Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Should You Do When Another Participant, Rather Than the Researcher, Reveals Confidential Research Information?

A confidentiality problem can arise even when the research team did not cause the disclosure. Researchers should assess what happened, potential harm, immediate protective steps, and whether ethics or institutional reporting is required.

305
When a Participant Reveals Confidential Information Guide 305 of 398
01 · The Question

What happens when a participant reveals information they learned through the research?

You protected the recording. The transcript is secure. No researcher sent information to the wrong person.

But after a focus group, one participant tells a coworker what another participant said. Or a participant posts part of the discussion online. Perhaps someone repeats another person's sensitive disclosure to a supervisor, relative, colleague, or community member.

The researcher did not make the disclosure, but the disclosure occurred because people encountered the information through the research. What should the research team do now?

02 · The Short Answer

Assess the disclosure, protect participants, document it, and follow the applicable reporting procedure

In Brief

When a participant reveals another participant's confidential research information, the research team should promptly establish what is known, assess the nature and potential consequences of the disclosure, take reasonable steps within its control to reduce further harm, document the incident, and follow the study's approved protocol and applicable institutional or ethics reporting requirements.

Not every participant disclosure automatically has the same regulatory status or requires the same response. Reporting obligations depend on the research, jurisdiction, institution, whether the event was expected, its relationship to research participation, and whether it creates greater risk of harm than previously recognized.

03 · What You Need to Know

The source of the disclosure changes the facts, but not the need to assess the risk

First establish what actually happened

Do not begin by labeling the event before you know the basic facts.

Determine, as far as reasonably possible, what information was revealed, who revealed it, who received it, whether the affected participant was identified, how widely the information has spread, whether the disclosure is continuing, and whether any immediate consequences are apparent.

There is a considerable difference between a participant vaguely mentioning that "someone in the group disagreed with management" and posting an identifiable participant's detailed account of workplace harassment on a public social-media page.

The response should reflect the actual disclosure and risk rather than the mere fact that someone spoke outside the research setting.

Participant-caused disclosure is different from researcher-caused disclosure

A research assistant emailing a transcript to the wrong recipient, a stolen unencrypted laptop containing identifiable research data, and a focus-group participant repeating another person's comments are not the same event.

In the first two examples, the research team or its data systems directly control the information that was exposed. In the third, another participant has acted outside the research team's direct control.

This distinction matters when assessing cause, preventability, noncompliance, and appropriate corrective action. It does not mean the researcher should ignore participant-caused disclosure.

If participants gained access to the confidential information through participation in the study, the incident may still create research-related risks that need to be assessed.

Focus groups make this type of disclosure foreseeable

Focus groups are a particularly obvious setting because participants hear one another's comments directly.

This is why researchers generally cannot guarantee complete confidentiality among focus-group participants. Consent and moderator procedures should ordinarily establish expectations that participants not repeat other people's identities or personal disclosures outside the group while making clear that the researcher cannot guarantee compliance.

If another participant later reveals information, the fact that participant disclosure was recognized as a general possibility does not automatically settle whether the particular incident requires further action. The nature and consequences of the actual disclosure still matter.

Assess the sensitivity of what was revealed

The potential harm from disclosure depends partly on the information.

A participant repeating someone's opinion about preferred meeting times is different from revealing allegations of misconduct, immigration status, a stigmatized diagnosis, experiences of violence, sexual information, illegal behavior, financial difficulties, or criticism of an employer.

OHRP's framework for unanticipated problems explicitly recognizes that research-related harm is not limited to physical injury. Psychological, economic, and social harms can also matter.

Researchers should therefore consider realistic consequences such as embarrassment, stigma, damaged relationships, employment consequences, retaliation, discrimination, financial loss, or other harms relevant to the study population.

Assess how identifiable the affected participant is

A disclosure can expose confidential information without explicitly naming the participant.

