Reference:GBR Guidance Access to Electronic Health Records by Sponsor representatives in clinical trials 44447 System Security
From GxPlex
| Document information | |
|---|---|
| Reference | GBR Guidance
Access to Electronic Health Records by Sponsor representatives in clinical trials 44447 |
| Validity area | GBR |
| Scope(s) | G |
| Document name | Guidance
Access to Electronic Health Records by Sponsor representatives in clinical trials |
| Version / Revision | 2021-09-08 00:00:00 |
| Status | Current |
| Document type | Official recommendation |
| Language(s) | EN |
| Description | Guidance
Access to Electronic Health Records by Sponsor representatives in clinical trials The following guidance has been jointly developed by the Heath Research Authority (HRA) and MHRA, in consultation with the Information Commissioners Office (ICO), on behalf of the UK. |
| Official source | Official link |
| Restricted access | No |
| Submitted by | Florian Adragna |
| Contributors | |
| Reference Details | |
|---|---|
| Module | Module 4 â Unit 4.3.4 |
| Scope | G |
| Document part | System Security |
| Language | EN |
| Original entry by | Florian Adragna |
| Contributors | |
| Tags | Systems validation, Remote access, Data protection, Sponsor, Monitoring |
Content
System Security [...] There should be the implementation of robust security procedures by the sponsor and investigator site/institution, such as; password criteria and renewal rules, firewalls, virus and malware protection, penetration testing (to identify vulnerabilities), system monitoring for detection of inappropriate/unusual activities/intrusions and changes to network configurations, threat intelligence software, physical security considerations at data centres and timely implementation of any security updates/patches. [...] Controls Implemented by the Sponsor (or authorised delegated party, e.g. CRO) [...] 3. Remote Log-in Access to the EHR system at UK sites must only be undertaken from a physical location in the UK, an EEA state, or another state covered by a UK adequacy decision 4. The device through which remote Log-in Access to the EHR system is used should be provided by the sponsor, or the sponsor should have undertaken an assessment of the security processes applied to the device(s) [...]5. The sponsor must not record any video calls where screen sharing of guided direct access or of paper source documentation has taken place. There must be no records of any trial participant information in any âchatâ function of the remote video call. [...] 6. The model clinical trial agreements require that Monitors (or Auditor) are suitably trained to understand information governance requirements. There should be training courses put in place by the sponsor to cover the protection of trial participantsâ data confidentiality in relation to the contractual obligations of the sponsor with the investigator site/institutions. [...]