compliance/pias/YYYY-MM-.md .
| Field | Value |
|---|---|
| Modalities | [e.g., WGS genotypes, RNA-seq, clinical phenotypes] |
| N individuals | [number] |
| Age range | [e.g., adult 18-85] |
| Geographic origin | [e.g., US, multi-site] |
| PHI identifiers present | [list any of the 18 HIPAA identifiers present] |
| De-identification method | [Safe Harbor / Expert Determination / N/A] |
| Re-identification risk | [Low / Medium / High — with justification] |
| Field | Value |
|---|---|
| Intended use | [e.g., GWAS + gene expression QTL analysis] |
| Permitted uses per DUC | [list exactly what the DUC allows] |
| Prohibited uses | [list explicitly prohibited uses per DUC] |
| Data sharing | [Internal only / Purdue collaboration / etc.] |
| Publication plans | [summary statistics only / no individual-level data] |
| Component | Configuration | Justification |
|---|---|---|
| Storage bucket | gs://cytognosis-phi-core/duc- | Tier 4 PHI bucket |
| Encryption | CMEK (activate before ingest) | DUC requirement |
| Access group | duc- | Approved-user-only access |
| Network controls | No public IP; IAP access only | DUC / NIH GDS requirement |
| Audit logging | All access logged to cytognosis-audit-7yr | HIPAA 164.312(b) |
| Risk | Likelihood | Mitigation | Residual risk |
|---|---|---|---|
| Re-identification from genomic data | Medium | No public release of individual-level data; k-anonymity enforced | Low |
| Scope creep (use beyond DUC) | Low | DUC terms documented; access scoped to approved users only | Low |
| Accidental disclosure via model | Medium | Member-inference evaluation before model release (see member-inference-eval.md) | Low |
| Insider access | Low | Audit logs; group-based access; least-privilege | Low |
| Phase | Action | Timeline |
|---|---|---|
| Active analysis | Data retained in phi-core | Duration of DUC |
| DUC expiration | Remove user access; notify data custodian | Within 30 days of expiry |
| Data deletion | Delete objects + KMS key destruction (cryptographic erasure) | Per DUC terms (typically within 60-90 days of expiry) |
| Role | Name | Date |
|---|---|---|
| Privacy Officer | [Name] | [Date] |
| Executive Lead | Shahin Mohammadi | [Date] |
| IRB confirmation | [N/A / Protocol #] | [Date] |