
Regulators’ failure to define key terms has undermined safeguards for individuals with disabilities.
The federal rule governing research on human subjects, issued by the U.S. Department of Health and Human Services (HHS), has five subparts. One sets general guidelines. Three add protections for specifically named populations—pregnant women and fetuses, prisoners, and children. The fifth covers registration of review boards. No subpart addresses people with disabilities or defines who qualifies as disabled.
The rule’s core approval criteria tell institutional review boards—committees that ensure the safety and ethical treatment of research subjects—to pay particular attention when research subjects are likely to be vulnerable to coercion or undue influence, naming four examples, among them individuals with impaired decision-making capacity. Where that vulnerability exists, a board must find that additional safeguards were included before approving research on those subjects. But the definitions section of the same rule—which defines terms such as “certification,” “clinical trial,” “human subject,” “minimal risk,” and more than a dozen other terms with precision—nowhere defines “impaired decision-making capacity” or “vulnerable.” The definition section contains no term relating to disability at all. A board applying the rule’s child-protection provisions, for instance, is provided with an age threshold, a permission structure, an assent requirement, and four risk categories. A board applying the phrase “additional safeguards” to a disabled subject, however, receives no guidance.
The class left undefined is wide. Impaired decision-making capacity includes people with intellectual disabilities, psychotic disorders, Alzheimer’s disease, and other cognitive disorders, permanent or temporary, and people whose capacity is temporarily impaired by severe pain, fear, or anxiety. HHS said as much itself. In a 2007 notice, the agency reported that its own working group had concluded that adults whose capacity is impaired by any disease or condition should receive the same protections as those impaired by a mental disorder, and the group had expressed concern that confining protection to mental disorders could be seen as stigmatizing the people it named. In the same notice, HHS also plainly stated that the regulations contain no specific additional standards for these subjects and do not define who belongs to the group.
That notice was the fourth federal effort since 1978 to consider added protections for this group. In 1978, the National Commission for the Protection of Human Subjects recommended specific protections for people institutionalized as mentally infirm, and HHS’s predecessor agency issued proposed regulations that year. They were never finalized. HHS’s own later account gives the reason: no consensus, plus a judgment that the general rules sufficed. Everybody that took up the question afterward proposed more. A 1998 national commission proposed a framework sorting research into three categories of risk and benefit. An HHS working group studied the framework and looked instead, as a model, at the provision that establishes protections for children in research. A federal advisory committee drafted its own version. Then came a 2007 request for comment, and a federal advisory committee sent recommendations to the Secretary of HHS in July 2009. Those recommendations are advisory and do not become regulations unless adopted. Apart from a 2018 change in wording, they were not.
Nor is there anywhere for a subject to complain. Enforcement runs one direction: An institution certifies to a funding agency that its review board approved a study, and that agency can restrict the institution’s assurance or suspend its funding. Nothing in the rule establishes a complaint process for subjects or gives them a right to a decision. Courts have declined for over 20 years to read the rule as giving individual subjects a right to sue to enforce it. In the leading case, Wright v. Fred Hutchinson Cancer Research Center, a federal court reasoned that the rule’s provisions are phrased in terms of what institutions must do, rather than what subjects are owed, and are built to control aggregate behavior rather than to satisfy the needs of any particular person. A disabled subject who believes they were harmed because an institutional review board failed to properly review a study can use the institution’s own internal process or sue under state tort law.
The combined effects of inadequate guidance for regulators and review boards, and the lack of a subject-complaint mechanism, are visible in one study published this year. That study analyzed chat logs from 19 people who reported psychological harm from chatbot use. The study was funded by the U.S. National Science Foundation, whose version of the rule copies HHS’s text, including the undefined clause. The undefined clause appears word for word in the parallel provisions adopted by the U.S. Department of Homeland Security, the U.S. Consumer Product Safety Commission, Veterans Affairs, the Environmental Protection Agency, and AmeriCorps, so the gap in the rule affects research funded across the federal government.
How the study’s participants were obtained is disputed, and every account comes from the study and its own data partner. The published methods describe receiving logs through the Human Line Project, a peer support community, which had identifiers removed from the logs before the researchers reviewed them. That organization’s own published page on the study notes that 12 of the 19 participant datasets were provided by the Human Line Project. On a public recording, however, the Human Line Project’s founder, Etienne Brisson, said that the study did not get its transcripts through the organization, that the researchers recruited people from its community themselves, and that they paid those people directly. The methods and the organization’s own page agree. Its founder contradicts both.
Who supplied the data determines which regulatory standard applies. On the researchers’ account, the study used secondary material that an outside party assembled. On Brisson’s account, investigators recruited from a support community and paid people whose capacity may have been impaired at the time. If so, the study would qualify as primary human subjects research and be subject to the full weight of HHS’s requirement that the “selection of subjects is equitable” and that “additional safeguards” were provided to protect particularly vulnerable populations. A board reviewing a similar recruitment issue involving children would have the additional guidance from the child-specific provision of the rule to help evaluate that question. The board reviewing these subjects had only the instruction to include “additional safeguards,” with no definition of who needed them or what they required. The board resolved the question using a standard the government has spent 48 years declining to write, and no one outside that board can evaluate how that standard was applied.
Two changes would close the gap, and each answers a different question. HHS should define the population by adopting a definition and prescribed set of protections modeled after the similar provisions governing research on children, or else by implementing the definition it sketched in its 2007 notice so that a review board knows what standard it must apply and to whom. HHS should then build a complaint pathway with a duty to respond and a route past the institution that approved the study. Neither requires a new legal approach. The children-specific provision is the template for the first, and data protection statutes that require a complaint process before regulatory escalation are the template for the second. Disabled research subjects have had neither for nearly half a century.



