved risk.

324
When a Data Breach May Pause a Study Guide 324 of 398
01 · The Question

Should Research Continue While a Data Breach Is Being Investigated?

A research database has been exposed. The immediate sharing link is disabled, but nobody yet knows why the permissions failed. Recruitment is scheduled to continue tomorrow, and another 200 participants could enter the same system.

Should the study keep running while the investigation continues?

Sometimes yes, sometimes no. A data breach does not automatically invalidate the entire study or require every research activity to stop. But when the incident reveals an unresolved vulnerability that could expose additional participants, continuing the affected activity unchanged may be difficult to justify.

02 · The Short Answer

Pause the Activities That Cannot Yet Be Conducted Safely

In Brief

A research data breach may justify temporarily pausing recruitment, data collection, data access, transfers, or other affected activities when continuing them would expose participants or their information to an unresolved or materially increased risk.

A breach does not automatically require stopping the entire study. The appropriate response should be determined through the institution's privacy, security, ethics, and research-governance processes, with the pause targeted to the activities necessary to protect participants while the problem is contained and corrected.

03 · What You Need to Know

The Decision Should Follow Risk, Not the Word "Breach"

Some breaches can be contained without interrupting the study

Suppose a researcher accidentally sends one pseudonymized file to the wrong internal recipient. The recipient immediately reports the mistake, confirms deletion, no identifiers were involved, the transfer system itself remains secure, and the incident does not affect ongoing data collection.

The organization may still need to document and assess the breach, but stopping recruitment or suspending unrelated study procedures may add little protection.

The existence of a breach therefore does not mechanically produce a study suspension.

Other breaches reveal a continuing risk to new participants

Now suppose every new survey response is automatically stored in a publicly accessible folder because of a configuration error. Fixing yesterday's exposure does not protect tomorrow's participants unless the underlying configuration is corrected.

Continuing data collection would knowingly add new personal data to an environment whose safety is uncertain.

In that situation, temporarily pausing the affected collection process may be an appropriate containment measure while the vulnerability is corrected, validated, and reviewed.

The key question is whether the activity can continue within the approved risk profile

Research ethics depends partly on whether participant risks remain reasonable and adequately controlled.

OHRP guidance on unanticipated problems explains that an incident may require corrective action where it suggests that research places participants or others at greater risk than previously known or recognized. Possible corrective actions include protocol changes, additional monitoring, suspension of enrollment of new participants, suspension of research procedures in currently enrolled participants, and revisions to informed consent.

The important concept is not that every confidentiality breach requires suspension. It is that newly recognized risk can require changes to research activity when existing protections are no longer adequate.

Research ethics committees can have authority to suspend research

Under U.S. HHS human-subject protections, an IRB has authority to suspend or terminate approval of research that is not being conducted in accordance with IRB requirements or that has been associated with unexpected serious harm to participants.

The 2024 Declaration of Helsinki similarly states that research ethics committees must have authority to monitor research, recommend changes, withdraw approval, and suspend ongoing research.

These frameworks apply to particular research contexts and should not be generalized into a universal legal rule for every study. They do illustrate an important ethical principle: continuing approval depends on continued acceptability of participant protections.

A "pause" does not have to mean shutting down everything

Research studies contain multiple activities. Recruitment, consent, intervention delivery, surveys, interviews, record extraction, laboratory processing, data entry, analysis, data transfer, and follow-up may use different systems and create different risks.

A breach affecting one component may justify pausing only that component.

Problem Possible targeted pause Activity that might continue
Online survey is exposing new responses Pause new survey collection and recruitment into that workflow Analysis of already secured data may continue if authorized
External collaborator's access account is compromised Suspend that collaborator's access and transfers Local study procedures may continue if unaffected
Participant contact database is exposed Pause activities requiring the compromised contact system Unrelated laboratory or analytical work may continue where safe
Ransomware affects the primary research environment Pause processing through affected systems Only activities confirmed independent and safe should continue

A targeted pause can protect participants without unnecessarily disrupting scientifically and ethically unaffected work.

