03 · What You Need to Know
The source of the disclosure changes the facts, but not the need to assess the risk
First establish what actually happened
Do not begin by labeling the event before you know the basic facts.
Determine, as far as reasonably possible, what information was revealed, who revealed it, who received it, whether the affected participant was identified, how widely the information has spread, whether the disclosure is continuing, and whether any immediate consequences are apparent.
There is a considerable difference between a participant vaguely mentioning that "someone in the group disagreed with management" and posting an identifiable participant's detailed account of workplace harassment on a public social-media page.
The response should reflect the actual disclosure and risk rather than the mere fact that someone spoke outside the research setting.
Participant-caused disclosure is different from researcher-caused disclosure
A research assistant emailing a transcript to the wrong recipient, a stolen unencrypted laptop containing identifiable research data, and a focus-group participant repeating another person's comments are not the same event.
In the first two examples, the research team or its data systems directly control the information that was exposed. In the third, another participant has acted outside the research team's direct control.
This distinction matters when assessing cause, preventability, noncompliance, and appropriate corrective action. It does not mean the researcher should ignore participant-caused disclosure.
If participants gained access to the confidential information through participation in the study, the incident may still create research-related risks that need to be assessed.
Focus groups make this type of disclosure foreseeable
Focus groups are a particularly obvious setting because participants hear one another's comments directly.
This is why researchers generally cannot guarantee complete confidentiality among focus-group participants. Consent and moderator procedures should ordinarily establish expectations that participants not repeat other people's identities or personal disclosures outside the group while making clear that the researcher cannot guarantee compliance.
If another participant later reveals information, the fact that participant disclosure was recognized as a general possibility does not automatically settle whether the particular incident requires further action. The nature and consequences of the actual disclosure still matter.
Assess the sensitivity of what was revealed
The potential harm from disclosure depends partly on the information.
A participant repeating someone's opinion about preferred meeting times is different from revealing allegations of misconduct, immigration status, a stigmatized diagnosis, experiences of violence, sexual information, illegal behavior, financial difficulties, or criticism of an employer.
OHRP's framework for unanticipated problems explicitly recognizes that research-related harm is not limited to physical injury. Psychological, economic, and social harms can also matter.
Researchers should therefore consider realistic consequences such as embarrassment, stigma, damaged relationships, employment consequences, retaliation, discrimination, financial loss, or other harms relevant to the study population.
Assess how identifiable the affected participant is
A disclosure can expose confidential information without explicitly naming the participant.
If the recipient knows the research setting, a job title, event, relationship, or distinctive experience may be enough to identify the person. This is especially likely when participants already know one another.
Ask whether the recipient actually knows or could reasonably infer who the information concerns. The risk may be very different if the disclosure remains genuinely non-identifiable.
Assess how far the information has spread
Containment may be possible when one participant has told one other person. A public post, forwarded message, group chat, screenshot, or workplace rumor may be much harder to contain.
Relevant questions include whether the information has been copied, whether it remains publicly accessible, whether recipients are likely to redistribute it, and whether any practical action can reduce further dissemination.
Researchers should be realistic. They may be able to request deletion or remind participants of confidentiality expectations, but they cannot guarantee that information already learned will disappear.
Take proportionate steps to reduce further harm
The appropriate immediate response depends on the incident. Possible actions might include reminding the disclosing participant of the agreed confidentiality expectations, asking them not to repeat the information further, requesting removal of an online disclosure where feasible, reviewing whether additional sessions create similar risk, or seeking prompt advice from the responsible research-ethics or institutional office.
Researchers should avoid escalating the situation unnecessarily. Contacting a participant's employer, family, or other third party without justification could create additional disclosure or harm.
When an immediate protective action is necessary, follow the approved protocol and institutional procedures as far as circumstances permit.
Do not promise the affected participant an outcome you cannot deliver
If the affected participant learns about the disclosure, the research team should communicate accurately about what is known and what steps are within its control according to applicable institutional procedures.
Do not promise that all copies can be recovered, that nobody else knows, that the disclosing participant will face a particular consequence, or that the information can be made confidential again.
Once information has left the controlled research environment, complete reversal may be impossible.
Document the incident while the facts are fresh
A contemporaneous record can be important for institutional assessment and for deciding whether the study's protections need modification.
Document factual information rather than speculation: when the research team learned of the incident, what is known to have been disclosed, who is known to have received it, any immediate consequences, actions already taken, and consultations or reports made.
Documentation should itself be handled appropriately because an incident report may contain additional sensitive information about the affected participant.
Not every confidentiality incident has the same reporting requirement
Researchers should follow the reporting procedures applicable to their institution and study rather than assuming that every incident follows one universal rule.
For nonexempt HHS-conducted or supported human-subjects research, OHRP requires institutions to have written procedures for prompt reporting of unanticipated problems involving risks to participants or others, serious or continuing noncompliance, and suspensions or terminations of IRB approval.
OHRP's guidance generally characterizes an unanticipated problem as an incident, experience, or outcome that is unexpected, related or possibly related to participation in the research, and suggests that the research places participants or others at greater risk of harm than was previously known or recognized.
Those criteria matter. An incident is not automatically an unanticipated problem simply because something undesirable occurred. Conversely, a confidentiality incident can qualify when the criteria are met. OHRP provides the example of an unencrypted laptop containing individually identifiable sensitive research information being stolen, creating increased psychological and social risk from the breach.
Institutional reporting procedures may be broader than federal requirements
An institution may require investigators to report certain incidents to its IRB or research office so that the institution can determine whether they meet a regulatory reporting threshold. Other jurisdictions and regulatory systems may use different terminology and requirements.
Do not independently conclude that an event is "not reportable" based only on a general guide if your institution instructs investigators to submit confidentiality incidents for review.
Likewise, do not assume that reporting something to an institutional IRB automatically means it must be reported to a national regulator. Under the HHS framework, institutions and IRBs apply defined criteria and their written procedures to determine further reporting obligations.
Review whether the study's protections were adequate
After addressing the immediate incident, ask whether anything about the study design contributed to the problem.
Were participants adequately informed about confidentiality limitations? Were ground rules clear? Were participants placed in groups with relationships that made disclosure particularly consequential? Did the topic elicit more sensitive information than expected? Should future groups receive a stronger reminder or a private alternative for sensitive responses?
OHRP guidance notes that unanticipated problems may warrant changes to the protocol, informed-consent process, or other corrective actions to protect participants. For covered research, changes ordinarily require IRB review before implementation except when necessary to eliminate apparent immediate hazards.
This is not about retroactively blaming the research team for another person's behavior. It is about learning whether the study can reasonably reduce the chance or consequences of recurrence.
A participant's breach does not cancel the research team's confidentiality obligations
If one participant publicly reveals another participant's identity, the research team should not treat the information as newly public and therefore free to use.
The team's own obligations continue according to the consent, approved protocol, applicable law, and institutional requirements. Researchers should not repeat the disclosure in publications, presentations, emails, or incident discussions beyond what is necessary for legitimate research and oversight purposes.
Watch Out
Do not respond to one confidentiality disclosure by creating another. Limit incident discussions and documentation to the people and information necessary to assess the event, protect participants, and meet applicable reporting obligations.