Since these apps are not managed by BU, accounts need to be removed or disabled when no longer required. Researchers and staff need to use strong passwords and two-factor authentication, even if not required by the app.

HIPAA Compliant for BU: We conducted a security review and obtained a HIPAA Business Associate Agreement with the vendor/platform. Only health plans, health care clearinghouses, and health care providers who bill insurance companies have to comply with HIPAA. So, apps/platforms listed under HIPAA compliant have gone through a BU InfoSec security review and have agreed to comply with HIPAA through a HIPAA Business Associate Agreement. These apps may be used by BU HIPAA Components. BMC Investigators should contact BMC to determine which apps are cleared for BMC research.

Restricted Use: personally identifiable human subject health data, such as diagnosis tied to email, phone #, or picture/video of face

Confidential: anonymized human subject health data (i.e., dates, city, Zip Code only) or personally identifiable human subject data that is not health related (e.g., texts per day, decision making).

Click here to learn about Restricted Use and Confidential data classifications: www.bu.edu/policies/data-classification-policy/