Recruitment deserves particular attention

Recruiting new participants while an unresolved breach continues can enlarge the number of people exposed to the same risk.

Ask whether new participants would enter the compromised system, whether the consent information still accurately describes confidentiality protections, and whether the newly discovered risk would reasonably affect someone's decision to participate.

OHRP guidance identifies suspension of enrollment as one possible corrective response to an unanticipated problem and also identifies revision of informed consent materials where newly recognized risks need to be communicated.

The consent process may need revision before recruitment resumes

A serious confidentiality incident can reveal that the study's actual privacy risks differ materially from what participants were told.

If the underlying system or procedure is changed, participant information may need to be updated. If the incident reveals a newly recognized material risk, the ethics committee may need to determine whether future participants should receive additional information and whether previously enrolled participants need to be informed.

Under HHS guidance, IRB procedures should include consideration of whether informed consent materials require revision following unanticipated problems or serious noncompliance.

Pausing can itself create participant risks

Stopping research is not always neutral.

In an intervention study, abruptly interrupting a procedure might affect participants' welfare. In longitudinal research, missing time-sensitive follow-up could damage scientific validity. In a clinical context, stopping an intervention without an orderly plan could create greater risk than continuing selected activities under controlled conditions.

Any suspension decision should therefore consider both sides: the risk of continuing and the risk of stopping.

OHRP's current guidance on IRB procedures specifically recommends considering participants already enrolled when research is suspended or terminated, including orderly termination or transfer where appropriate.

Do not confuse containment with formal suspension

A research team may temporarily disable a compromised account, stop uploading files, or take a vulnerable survey offline as an immediate security measure. That is operational containment.

A formal suspension of research approval is a governance action that may be taken by an ethics committee, institutional official, regulator, sponsor, or another authorized body under the relevant framework.

The two can overlap but are not identical. Researchers should take reasonable emergency measures needed to prevent immediate harm within their authority, then promptly seek the required institutional and ethics review.

Emergency changes may sometimes precede formal ethics approval

Research protocols ordinarily should not be changed without the required ethics approval. However, some human-subject protection frameworks recognize that investigators may need to implement changes immediately when necessary to eliminate apparent immediate hazards to participants.

OHRP guidance identifies protocol changes initiated before IRB approval to eliminate apparent immediate hazards as a possible corrective action following an unanticipated problem.

This should not be treated as permission to redesign the study informally after every security incident. Emergency changes should be limited to what is necessary to address the immediate risk and reported through the applicable ethics and institutional procedures promptly.

Privacy notification and study-pause decisions answer different questions

Whether a breach must be reported to a privacy regulator depends on the legal notification threshold. Whether research activities should pause depends on whether continuing those activities remains safe, ethical, compliant, and consistent with the approved protocol.

A breach might fall below the privacy regulator's notification threshold yet reveal a recurring study-system vulnerability that should be fixed before further participants are enrolled.

Conversely, a reportable historical breach might already be fully contained, with no continuing vulnerability affecting current study procedures.

That is why breach notification and study continuation should be assessed separately.

The decision should involve the right institutional functions

A serious breach can require input from privacy, information security, research ethics, the principal investigator, research governance, legal counsel, sponsors, data safety personnel, and collaborating institutions.

No single perspective answers every question. Security personnel can determine whether a vulnerability remains active. Privacy personnel can assess personal-data risk and notification. The research team understands the protocol. The ethics committee evaluates participant protections. Sponsors or regulators may have additional authority.

Coordinated decision-making is especially important when the breach affects a system used across several studies.

What should be fixed before the affected activity resumes?

Resumption should be based on evidence that the relevant risk has been adequately controlled, not merely on the passage of time.

Depending on the incident, that may require patching a system, changing access permissions, resetting credentials, migrating data, replacing a service provider, implementing encryption, revising procedures, retraining staff, reducing collected data, updating agreements, modifying consent materials, or obtaining ethics approval for protocol changes.

