Protect & Secure Sensitive Data and Intellectual Property
Safeguarding health-related information and other sensitive personal data, including Social Security numbers is a critical priority to UMB. The Secure Research Environment (SRE) has been established to ensure the protection of both this data and intellectual property generated from research studies. Utilization of the SRE is mandatory for any research that involves sensitive data, such as data supplied by the University of Maryland Medical System (UMMS). The SRE adheres to HIPAA regulations and relevant IT security policies to secure Protected Health Information (PHI) and Personally Identifiable Information (PII).
UMB Research Computing Environment
The SRE provides UMB faculty with a secure platform for conducting research remotely, eliminating the need for local computing. Researchers are granted access to data and software within a protected cloud environment. Use of the SRE mitigates the risk of data breaches, improves computational capabilities, and delivers a personalized workspace tailored to the needs of the Principal Investigator (PI) and team.
Security Compliance
We are pleased to announce that our Secure Research Environment (SRE), built in Microsoft Azure, has received formal approval for its System Security Plan (SSP) for use by the Department of Defense (DoD). This approval confirms that our environment meets the requirements of NIST 800-171, ensuring robust protection of Controlled Unclassified Information (CUI) in accordance with federal standards.
In parallel, we are actively preparing a submission for an NIST 800-53 compliant environment to further extend our capabilities and compliance coverage. This next phase will support broader research initiatives and enhance our alignment with federal cybersecurity frameworks.
We appreciate the continued collaboration across teams and will share updates as the 800-53 submission progresses. For questions or further details, please contact the SRE support team.
SRE - Glossary
For definitions to SRE related abbreviations or to learn more about how PHI & PII are defined, download & print the SRE Glossary here or view the glossary from the drop-down menu below.