911勛圖

Research Data Storage Options

Information Security 繚 911勛圖 College

Research Data Storage Options

A guide to TC-approved storage platforms for research data, organized by data sensitivity level so you can quickly find the right option for your project.

Choosing the right storage platform for your research data is one of the most important security decisions you will make for your project. The right choice depends on what kind of data you are working with. Use this page to identify approved options based on your data's sensitivity level, and contact the TCIT Information Security team if you are unsure which applies to your situation.

Not sure how to classify your data? Check the data classification key below, review TC's Data Classification Policy, or . When in doubt, treat data as the most sensitive category that could apply.
Data Classification Key

Public

Data appropriate for public release. Examples: published datasets, public-facing content, open research data.

Internal

Non-public TC information not intended for public release. Examples: unpublished drafts, aggregate operational data, internal communications.

Confidential

Sensitive data whose unauthorized disclosure could harm individuals or TC. Examples: de-identified human subjects data, unpublished research, donor records.

Restricted

Highly sensitive data governed by law or regulation. Examples: HIPAA-covered health data, FERPA student records, CUI, federally controlled research data.

Storage Options by Data Classification

The table below shows which storage platforms are approved for each data classification level. Approved means the platform is cleared for that data type. Requestable means access is available but must be requested. Contact InfoSec means additional review is required before use.

Data Level TC Google Drive
(Standard - included with TC account)
TC Google Drive
(HIPAA Account)
TC Dropbox
(HIPAA compliant)
Secure Research
File Server
Public Approved Standard TC Google account. No additional setup required. Approved HIPAA account also works for public data. Approved Subject to license availability. Approved Contact InfoSec to discuss suitability for your project. Approved Qualtrics available to all researchers. REDCap must be requested via ServiceNow. Both are HIPAA compliant by default.
Internal Approved Use your TC Google account with appropriate sharing restrictions. Do not use personal Google accounts. Approved Requestable Limited licenses available. Contact InfoSec to request access. Approved Good option for large datasets or projects requiring controlled access. Approved Both platforms support internal research workflows. Qualtrics available immediately. REDCap request via ServiceNow.
Confidential Contact InfoSec Standard Google Drive may be appropriate depending on data type and access controls. Confirm with InfoSec before use. Approved Requestable. Recommended for confidential research data requiring enhanced controls. Requestable HIPAA-compliant. Limited licenses. Contact InfoSec to request and confirm suitability. Approved Recommended for large or sensitive datasets requiring granular access control. Approved Both are HIPAA compliant by default and well suited for confidential research data including de-identified human subjects data. Recommended for survey and data collection workflows.
Restricted Not Approved Standard Google Drive is not approved for HIPAA, FERPA, CUI, or other restricted data. Contact InfoSec May be appropriate for some restricted data types. InfoSec and sponsor review required before use. Contact InfoSec HIPAA-compliant. May be appropriate for some restricted data. InfoSec review and sponsor approval required. Contact InfoSec Often the best option for restricted data. Contact InfoSec to discuss configuration and access controls for your specific requirements. Not Approved REDCap and Qualtrics are approved for Public and Confidential data only. For Restricted data (HIPAA-covered, FERPA, CUI), contact InfoSec to discuss appropriate alternatives.
911勛圖 Each Storage Option
���� Included with TC account

TC Google Drive (Standard)

Available to all TC faculty, staff, and students as part of TC's Google Workspace agreement. Appropriate for Public and Internal research data with proper sharing restrictions applied. Do not use a personal Google account for research data.

���� Requestable

TC Google Drive (HIPAA Account)

A specially configured Google Workspace account with enhanced security controls, suitable for Confidential research data and some Restricted data types. Must be requested through InfoSec. Not included with a standard TC Google account.

���� Requestable - limited licenses

TC Dropbox (HIPAA Compliant)

TC's enterprise Dropbox environment is HIPAA compliant and appropriate for Confidential and some Restricted research data. Licenses are limited - contact InfoSec to check availability and confirm suitability for your data type before requesting access.

���伐�� Contact InfoSec to set up

Secure Research File Server

TC's secure research file server environment provides dedicated, access-controlled storage for research projects with large datasets or heightened security requirements. Particularly well-suited for projects with significant data volumes, sensitive data classifications, or sponsor-mandated security controls. Contact InfoSec to discuss whether this option is right for your project.

���� Available to all TC researchers

TC Qualtrics

TC's enterprise Qualtrics environment is available to all researchers and is HIPAA compliant by default. Ideal for surveys, questionnaires, and online data collection. Appropriate for Public and Confidential research data. Log in to the myTC portal with your TC credentials to access the enterprise environment.

���� Requestable

TC REDCap

TC's REDCap environment is HIPAA compliant by default and purpose-built for clinical and research data collection, management, and storage. Particularly well suited for longitudinal studies, multi-site research, and projects requiring robust data validation and audit trails. Access must be requested through the TCIT Service Desk.

Important Reminders
Never use these for research data: Personal Google accounts, personal Dropbox, personal email, iCloud, or any consumer storage service not listed on TC's Applications Approved for Research list. Using unapproved storage can violate your IRB protocol, your grant agreement, and TC policy.
Related Resources

Not sure which storage option is right for you?

TCIT Information Security 繚 212-678-3300, Opt. 2

Back to skip to quick links