If the recipient knows the research setting, a job title, event, relationship, or distinctive experience may be enough to identify the person. This is especially likely when participants already know one another.

Ask whether the recipient actually knows or could reasonably infer who the information concerns. The risk may be very different if the disclosure remains genuinely non-identifiable.

Assess how far the information has spread

Containment may be possible when one participant has told one other person. A public post, forwarded message, group chat, screenshot, or workplace rumor may be much harder to contain.

Relevant questions include whether the information has been copied, whether it remains publicly accessible, whether recipients are likely to redistribute it, and whether any practical action can reduce further dissemination.

Researchers should be realistic. They may be able to request deletion or remind participants of confidentiality expectations, but they cannot guarantee that information already learned will disappear.

Take proportionate steps to reduce further harm

The appropriate immediate response depends on the incident. Possible actions might include reminding the disclosing participant of the agreed confidentiality expectations, asking them not to repeat the information further, requesting removal of an online disclosure where feasible, reviewing whether additional sessions create similar risk, or seeking prompt advice from the responsible research-ethics or institutional office.

Researchers should avoid escalating the situation unnecessarily. Contacting a participant's employer, family, or other third party without justification could create additional disclosure or harm.

When an immediate protective action is necessary, follow the approved protocol and institutional procedures as far as circumstances permit.

Do not promise the affected participant an outcome you cannot deliver

If the affected participant learns about the disclosure, the research team should communicate accurately about what is known and what steps are within its control according to applicable institutional procedures.

Do not promise that all copies can be recovered, that nobody else knows, that the disclosing participant will face a particular consequence, or that the information can be made confidential again.

Once information has left the controlled research environment, complete reversal may be impossible.

Document the incident while the facts are fresh

A contemporaneous record can be important for institutional assessment and for deciding whether the study's protections need modification.

Document factual information rather than speculation: when the research team learned of the incident, what is known to have been disclosed, who is known to have received it, any immediate consequences, actions already taken, and consultations or reports made.

Documentation should itself be handled appropriately because an incident report may contain additional sensitive information about the affected participant.

Not every confidentiality incident has the same reporting requirement

Researchers should follow the reporting procedures applicable to their institution and study rather than assuming that every incident follows one universal rule.

For nonexempt HHS-conducted or supported human-subjects research, OHRP requires institutions to have written procedures for prompt reporting of unanticipated problems involving risks to participants or others, serious or continuing noncompliance, and suspensions or terminations of IRB approval.

OHRP's guidance generally characterizes an unanticipated problem as an incident, experience, or outcome that is unexpected, related or possibly related to participation in the research, and suggests that the research places participants or others at greater risk of harm than was previously known or recognized.

Those criteria matter. An incident is not automatically an unanticipated problem simply because something undesirable occurred. Conversely, a confidentiality incident can qualify when the criteria are met. OHRP provides the example of an unencrypted laptop containing individually identifiable sensitive research information being stolen, creating increased psychological and social risk from the breach.

Institutional reporting procedures may be broader than federal requirements

An institution may require investigators to report certain incidents to its IRB or research office so that the institution can determine whether they meet a regulatory reporting threshold. Other jurisdictions and regulatory systems may use different terminology and requirements.

Do not independently conclude that an event is "not reportable" based only on a general guide if your institution instructs investigators to submit confidentiality incidents for review.

Likewise, do not assume that reporting something to an institutional IRB automatically means it must be reported to a national regulator. Under the HHS framework, institutions and IRBs apply defined criteria and their written procedures to determine further reporting obligations.

Review whether the study's protections were adequate

After addressing the immediate incident, ask whether anything about the study design contributed to the problem.

Were participants adequately informed about confidentiality limitations? Were ground rules clear? Were participants placed in groups with relationships that made disclosure particularly consequential? Did the topic elicit more sensitive information than expected? Should future groups receive a stronger reminder or a private alternative for sensitive responses?

