
Quick answer: A transcription company is not made “IRB compliant” by a badge or generic certificate. The practical question is whether the vendor can perform the transcription work exactly within your approved protocol, consent language, institutional security requirements, and any applicable privacy rules. Before sending recordings, confirm who will access them, where data will be transferred and stored, whether subcontractors are used, how long files are retained, how deletion is documented, and what happens if protected health information (PHI) or other sensitive data is present.
For researchers working with interviews, focus groups, oral histories, or clinical conversations, the transcript can become one of the most sensitive datasets in the project. A recording may contain names, workplaces, diagnoses, immigration histories, family details, allegations, or indirect identifiers that were never meant to circulate outside the research team. Choosing a transcription vendor therefore belongs in the study’s data-management plan - not at the end of fieldwork when a deadline is approaching.
If your team needs human-reviewed research transcripts, VerbalScripts academic and conference transcription and qualitative interview transcription can be evaluated against the checklist below. For institution-specific requirements, request a written quote and workflow before uploading restricted data.
In the United States, Institutional Review Boards review research under the rules and policies that apply to the institution and study. HHS regulations at 45 CFR part 46 set federal requirements for many human-subjects studies, while universities may impose additional contractual, security, or privacy controls. The IRB approves the research protocol; it does not normally confer a universal compliance certification on an outside transcription company.
That distinction matters. A vendor can have strong security practices and still be unsuitable if the approved protocol says recordings will be accessible only to named study personnel, retained for a particular period, processed in a particular environment, or stripped of identifiers before an outside party receives them.
The safest procurement language is therefore concrete: “Can this vendor meet the requirements of our approved protocol and institutional data-security terms?”
Send the vendor only the provisions that are necessary to define the workflow, and identify any promises made to participants about recording, transcription, third-party access, de-identification, retention, or destruction. If outsourcing transcription was not anticipated in the protocol, ask the PI or IRB office whether a modification is needed before transferring recordings.
Ask for a role-based description, not a vague promise of confidentiality. Clarify whether access may include a project manager, transcriptionist, reviewer, proofreader, technical administrator, or subcontractor. Then compare that access model with your protocol.
The research team should know whether the company performs all work itself or routes files to additional parties. If subcontractors can receive identifiable data, ask how they are bound to the same confidentiality and security obligations and whether your institution requires prior approval.
Your university may have a security questionnaire specifying encryption, authentication, access controls, logging, password standards, vulnerability management, or incident-response obligations. Do not substitute marketing language for the institution’s actual checklist. Ask the vendor to answer the controls that matter to your data classification.
Some protocols, grants, contracts, tribal agreements, export-control rules, or institutional policies can restrict where data is handled. Ask about storage location and any cross-border processing rather than assuming that “online transcription” means domestic processing.
Define the lifecycle for audio, working copies, drafts, final transcripts, backups, and support attachments. Decide whether deletion happens immediately after acceptance, after a fixed quality-assurance window, or on written request. If your institution requires evidence of deletion, state that requirement in the order.
A research transcript can remain identifiable even after names are removed. Locations, job titles, rare conditions, relationship details, and distinctive events may be indirect identifiers. Specify whether the vendor should:
• transcribe identifiers exactly;
• replace them with neutral placeholders such as [PARTICIPANT NAME];
• produce both an original and a de-identified copy; or
• leave de-identification to the research team.
The vendor should never invent a de-identification scheme that conflicts with the codebook or analysis plan.
IRB requirements and HIPAA requirements are different. When a HIPAA covered entity or business associate hires a vendor to create, receive, maintain, or transmit PHI on its behalf, a Business Associate Agreement (BAA) may be required. HHS specifically describes business-associate obligations and downstream subcontractor requirements. For health-related studies, your privacy office should determine whether the recording contains PHI and whether the transcription relationship requires a BAA.
Security is only one part of research quality. Tell the vendor whether the study needs clean verbatim, full verbatim, pauses, fillers, false starts, overlapping speech, nonverbal events, timestamps, or special notation. A transcript that is “cleaner” but analytically incompatible with the methodology can be a poor research deliverable.
