STAR Data Protection Statements for IRB Applications (Human Research Application Version 1.4) are available below. When using STAR information resources, you may insert the following statements into IRB applications. Simply copy and paste the text into your proposal.
The acquisition of data sets from research partners outside of Texas A&M University is facilitated with Globus, a secure data transfer tool developed by the University of Chicago. Globus uses "data channels" for moving data between endpoints. All transfers are encrypted using an SSL cipher configured on the endpoints with AES256-SHA encryption. Any data that transits between on-premises storage and STAR-AWS cloud storage and compute is encrypted against each applicable protocol.
STAR-AWS requires mandatory security configurations for the protection of PHI. All STAR virtual machines and storage repositories are hosted by Amazon AWS with encryption of EC2 virtual compute and S3 storage buckets using preconfigured HIPAA cloud formation templates that fulfill all applicable HIPAA security requirements across access control, monitoring, backups, and all other controls. Supplemental reports and security configuration attestation is available upon request.
STAR-AWS data is stored in the Amazon AWS US East – Northern Virginia availability zone. Data is encrypted in transit when traversing between Amazon AWS and on-premises Texas A&M University data repositories.
You may answer "Yes." Technology Services is able to attest to this statement if verification is required.
You may answer: The STAR program, managed by Technology Services, enables security monitoring for intrusion prevention, intrusion detection, and passive access control. The Principal Investigator serves as the data manager, exercising governance over access to the environment by authorizing (or denying) requests for access to datasets. Technology Services serves as the data custodian with responsibility for implementing security controls required by the Texas A&M University Controls Catalog and monitoring the environment.