Since these apps are not managed by BU, accounts need to be removed or disabled when no longer required. Researchers and staff need to use strong passwords and two-factor authentication, even if not required by the app.
HIPAA Compliant for BU: We conducted a security review and obtained a HIPAA Business Associate Agreement with the vendor/platform. Only health plans, health care clearinghouses, and health care providers who bill insurance companies have to comply with HIPAA. So, apps/platforms listed under HIPAA compliant have gone through a BU InfoSec security review and have agreed to comply with HIPAA through a HIPAA Business Associate Agreement. These apps may be used by BU HIPAA Components. BMC Investigators should contact BMC to determine which apps are cleared for BMC research.
Restricted Use: personally identifiable human subject health data, such as diagnosis tied to email, phone #, or picture/video of face
Confidential: anonymized human subject health data (i.e., dates, city, Zip Code only) or personally identifiable human subject data that is not health related (e.g., texts per day, decision making).
Click here to learn about Restricted Use and Confidential data classifications: www.bu.edu/policies/data-classification-policy/
HIPAA Compliant for BU
Constant Contact
DeDoose
- A cross-platform app for analyzing qualitative and mixed methods research with text, photos, audio, videos, spreadsheet, data and more.
- https://www.dedoose.com/
Wellpepper
- It is an exercise tracker to engage and connect with patients and research subjects.
- It can be used for Restricted Use data if passwords are changed every 3 months.
- https://www.wellpepper.com/
Restricted Use
Agile Health
- Can be used for patient or research subject communication, usually for health reminders.
- A coordinator must be appointed to complete quarterly access audits.
- https://agilehealth.com/
Aridhia
- Aridhia is a research collaboration platform that will be used for de-identifying individually identifiable human subject health data and sharing with other research sites.
- https://www.aridhia.com/
BigHealth Sleepio and Daylight apps
Blank Slate
- Medical Campus researchers want to use BlankSlate.com to provide training to human subjects (research participants).
- https://blankslate.io/
Brainwave Bank
BuildClinical
Calendly
- Allow research participants to pick available meeting times.
- Calendly coordinates a scheduled time between researcher and participant.
- https://www.calendly.com/
Cisco Jabber
CommCare by Dimagi
Curebase
Eleos Health
Exxat
- Streamline your program’s data collection, document storage, contracts and daily workflows to manage your placements, curriculum, compliance and profiles for everyone in one place. Exxat Prism optimizes your program management.
- https://exxat.com/
Gyrtics
- Gyrtics is a non-BU, SaaS app/platform that is used by companies to get feedback on Facebook contests, rank/reward programs, and – like here – level of engagement.
- https://grytics.com/
HelloHibou
Human API
- Human API allows patients and research subjects to gather their medical records from multiple sources (e.g., BMC, Partners), and share them with researchers
- https://www.humanapi.co/
iMotions
Jet Mail Services
Kernel
- Using Kernel’s device and cloud instance allows analysis and image rendering for human activity.
- https://www.kernel.com/
Linus Health
- Can be used for brain health research, including coordination with other apps:
- DANA (subjects identified by anonymous subject ID)
- Aural Analytics (subjects identified by anonymous subject ID)
- A coordinator must be appointed to complete quarterly access audits.
- https://linus.health/
Lookit
Medidata
- Medidata provides clinical trial support services.
MetaOptima DermEngine
MetaSource
MetricWire
MyMeds
- MyMeds provides real-time data exchange for medication management, that can be used by researchers for gathering human subject medication information
- https://my-meds.com/
Seqster
- Can be used to collect patient medical records from multiple sources (e.g., BMC or Partners Healthcare)
- Allows the research subject to share all of their records with the research project.
- Can also be used to replace the use of HIPAA authorization forms.
- https://www.seqster.com/
Sfax by Scrypt
Solo
SurveyCTO
Tasso
- Tasso’s patient-centric devices are a digitally-enhanced solution for easy, virtually painless remote sample collection.
- https://www.tassoinc.com/
Trialfacts
Veeva SiteVault
Washington University in St. Louis REDCap
- The use and collaboration with other researchers must be approved by the Institutional Review Board.
- It has the same features as the BU REDCap.
Confidential
Asana
Blackboard Transact
- Allows Student Life & Engagement locations to accept MSU ID Cards for authorized access to events or for payment in business operations
- https://transactcampus.com/
Box
Confluence Atlassian
Slack
Smartsheet
Synapse AD Knowledge Portal
- Knowledge portal approved by NIA for sharing anonymous or HIPAA Limited Data Set data
- This means that all identifiers have been removed except for dates (DOB, dates of treatment), city, and Zip Code
- https://adknowledgeportal.synapse.org/
Apps Currently Under Review
We are working on gathering security information about these apps. Until the security review is complete, please only use anonymized data. (e.g., identify subjects by Subject ID, anonymous emails).
Fitbit