The corrective measure should address the actual cause. If the breach occurred because everyone on the project had access to everything, changing one password may not solve the underlying problem.

Someone should explicitly authorize resumption

Where an activity has been paused formally or because of a serious unresolved risk, researchers should know who has authority to determine that it can resume.

Depending on the project, that may involve the PI, institutional privacy or security leadership, research governance, an ethics committee, sponsor, regulator, or a combination of these.

HHS guidance notes that IRB decisions concerning suspension, termination, and subsequent actions should be documented through the appropriate oversight process.

"The system seems fine now" is useful technical information. It is not necessarily the final governance authorization.

Do Not Keep Feeding a Known Vulnerability

If continuing recruitment or data collection would place new participant information into a system reasonably suspected to be insecure, escalate immediately and consider stopping that affected activity until the risk is controlled. Waiting for another disclosure to confirm the first one was serious is not a sensible validation strategy.

04 · A Practical Example

When Pausing Data Collection Protects the Next Participant

Hypothetical Example

An online survey exposes participant responses

A longitudinal study collects weekly mental-health surveys through an external platform. The research team discovers that a configuration error allowed some participants to view records belonging to other participants. The cause is not yet understood, and another survey wave is scheduled to open the following morning.

Contain The affected survey is taken offline and external access is disabled while the institution investigates.
Pause the vulnerable activity The next survey wave is not opened because new responses would enter the same unresolved system.
Continue unaffected work where appropriate Researchers continue analyses using an already secured pseudonymized dataset after institutional confirmation that the analytical environment is unaffected.
Review participant risk Privacy and ethics personnel assess the exposed information, affected participants, notification obligations, and whether the confidentiality risk described in participant materials remains accurate.
Correct and validate The platform configuration is corrected, permissions are independently tested, access controls are reviewed, and the relevant institutional and ethics approvals for any changes are completed.
Resume deliberately Data collection resumes only after the responsible bodies determine that the vulnerability has been adequately addressed and any required participant communication or protocol modification is in place.

The breach did not require every member of the research team to stop all work. It required stopping the activity that would have continued exposing participants to the unresolved problem.

05 · What Researchers Often Get Wrong

Common Misconceptions About Pausing Research After a Breach

Misconception

Does Every Data Breach Require the Entire Study to Stop?

No. The response should be proportionate to the continuing risk. Some incidents can be contained without interrupting study procedures, while others justify pausing only the affected recruitment, collection, access, or transfer activity.

Misconception

If the Breach Is Reportable to the Privacy Regulator, Must the Study Automatically Be Suspended?

No. Regulatory notification and research suspension use different decision criteria. A reportable breach may already be contained, while a non-reportable incident may reveal a continuing vulnerability that still requires corrective action before research proceeds.

Misconception

Can the PI Simply Decide to Continue Because the Study Is Time-Sensitive?

Not when continued activity presents an unresolved participant, privacy, security, or protocol risk requiring institutional or ethics oversight. Scientific deadlines should be considered, but they do not replace participant protection requirements.

Misconception

Can the PI Permanently Stop the Study Without Involving Anyone Else?

Researchers may need to take immediate protective action within their authority, but formal suspension or termination can involve institutional, ethics, sponsor, regulatory, and participant-welfare requirements. Abrupt termination can itself create risks for enrolled participants.

Misconception

Can Research Resume as Soon as the IT Team Says the System Is Working?

Not necessarily. Technical remediation is important, but serious incidents may also require privacy assessment, ethics review, protocol amendments, participant communication, contractual action, or formal authorization before the affected activity resumes.

