Data and Privacy
All of Us Research Program
Data and Privacy
Protecting Your Data and Privacy
Your privacy is very important to the All of Us Research Program. We take great care to protect it.
The program follows strict privacy and data security rules that govern how we collect data, work with participants, and keep your information safe. Here are some specific ways we protect your privacy:
- We remove names and other identifying information from people's data before researchers can see it.
- We follow all federal, state, and local laws and regulations for keeping information safe.
- We have strict internal policies and procedures to prevent misuse of data.
- Experts regularly check our systems to make sure they're secure.
- We store information on protected computers. We limit and keep track of who can see it.
- To work with your health data, researchers must agree to a number of rules. This includes promising they will not try to find out who you are.
- We will tell you if there is a risk to your privacy because of a data breach.
- We have Certificates of Confidentiality from the U.S. government. They will help us fight legal demands (such as a subpoena) to give out information that could identify you.
These protections are grounded in two foundational policy documents developed as part of the Precision Medicine Initiative: the Privacy and Trust Principles and the Data Security Policy Principles and Framework. Both are summarized below and available for download.
Learn more about how the program works in the All of Us Research Program Protocol.
Privacy and Trust Principles
In 2015, the White House convened an interagency working group to develop Privacy and Trust Principles for the Precision Medicine Initiative. Co-led by the Office of Science and Technology Policy, HHS Office for Civil Rights, and the National Institutes of Health, the principles were developed through expert roundtables, review of bioethics literature, analysis of existing biobank privacy frameworks, and public comment.
The principles provide foundational guidance for how the All of Us Research Program collects, protects, and shares participant data. They address six areas:
- Governance - substantive participant representation at all levels of oversight, design, and implementation
- Transparency - keeping participants informed through all stages, including prompt notification of any breach
- Participant Empowerment through Access to Information - consumer-friendly access to information participants contribute
- Data Sharing, Access, and Use - authorized purposes only; sale and targeted advertising expressly prohibited
- Data Quality and Integrity - standards of accuracy, relevance, and completeness at every stage
- Respecting Participant Preferences - broad inclusion, dynamic consent, and the ability to withdraw at any time
Each principle includes detailed sub-principles that define specific commitments and safeguards.
Download the full PMI Privacy and Trust Principles.
Data Security Policy
The Precision Medicine Initiative Data Security Policy provides a broad framework for protecting participant data and resources. Developed through a collaborative interagency process with input from OSTP, the National Security Council, U.S. Digital Service, NIST, the FTC, VA, DoD, and HHS (including OCR, ONC, NIH, FDA, and CMS), the policy recognizes that data security requires continuous, evolving processes to address both internal and external threats.
Participant-contributed data is the foundational asset of the program. PMI data is highly sensitive and may include clinical and insurance claims data, survey and demographic data, genomic and other biospecimen-derived data, and mobile or device data. All systems used by the All of Us Research Program meet the requirements of the Federal Information Security Management Act (FISMA).
The policy is organized around overarching security principles and a five-function cybersecurity framework, both summarized below.
Download the full PMI Data Security Policy Principles and Framework.
Security Principles
The overarching security principles guide organizations in developing and implementing appropriate security plans. PMI organizations should, at a minimum:
- Build systems that participants trust, maintaining a "participant first" orientation when addressing data security risks
- Treat security as a core element of organizational culture, with adaptable and updatable processes
- Preserve data integrity so that participants, researchers, and health care providers can depend on the data
- Identify key risks and develop management plans that address them while enabling research to advance
- Provide clear expectations and transparent security processes
- Use security controls to protect data, not as a reason to deny participant access or limit appropriate research
- Minimize exposure of participant data and maintain breach awareness to preserve trust
- Share experiences and challenges so organizations can learn from each other
Security Framework
The Data Security Policy Framework is based on the NIST Framework for Improving Critical Infrastructure Cybersecurity (Version 1.0). It defines five simultaneous and continuous functions for assessing and maintaining cybersecurity and data security:
- Identify - develop a comprehensive, risk-based security plan with regular independent review and public transparency about security approach and breach notification processes
- Protect - implement access controls with strong multi-factor authentication, role-based training for all data users, encryption of data at rest and in motion, and service provider security assurances
- Detect - maintain continuous audit logs with tamper protection, anomaly detection and alerting, and participate in threat information sharing forums
- Respond - execute incident response plans, regularly test them, notify affected individuals promptly following a breach, and designate an accountable point of contact
- Recover - establish emergency response and post-incident recovery plans, communicate restoration of secure environment to stakeholders, and apply lessons learned across the PMI community
Each function includes detailed sub-requirements for PMI organizations. See the PMI Data Security Policy Principles and Framework for the full framework.
Requirements for Research Partners and Awardees
This section applies to research partners and awardees. Program participants are not subject to these requirements.
All partners in the All of Us Research Program are required to adhere to the Precision Medicine Initiative (PMI) Data Security Policy Framework.
The National Institutes of Health (NIH) is an Operational Division (OpDiv) of the U.S. Department of Health and Human Services. Security controls are required by the Department to provide minimum levels of assurance for safeguarding OpDiv information. All of Us is a special federally funded program that has selected NIST Special Publication 800-53 as its security controls framework.
NIST SP 800-53 is designed for safeguarding federal information and information systems. The controls outlined in the framework provide adequate security that can be applied to extramural research partners as a method of meeting the PMI Data Security Policy Framework.
For non-federal awards not covered by Federal Acquisition Regulation, All of Us will provide a list of NIST SP 800-53 exempt security controls. A separate control mapping will be provided as equivalent to lower risk profile systems that apply the NIST SP 800-171 controls framework for non-federal systems processing Controlled Unclassified Information.
This page last reviewed on
