User Tools

Site Tools


security:addhealth

This is an old revision of the document!


Add Health Data Security

This page is designed to be used as a reminder of the policies and restrictions that govern the access to and use of Add Health Restricted-Use Data that is hosted at University of California, Irvine. It does not cover the entirety of the Restricted-Use Data Hosting Agreement. Users are responsible for reviewing and adhering to all relevant agreements and policies.

UNC Policies

UCOP & UCI Policies

Below are links to the relevant UCOP and UCI policies:

Shared Responsibility Model

While there are many physical and technical security measures in place, security is a shared responsibility. All users of Add Health data must be aware of their responsibility to follow the above policies and maintain data security.

Below are summaries highlighting the main points for each area of responsibility.

Responsibility of Principal Investigator

  • Ensuring that only approved and authorized users are added to the Add Health agreement and related Data Use Agreement.
  • Ensuring that users understand the permitted uses and restrictions associated with Add Health Restricted-Use Data.
  • Ensuring that users complete required onboarding and training before being granted access.
  • Notifying system administrators when user access should be added, renewed, modified, or removed.
  • Ensuring that research use remains consistent with the approved Add Health agreement, conditions of use, and any related IRB or data use requirements.

Responsibility of All Users

  • Review and comply with the Add Health Conditions of Use.
  • Protecting credentials and never sharing accounts or passwords.
  • Accessing the data only for approved purposes.
  • Not attempting to identify, locate, contact, or re-identify individuals represented in the data.
  • Protecting their endpoint systems and work areas from unauthorized access or disclosure.
  • No unauthorized copying or sharing of data.
  • Prompt reporting of suspected security incidents.

Responsibility of System Administrators

  • Maintaining the operating system, software, access controls, firewall rules, encryption, logging, backups, monitoring, and other technical safeguards.
  • Annually extending the expiration date of user accounts that are authorized to maintain access to the data.
  • Applying patches and responding to vulnerabilities.
  • Maintaining administrative records such as access changes and system changes.
  • Supporting UCI and UNC incident response activities.
security/addhealth.1783376762.txt.gz · Last modified: 2026/07/06 22:26 by jnilsson