For phenomenological work, see Phenomenological Research Transcription. For coding workflows, see Thematic Analysis Transcription.
Ask whether a second person reviews the transcript, how uncertain speech is marked, how names and technical terms are verified, and whether the vendor accepts a study glossary. A responsible workflow marks genuinely inaudible material instead of guessing.
VerbalScripts describes a human-driven workflow across transcription, review, proofreading, and formatting. For research teams, the practical benefit of multiple review stages is consistency across participant files - particularly when a dissertation or funded project contains dozens of interviews.
Your contract or data-use agreement may require notification within a defined time. Ask who receives incident reports, what information is supplied, and how the vendor coordinates containment and investigation. This should be established before an incident, not negotiated afterward.
Research offices often need more than a price. Ask whether the vendor can provide a written scope covering confidentiality, access, file transfer, retention, deletion, turnaround, transcription convention, and any required agreement. This makes the arrangement easier to defend during internal review and easier to reproduce later.
Study fit: Confirmation that the vendor can follow the approved protocol and consent restrictions
Confidentiality: NDA/confidentiality terms and description of authorized personnel
Subcontracting: Disclosure of any downstream processors or transcriptionists
Security: Transfer, storage, authentication, access-control and incident-response information
HIPAA: BAA capability when the relationship and data require one
Data location: Processing/storage locations relevant to institutional restrictions
Retention: Defined retention window for audio, drafts, finals and backups
Deletion: Deletion procedure and documentation if required
Transcript standard: Verbatim level, timestamps, speaker labels, redaction/de-identification rules
QA: Review/proofreading process and treatment of inaudible speech
Deliverables: Word/PDF/text format, naming convention, QDAS-ready structure if required
Project management: Turnaround, revision window, point of contact and escalation process
Provide a concise project brief. Include participant codes rather than real names when feasible, the moderator/interviewer name, expected speaker count, a terminology list, transcription convention, timestamp rule, redaction instructions, file-naming scheme, and the deadline. If a consent form or protocol imposes restrictions, communicate the operational requirement without unnecessarily circulating the entire research file.
For dissertation projects, VerbalScripts also maintains a dedicated dissertation interview transcription service. Researchers can upload files through the order portal only after confirming that the chosen workflow is permitted by their protocol and institution.
Generally, no. An IRB reviews the research and the protections described in the protocol. A university may separately approve or contract with vendors. Treat “IRB compliant” as shorthand for a vendor workflow that follows the approved study requirements, not as a universal certification.
It depends on the study and what the approved protocol already permits. If the protocol or consent materials did not anticipate third-party transcription, identifiable data, or a new data-handling arrangement, contact the PI or IRB office before outsourcing.
When feasible, minimizing identifiers before transfer can reduce risk, but it is not always practical because identifiers may be spoken throughout the recording. The approved protocol and analysis needs should control whether the vendor transcribes, masks, or leaves identifiers for the research team to remove.
No. HIPAA regulates certain health information handled by covered entities and business associates; IRB and Common Rule requirements concern human-subjects research. A clinical study can implicate both, one, or neither depending on the facts.
Usually yes when the output uses consistent speaker labels, clean paragraph structure, predictable filenames, and stable participant IDs. Tell the vendor which analysis environment you use before transcription begins.
The best research transcription vendor is not simply the one that says “secure.” It is the one that can explain who touches the data, how it moves, how it is protected, how long it exists, how it is deleted, and how the transcript will preserve the analytic features your methodology requires.
If you are preparing a U.S. university study, dissertation, or funded qualitative project, request a VerbalScripts quote with your protocol constraints, file count, approximate audio minutes, and desired transcript convention. The team can then scope the transcription workflow before restricted research data is transferred.
Research compliance note: This article is operational guidance, not legal advice or a substitute for your IRB, privacy office, information-security team, or institutional counsel.
• U.S. HHS Office for Human Research Protections, 45 CFR part 46 and human-subjects guidance
• HHS, Business Associates under HIPAA
• NIH, Data Management and Sharing Policy
• NIH, Principles and Best Practices for Protecting Participant Privacy
Quick answer: A transcription company is not made “IRB compliant” by a badge or generic certificate. The practical question is whether the vendor can perform the transcription work exactly within your approved protocol, consent language, institutional security requirements, and any applicable privacy rules. Before sending recordings, confirm who will access them, where data will be transferred and stored, whether subcontractors are used, how long files are retained, how deletion is documented, and what happens if protected health information (PHI) or other sensitive data is present.
For researchers working with interviews, focus groups, oral histories, or clinical conversations, the transcript can become one of the most sensitive datasets in the project. A recording may contain names, workplaces, diagnoses, immigration histories, family details, allegations, or indirect identifiers that were never meant to circulate outside the research team. Choosing a transcription vendor therefore belongs in the study’s data-management plan - not at the end of fieldwork when a deadline is approaching.
If your team needs human-reviewed research transcripts, VerbalScripts academic and conference transcription and qualitative interview transcription can be evaluated against the checklist below. For institution-specific requirements, request a written quote and workflow before uploading restricted data.
In the United States, Institutional Review Boards review research under the rules and policies that apply to the institution and study. HHS regulations at 45 CFR part 46 set federal requirements for many human-subjects studies, while universities may impose additional contractual, security, or privacy controls. The IRB approves the research protocol; it does not normally confer a universal compliance certification on an outside transcription company.
That distinction matters. A vendor can have strong security practices and still be unsuitable if the approved protocol says recordings will be accessible only to named study personnel, retained for a particular period, processed in a particular environment, or stripped of identifiers before an outside party receives them.
The safest procurement language is therefore concrete: “Can this vendor meet the requirements of our approved protocol and institutional data-security terms?”
Send the vendor only the provisions that are necessary to define the workflow, and identify any promises made to participants about recording, transcription, third-party access, de-identification, retention, or destruction. If outsourcing transcription was not anticipated in the protocol, ask the PI or IRB office whether a modification is needed before transferring recordings.
Ask for a role-based description, not a vague promise of confidentiality. Clarify whether access may include a project manager, transcriptionist, reviewer, proofreader, technical administrator, or subcontractor. Then compare that access model with your protocol.
The research team should know whether the company performs all work itself or routes files to additional parties. If subcontractors can receive identifiable data, ask how they are bound to the same confidentiality and security obligations and whether your institution requires prior approval.
Your university may have a security questionnaire specifying encryption, authentication, access controls, logging, password standards, vulnerability management, or incident-response obligations. Do not substitute marketing language for the institution’s actual checklist. Ask the vendor to answer the controls that matter to your data classification.
Some protocols, grants, contracts, tribal agreements, export-control rules, or institutional policies can restrict where data is handled. Ask about storage location and any cross-border processing rather than assuming that “online transcription” means domestic processing.
Define the lifecycle for audio, working copies, drafts, final transcripts, backups, and support attachments. Decide whether deletion happens immediately after acceptance, after a fixed quality-assurance window, or on written request. If your institution requires evidence of deletion, state that requirement in the order.
A research transcript can remain identifiable even after names are removed. Locations, job titles, rare conditions, relationship details, and distinctive events may be indirect identifiers. Specify whether the vendor should:
• transcribe identifiers exactly;
• replace them with neutral placeholders such as [PARTICIPANT NAME];
• produce both an original and a de-identified copy; or
• leave de-identification to the research team.
The vendor should never invent a de-identification scheme that conflicts with the codebook or analysis plan.
IRB requirements and HIPAA requirements are different. When a HIPAA covered entity or business associate hires a vendor to create, receive, maintain, or transmit PHI on its behalf, a Business Associate Agreement (BAA) may be required. HHS specifically describes business-associate obligations and downstream subcontractor requirements. For health-related studies, your privacy office should determine whether the recording contains PHI and whether the transcription relationship requires a BAA.
Security is only one part of research quality. Tell the vendor whether the study needs clean verbatim, full verbatim, pauses, fillers, false starts, overlapping speech, nonverbal events, timestamps, or special notation. A transcript that is “cleaner” but analytically incompatible with the methodology can be a poor research deliverable.
For phenomenological work, see Phenomenological Research Transcription. For coding workflows, see Thematic Analysis Transcription.