OHRP guidance notes that unanticipated problems may warrant changes to the protocol, informed-consent process, or other corrective actions to protect participants. For covered research, changes ordinarily require IRB review before implementation except when necessary to eliminate apparent immediate hazards.

This is not about retroactively blaming the research team for another person's behavior. It is about learning whether the study can reasonably reduce the chance or consequences of recurrence.

A participant's breach does not cancel the research team's confidentiality obligations

If one participant publicly reveals another participant's identity, the research team should not treat the information as newly public and therefore free to use.

The team's own obligations continue according to the consent, approved protocol, applicable law, and institutional requirements. Researchers should not repeat the disclosure in publications, presentations, emails, or incident discussions beyond what is necessary for legitimate research and oversight purposes.

Watch Out

Do not respond to one confidentiality disclosure by creating another. Limit incident discussions and documentation to the people and information necessary to assess the event, protect participants, and meet applicable reporting obligations.

04 · A Practical Example

A focus-group participant repeats a sensitive disclosure at work

Hypothetical Example

A participant tells a supervisor what a coworker said

During a workplace focus group, one employee says they believe a supervisor has retaliated against staff who raise safety concerns. Participants had been asked not to repeat personal comments outside the group and had been told that the research team could not guarantee participant-to-participant confidentiality. Two days later, the researcher learns that another participant told the supervisor who made the statement and summarized what was said.

Establish the facts The researcher records what is known about the disclosure, who received it, and whether it has spread further without circulating the sensitive allegation unnecessarily.
Assess potential harm Because the disclosure concerns alleged retaliation and has reached the supervisor involved, the researcher considers possible employment and social consequences for the affected participant.
Reduce further disclosure The research team follows its approved procedures and institutional advice regarding any appropriate communication with the participant who disclosed the information and other immediate protective steps.
Follow reporting procedures The investigator consults the institution's applicable incident-reporting requirements so that the event can be assessed under the correct regulatory and ethics framework.
Review the protocol The team considers whether future groups need different composition, stronger confidentiality reminders, alternative methods for particularly sensitive disclosures, or changes to the consent process.

The fact that the researcher did not personally reveal the information does not make the incident irrelevant. The research created the setting in which one participant learned another participant's sensitive statement, so the resulting risk warrants careful assessment.

05 · What Researchers Often Get Wrong

Common mistakes after a participant reveals confidential information

Misconception

The participant caused it, so it is no longer a research issue

If the information was learned through research participation and the disclosure creates research-related risk, the incident may still require assessment and action under the study's ethics and institutional procedures.

Misconception

Every participant disclosure must automatically be reported to a national regulator

Reporting frameworks contain defined thresholds and institutional procedures. Under the HHS framework, for example, reportable unanticipated problems meet criteria involving unexpectedness, relationship to research, and increased risk. Researchers should follow the procedures governing their study rather than inventing a universal rule.

Misconception

If participants were warned about confidentiality limits, nothing needs to be done

Prior warning is important, but an actual disclosure may still create significant harm or reveal that the study's protections need revision. Assess the incident rather than treating consent language as a waiver of researcher responsibility.

Misconception

The researcher should confront everyone immediately and find out who is responsible

An indiscriminate investigation can spread the sensitive information further or create new harm. Establish necessary facts proportionately and follow institutional procedures rather than turning the response into another disclosure event.

Misconception

Once the information has leaked, the research team can treat it as public

A participant's unauthorized disclosure does not automatically change the research team's confidentiality obligations. Continue handling the information according to the approved research and applicable requirements.

06 · What This Means for You

Respond to the risk, not merely to who caused the disclosure

The immediate task is to understand the incident and protect participants as far as reasonably possible. Responsibility, regulatory classification, and longer-term corrective action can then be assessed through the appropriate institutional process.

