Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For sensitive research files, use an organization-approved transfer method that protects data in transit and at rest and gives you control over who can access it. A managed sharing service or SFTP may fit online exchanges; encrypted removable media may suit an approved offline transfer. Choose based on the data, recipient, collaboration needs, and your institution’s rules—not on encryption claims alone.

Choose a method by the exchange, not by habit

Before sending a file, identify how it will be used and who will manage it. NIST recommends selecting solutions around user needs, security, and usability, training users, using cryptography for confidentiality and integrity, and monitoring exchanges. Its Special Publication 800-177 Revision 1 covers trustworthy email, while NIST’s August 3, 2020 bulletin announcement discusses possible solutions for secure file exchanges.

  • Recipient and workflow: Is this a one-time delivery, an ongoing collaboration, or a recurring automated exchange between organizations?
  • Protection scope: Does the method encrypt the connection, stored files, or both—and who controls the encryption keys?
  • Access governance: Can you limit access to named users, require authentication, set an expiry, revoke access, and review access records?
  • Operational fit: Can the recipient use it, can it handle the file size, and does your organization approve and support it?
  • Risk ownership: Where are files stored, who administers the service, how are they retained or deleted, and what happens if credentials or media are lost?

These are checks, not guaranteed features: confirm them for the specific service or deployment you plan to use.

Compare practical alternatives

Method Best suited to What to verify
Organization-approved sharing service Human collaboration and controlled access to shared files Recipient permissions, authentication, encryption in transit and at rest, logging, retention, deletion, and account controls
SFTP or another approved secure transfer protocol File delivery, including recurring or system-to-system exchange Account controls, server configuration, storage protection, audit records, and operational ownership
Encrypted file sent through a separate channel A specific file transfer when the recipient can handle encryption and a separate secret Appropriate encryption, secure delivery of the decryption secret through a separate channel, and safe handling after decryption
Encrypted removable media An approved transfer when online delivery is unsuitable or unavailable Encryption, authorized custody, physical security, and procedures for loss, return, or destruction

Organization-approved sharing services

A controlled sharing workflow can make collaboration easier than repeatedly sending copies. NIST includes file-sharing services among internet exchange methods, and the UK Information Commissioner’s Office (ICO) notes that online applications can support sharing and collaboration. Those general descriptions do not establish that a particular service encrypts stored files, offers every access control, or meets your organization’s requirements. Check its configuration and your organization’s approval before uploading research data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SFTP and secure transfer protocols

The U.S. Department of Education describes SFTP as network technology that encrypts authentication information and data files in transit. That protects the transfer, but does not by itself tell you how a particular server stores files, manages accounts, or records access. For an actual SFTP deployment, confirm those details with the service administrator. The Department’s SFTP explainer provides its description.

Encrypted files and separate-channel secrets

The ICO describes encrypting an individual file so it remains protected when sent over a non-secure channel, such as an encrypted email attachment. The recipient needs a decryption secret; communicate it through a separate, suitable channel rather than alongside the file. Once decrypted, the recipient’s handling and storage practices matter. This method is not a substitute for an approved workflow when policy or the sensitivity of the data requires one.

Encrypted removable media

Encrypted removable media can be considered when online transfer is unsuitable or unavailable, but only with organizational approval and custody controls. Plan who may handle the media, how it will be transported and stored, and what to do if it is lost. CDC guidance calls for encryption of identifiable data before transfer, and HHS’s HIPAA Security Rule overview includes device and media controls. Neither source evaluates or recommends a particular USB device.

Check encryption both in transit and at rest

A secure connection does not necessarily protect a file after it reaches a server or is stored in a collaboration service. The ICO explains that without additional encryption methods, such as encrypted storage, data may be encrypted only while in transit. Its encryption and data-transfer guidance identifies TLS or a VPN as possible secure communication methods and file-level encryption as another option. The page says its guidance is under review following the Data (Use and Access) Act, so check its current status when applying it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ask the provider or administrator which protections apply at each stage: upload, storage, sharing, download, and deletion. If a service offers encryption at rest, establish whether it is enabled for your files and who can access or control the keys. Do not treat the word “encrypted” as an answer to all of these questions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Apply the rules that govern your data

U.S. health information and HIPAA

The HIPAA Security Rule requires covered entities and business associates to use administrative, physical, and technical safeguards for electronic protected health information (ePHI). Whether a specific organization or activity is covered, and what safeguards apply, depends on the circumstances; follow your security officer’s and risk-analysis process rather than assuming a tool makes a workflow compliant. See the HHS Security Rule overview.

HHS separately explains an individual’s right to request copies of their own protected health information. In the described access-right circumstances, an individual may request unencrypted email after a brief warning and confirmation. That narrow context is not a general endorsement of ordinary email for routine research sharing. See HHS guidance on individuals’ right of access.

UK personal information

The ICO advises using encrypted communications when available and discusses TLS, VPNs, and file-level encryption. Its guidance also distinguishes protection during transfer from protection while data is stored. Because the page is under review following the Data (Use and Access) Act, consult its current version and your organization’s guidance before relying on it.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identifiable research data

CDC guidance calls for approved, access-controlled electronic transfers and encryption of identifiable information before transfer; its text specifically mentions AES criteria for personally identifiable information (PII). These agency principles do not replace a research institution’s data-use agreements, ethics requirements, or jurisdiction-specific legal analysis. Follow the rules attached to the data and the receiving party.

A practical pre-send checklist

  1. Classify the file. Identify whether it includes personal, health, confidential, or otherwise restricted data, and check applicable agreements and institutional rules.
  2. Choose an approved route. Match the method to the recipient, purpose, file size, and need for collaboration or automation.
  3. Verify protection. Confirm encryption in transit and at rest, and establish who controls keys where relevant.
  4. Restrict access. Use named recipients and the narrowest practical permissions; enable authentication and expiry or revocation when available.
  5. Plan oversight and cleanup. Check access records, retention and deletion settings, and who will administer the exchange. For physical media, document custody and loss procedures.
  6. Tell the recipient how to proceed. Provide any access instructions through an appropriate channel; for an encrypted file, send its decryption secret separately.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.