06 · What This Means for You

Pause the Risk, Not Automatically the Entire Research Program

A simple pause-or-continue framework

If the breach is fully contained and does not affect ongoing research procedures
The study may be able to continue while investigation, documentation, and notification proceed, subject to institutional and ethics requirements.
If new participants or data would enter the same unresolved vulnerable system
Pause that recruitment or data-collection pathway until the vulnerability is controlled.
If only one collaborator, account, transfer channel, or repository is affected
Suspend that access or activity while allowing demonstrably unaffected work to continue where authorized.
If the incident reveals materially greater participant risk than the approved protocol anticipated
Escalate for ethics review and determine whether protocol, consent, monitoring, or recruitment changes are required.
If stopping an intervention or procedure could itself harm participants
Coordinate an orderly protective response rather than abruptly terminating activity without considering enrolled participants' welfare.

The decision should be documented along with the reasons for continuing, limiting, pausing, or resuming activities. That record helps demonstrate that the response followed participant risk rather than convenience, panic, or the calendar of the next conference submission.

07 · A Quick Checklist

Before Continuing Research After a Data Breach

Ask:
Has the continuing exposure been contained, or could additional participant data still be compromised?
Do we understand the vulnerability well enough to know which research activities are affected?
Would continuing recruitment or data collection expose new participants to the same unresolved risk?
Has the incident materially changed the privacy, confidentiality, or other risks described in the approved protocol or participant information?
Does the ethics committee, sponsor, regulator, or institutional policy require notification, amendment, approval, or suspension before continuation?
Can unaffected study activities continue safely while only the vulnerable component is paused?
Could pausing or terminating an intervention create risks for participants already enrolled?
Have corrective technical, procedural, training, contractual, and governance measures been implemented and validated?
Has the appropriate authority explicitly confirmed when formally paused activities may resume?
08 · Frequently Asked Questions

Common Questions About Pausing Research After a Data Breach

Does a data breach automatically suspend ethics approval?

No. A breach should be reported and assessed under the applicable procedures, but suspension is a separate decision. Ethics bodies may require corrective action, protocol changes, temporary suspension, or other measures depending on the seriousness and continuing risk.

Can the PI temporarily stop data collection immediately?

Where continuing collection presents an apparent immediate hazard, taking necessary protective action may be appropriate, subject to the applicable institutional and ethics procedures. OHRP guidance recognizes immediate protocol changes necessary to eliminate apparent hazards as a possible corrective response, with prompt reporting and review afterward.

Can analysis continue while recruitment is paused?

Potentially. If the analytical environment and dataset are unaffected and continued analysis is authorized, a targeted pause may allow safe activities to continue while the vulnerable recruitment or collection process is corrected.

Who can formally suspend a research study?

The answer depends on the governing framework and institution. Ethics committees or IRBs may have suspension authority, while sponsors, institutional officials, regulators, or investigators may also have defined powers or responsibilities. The 2024 Declaration of Helsinki expressly states that research ethics committees must have authority to suspend ongoing research.

What should happen to participants already enrolled if a study is suspended?

Their welfare should be considered explicitly. Depending on the research, participants may need information, continued safety monitoring, orderly completion of procedures, transfer, or other protective arrangements. HHS guidance recommends considering already enrolled participants when suspension or termination occurs.

Does a breach below the regulator notification threshold ever justify pausing research?

Yes. Privacy notification thresholds and research-continuation decisions answer different questions. An incident might fall below a statutory notification threshold while still revealing an unresolved system weakness that would expose future participants if data collection continued.

When can a paused study resume?

When the relevant vulnerability has been adequately controlled and any required security validation, privacy review, ethics approval, protocol modification, participant communication, sponsor action, or other authorization has been completed. The precise resumption authority depends on how and by whom the activity was paused.

09 · The Bottom Line

A Serious Breach Can Justify a Pause, but the Pause Should Follow the Risk

The Bottom Line

A data breach can become serious enough to require pausing research activities when continuing them would expose participants or their information to an unresolved, newly recognized, or materially increased risk.

The appropriate response is often targeted rather than all-or-nothing: stop the vulnerable collection, access, or transfer pathway, protect participants already enrolled, correct and validate the problem, obtain any required review, and resume only when the affected activity can again be conducted responsibly.

10 · Sources and Further Reading

Authoritative Sources on Breaches and Research Suspension

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes