Clinical Research and AI-First Engineering Diagnostic Review

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/35

flashcard set

Earn XP

Description and Tags

Flashcards covering clinical research fundamentals, HIPAA and 21 CFR Part 11 compliance, secure engineering, and AI-first development principles.

Last updated 6:56 AM on 6/19/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

36 Terms

1
New cards

GCP (ICH-GCP E6)

An international ethical and scientific quality standard for designing, conducting, recording, and reporting clinical trials to protect subject rights and ensure data credibility.

2
New cards

Phase I

A sequential stage of clinical testing focused on safety and dosage in a small group, often healthy volunteers.

3
New cards

Phase II

A clinical trial stage focusing on early efficacy and side effects in patients.

4
New cards

Phase III

The pivotal stage of a trial before approval, intended to confirm efficacy and monitor adverse reactions in a large patient population.

5
New cards

Phase IV

Clinical trials conducted for long-term safety monitoring after a drug is already on the market.

6
New cards

CTMS

Clinical Trial Management System; the system of record for operations including site management, monitoring visits, and milestones.

7
New cards

EDC

Electronic Data Capture; a system used to capture and manage clinical trial data electronically through Case Report Forms (CRFs).

8
New cards

eSource

Original data captured electronically at the point of care, meaning there is no prior paper source.

9
New cards

eISF

Electronic Investigator Site File; the digital platform for storing a research site’s essential documents.

10
New cards

Sponsor

The entity that owns the investigational product and funds the clinical trial.

11
New cards

CRO

Contract Research Organization; an organization that performs trial activities outsourced to it by the sponsor.

12
New cards

SMO

Site Management Organization; an organization that provides management and operational support across multiple research sites.

13
New cards

Informed Consent

An ongoing process where a subject voluntarily agrees to participate in a study after being fully informed; it must be documented before any study-specific procedures occur.

14
New cards

Randomization

The process of assigning subjects to treatment arms by chance to reduce selection bias and balance confounders.

15
New cards

SDV

Source Data Verification; the process of comparing data in the EDC/CRF against original source documents to catch transcription errors.

16
New cards

IRB / IEC

Institutional Review Board / Independent Ethics Committee; a body that protects the rights, safety, and well-being of trial subjects by reviewing protocols and consent forms.

17
New cards

SAE

Serious Adverse Event; an event that results in death, is life-threatening, requires hospitalization, or causes significant disability or congenital anomaly.

18
New cards

Protocol Amendment

A change to the trial's master plan that generally requires IRB/IEC review and regulatory/sponsor approval before implementation.

19
New cards

PHI

Protected Health Information; health information tied to an identifiable individual, characterized as an identifier combined with health info.

20
New cards

Minimum Necessary

A HIPAA principle requiring that only the minimum PHI needed to do a task is used or disclosed.

21
New cards

BAA

Business Associate Agreement; a contract required when a vendor or subcontractor handles PHI on behalf of a covered entity.

22
New cards

Breach Notification Rule

A regulation requiring that breaches affecting 500+500+ individuals be reported to HHS within 6060 days of discovery.

23
New cards

Safe Harbor Method

A method of de-identification that involves removing 1818 specified categories of identifiers.

24
New cards

Audit Trail

A computer-generated, time-stamped, and tamper-evident log that records who performed what action and when in a regulated system.

25
New cards

CSV

Computer System Validation; documented evidence proving a system consistently performs its intended function.

26
New cards

ALCOA+

A data integrity acronym standing for Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, and Available.

27
New cards

GxP

An umbrella term for 'Good Practice' guidelines, including GCP (Clinical), GMP (Manufacturing), and GLP (Laboratory).

28
New cards

SQL Injection (SQLi)

A vulnerability where untrusted input is executed as code or a query; the best defense is using parameterized queries or prepared statements.

29
New cards

IDOR / Broken Access Control

A vulnerability where users reach data or actions they should not, such as changing an ID in a URL to read another user's records.

30
New cards

XSS

Cross-Site Scripting; injecting scripts into pages viewed by others, mitigated by output encoding and Content Security Policy (CSP).

31
New cards

Encryption in Transit

The protection of data moving between client and server, requiring TLS 1.2 or higher for PHI.

32
New cards

Encryption at Rest

The protection of stored data, with AES-256 being the recommended standard.

33
New cards

AuthN vs. AuthZ

Authentication verifies identity ('who are you?'), while Authorization verifies permissions ('what are you allowed to do?').

34
New cards

Secure SDLC

A development lifecycle that integrates security practices like threat modeling and code review from the beginning ('shift-left').

35
New cards

Spec-Driven Development

An AI-first practice of leading with a clear specification (goals, constraints, criteria) before letting an agent implement code.

36
New cards

MCP

Model Context Protocol; tools that allow an agent to reach real systems like repositories, databases, and APIs through a standard interface.