A simple incident-response framework

If you learn that a participant disclosed another participant's research information
Establish the necessary facts and document what is known without unnecessarily repeating the sensitive information.
If the information is sensitive or the affected participant is identifiable
Assess realistic psychological, social, economic, professional, legal, or other consequences and take appropriate steps within the research team's control.
If the disclosure may constitute an incident requiring institutional review
Follow the study's approved protocol and institutional reporting procedure promptly rather than deciding the regulatory classification informally.
If the disclosure reveals a recurring weakness in the research design
Consider whether consent, group composition, moderator instructions, data collection, or other safeguards need revision through the appropriate review process.
If the information has already spread beyond the research setting
Continue protecting it within the research team and avoid unnecessary redistribution while addressing what can realistically still be contained.

Having an incident-response plan before data collection helps. Researchers make better decisions when they are not trying to invent a confidentiality protocol while simultaneously discovering that the group chat has become ethnographic data of its own.

07 · A Quick Checklist

When a participant reveals another participant's confidential information

Assess and document:
What information was actually revealed and whether it came from participation in the research.
Whether the affected participant was directly named or can otherwise be identified.
Who is known to have received the information and whether it has spread further.
How sensitive the information is and what realistic harms could result from disclosure.
Whether any immediate step can reasonably reduce further disclosure or harm without creating additional exposure.
What the approved protocol and consent materials said about participant-to-participant confidentiality.
What your institution, ethics body, sponsor, or applicable regulatory framework requires you to report and within what timeframe.
Whether future participants face a similar risk that warrants changes to consent, procedures, group composition, or other safeguards.
Whether incident documentation itself is stored and shared in a way that avoids further unnecessary disclosure.
08 · Frequently Asked Questions

Questions about participant-caused confidentiality disclosures

Is it a research confidentiality breach if another participant reveals the information?

It is a confidentiality incident that should be assessed in context, but its regulatory classification depends on the applicable framework and facts. Participant-caused disclosure differs from the research team improperly releasing protected research records, although it may still create research-related risks requiring action.

Must every participant disclosure be reported to the IRB?

There is no universal rule covering every institution and jurisdiction. Follow your institution's reporting procedures and approved protocol. For HHS-covered research, specific regulatory reporting requirements apply to unanticipated problems involving risks to participants or others and other defined events.

What makes an incident an unanticipated problem under the HHS framework?

OHRP generally applies three criteria: the incident is unexpected given the protocol and participant population, is related or possibly related to research participation, and suggests that the research creates greater risk of harm than was previously known or recognized.

Should I tell the affected participant about the disclosure?

The appropriate communication depends on the incident, potential harm, institutional procedures, and applicable ethics or legal requirements. Seek the required institutional guidance rather than assuming that notification is either always required or never appropriate.

Should I remove the participant who disclosed the information from the study?

Not automatically. The appropriate response depends on the seriousness of the disclosure, study procedures, participant agreements, potential risks, and institutional or ethics guidance. Removing someone may itself have consequences and should not be improvised as punishment.

What if the disclosure was accidental?

Intent matters for understanding what happened and preventing recurrence, but accidental disclosure can still create harm. Assess what information was exposed, to whom, how identifiable and sensitive it was, and what corrective or reporting steps are required.

What if the information was posted publicly online?

Assess how identifiable and sensitive the information is, how widely it may have spread, and whether removal or containment is realistically possible. Follow the applicable institutional incident procedure promptly and continue protecting the information within the research team rather than treating the public post as permission for further disclosure.

09 · The Bottom Line

A participant-caused disclosure still deserves a research response

The Bottom Line

If another participant reveals confidential research information, establish what happened, assess identifiability and potential harm, take proportionate protective action within the research team's control, document the incident, and follow the reporting procedures that apply to the study.

Do not assume that every disclosure has the same regulatory status, but do not dismiss it merely because the researcher did not cause it. The important questions are what research participation exposed, what risk the disclosure created, what can still be protected, and whether the study's safeguards need to change.

10 · Sources and Further Reading

Authoritative guidance on confidentiality incidents and research reporting

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes