Do you have any standard IRB language for Foundation engagement features?
Foundation Engagement Features-Data Security
The study team will contact leads by text message, phone, and email through the engagement of the Foundation platform. Messages are delivered through third-party communications providers, with Business Associate Agreements (BAAs) in place with each provider. All message content is encrypted in transit using TLS 1.2 or higher, and delivery logs are stored encrypted. Personal data is encrypted at rest as well as in transit; access to systems containing personal data is monitored and logged, and BuildClinical maintains breach detection procedures and an incident response plan, with notification of confirmed breaches within legally mandated timeframes. Access to communications is controlled through role-based permissions, so only authorized study team members can view or send messages to participants. As with any standard SMS service, message delivery over carrier networks is not end-to-end encrypted; study teams are advised to limit sensitive health information in text message content. The study team will obtain each participant's consent before initiating communications, including express written consent for text messages as required under the Telephone Consumer Protection Act (TCPA), and communications will comply with TCPA and CAN-SPAM. Participants may opt out at any time, including by replying STOP to any text message; the platform records and honors communication preferences, with opt-out requests processed in real time and suppression lists enforced before delivery.