Ask whether a second person reviews the transcript, how uncertain speech is marked, how names and technical terms are verified, and whether the vendor accepts a study glossary. A responsible workflow marks genuinely inaudible material instead of guessing.
VerbalScripts describes a human-driven workflow across transcription, review, proofreading, and formatting. For research teams, the practical benefit of multiple review stages is consistency across participant files - particularly when a dissertation or funded project contains dozens of interviews.
Your contract or data-use agreement may require notification within a defined time. Ask who receives incident reports, what information is supplied, and how the vendor coordinates containment and investigation. This should be established before an incident, not negotiated afterward.
Research offices often need more than a price. Ask whether the vendor can provide a written scope covering confidentiality, access, file transfer, retention, deletion, turnaround, transcription convention, and any required agreement. This makes the arrangement easier to defend during internal review and easier to reproduce later.
Study fit: Confirmation that the vendor can follow the approved protocol and consent restrictions
Confidentiality: NDA/confidentiality terms and description of authorized personnel
Subcontracting: Disclosure of any downstream processors or transcriptionists
Security: Transfer, storage, authentication, access-control and incident-response information
HIPAA: BAA capability when the relationship and data require one
Data location: Processing/storage locations relevant to institutional restrictions
Retention: Defined retention window for audio, drafts, finals and backups
Deletion: Deletion procedure and documentation if required
Transcript standard: Verbatim level, timestamps, speaker labels, redaction/de-identification rules
QA: Review/proofreading process and treatment of inaudible speech
Deliverables: Word/PDF/text format, naming convention, QDAS-ready structure if required
Project management: Turnaround, revision window, point of contact and escalation process
Provide a concise project brief. Include participant codes rather than real names when feasible, the moderator/interviewer name, expected speaker count, a terminology list, transcription convention, timestamp rule, redaction instructions, file-naming scheme, and the deadline. If a consent form or protocol imposes restrictions, communicate the operational requirement without unnecessarily circulating the entire research file.
For dissertation projects, VerbalScripts also maintains a dedicated dissertation interview transcription service. Researchers can upload files through the order portal only after confirming that the chosen workflow is permitted by their protocol and institution.
Generally, no. An IRB reviews the research and the protections described in the protocol. A university may separately approve or contract with vendors. Treat “IRB compliant” as shorthand for a vendor workflow that follows the approved study requirements, not as a universal certification.
It depends on the study and what the approved protocol already permits. If the protocol or consent materials did not anticipate third-party transcription, identifiable data, or a new data-handling arrangement, contact the PI or IRB office before outsourcing.
When feasible, minimizing identifiers before transfer can reduce risk, but it is not always practical because identifiers may be spoken throughout the recording. The approved protocol and analysis needs should control whether the vendor transcribes, masks, or leaves identifiers for the research team to remove.
No. HIPAA regulates certain health information handled by covered entities and business associates; IRB and Common Rule requirements concern human-subjects research. A clinical study can implicate both, one, or neither depending on the facts.
Usually yes when the output uses consistent speaker labels, clean paragraph structure, predictable filenames, and stable participant IDs. Tell the vendor which analysis environment you use before transcription begins.
The best research transcription vendor is not simply the one that says “secure.” It is the one that can explain who touches the data, how it moves, how it is protected, how long it exists, how it is deleted, and how the transcript will preserve the analytic features your methodology requires.
If you are preparing a U.S. university study, dissertation, or funded qualitative project, request a VerbalScripts quote with your protocol constraints, file count, approximate audio minutes, and desired transcript convention. The team can then scope the transcription workflow before restricted research data is transferred.
Research compliance note: This article is operational guidance, not legal advice or a substitute for your IRB, privacy office, information-security team, or institutional counsel.
• U.S. HHS Office for Human Research Protections, 45 CFR part 46 and human-subjects guidance
• HHS, Business Associates under HIPAA
• NIH, Data Management and Sharing Policy
• NIH, Principles and Best Practices for Protecting Participant Privacy
Get latest updates for our Articles & Blogs. We post fresh content every week.
Sign up for our monthly newsletter