Our Commitment to Protecting Personal Information
Market Decisions Research (MDR) conducts survey research, in-depth interviews, focus groups, data analysis, and program evaluations for government agencies, health systems, nonprofits, and businesses. Participants entrust us with information about their health, households, experiences, and opinions, while clients rely on us to manage confidential data responsibly. Protecting this information is central to our work.
This statement explains how we collect, use, protect, retain, and destroy personally identifiable information (PII) when conducting research on behalf of our clients.
What We Collect and Why
Depending on the project, we may collect or receive personal identifiers such as names, addresses, phone numbers, email addresses, and dates of birth, along with information participants provide through surveys, interviews, or other research activities. This may include sensitive information about health conditions, health care experiences, insurance coverage, public program participation, health behaviors, and related topics.
MDR classifies PII as confidential information, our most restricted category of data. We use this information only for the purposes of conducting the research a client has commissioned. We do not sell personal information, we do not use it to market products or services to participants, and we do not share it outside the project team unless required by contract or law.
In many cases, personal information is provided to MDR by the client rather than directly by participants. For example, government agencies, health plans, and other organizations may provide lists of members, patients, beneficiaries, or program participants so we can contact the appropriate population for a study. This information remains the property of the client and is maintained under the terms of a contract or data use agreement.
Before any project begins, we review the privacy, security, and compliance requirements that apply to the data so that appropriate safeguards are in place from the start. In some cases, sample information may also be obtained from approved sample providers such as Marketing Systems Group, which utilizes addresses from the United States Postal Service Computerized Delivery Sequence File (CDSF).
Who Can Access It
Access to confidential information is granted only to employees whose work requires it.
Participant information is stored in restricted locations accessible only to authorized project team members. Access is granted for the duration of the project and is removed when the project closes or is no longer needed. Files used for analysis are separated from files containing direct identifiers whenever possible.
Access permissions are reviewed periodically to ensure they remain appropriate and consistent with project responsibilities. When an employee leaves MDR, access to company systems and confidential information is revoked promptly through a documented offboarding process.
All employees who handle confidential information are required to sign an acceptable use agreement and participate in information security training during onboarding. Employees also receive ongoing security awareness education through regular communications, training activities, and phishing simulations.
How We Protect It
We use administrative, physical, and technical safeguards to protect the information entrusted to us.
Data is protected in transit and at rest through encryption, multifactor authentication, and continuous security monitoring. Access to company systems requires authentication, and company devices are protected by full-disk encryption. Network environments are logically separated and protected by managed security controls, and endpoints are continuously monitored for malicious activity.
We also prioritize physical security. Our offices are secured through individually issued and tracked keys, controlled building access, security cameras, alarm systems, and on-site security personnel during business hours. Areas containing server infrastructure or other sensitive equipment are restricted to authorized personnel.
How Long We Keep Data and How We Destroy It
MDR retains data only for as long as required by the governing contract, data use agreement, or applicable legal requirements. Retention and destruction expectations are established with clients at the beginning of each project.
When data reaches the end of its retention period, destruction follows documented procedures designed to prevent recovery or unauthorized access. Electronic storage media and technology assets are securely sanitized before disposal. Disposal is performed by approved destruction vendors, and certificates of destruction or sanitization are retained as required by policy.
Where projects involve paper records, including questionnaires, consent forms, or interview notes, those materials are securely destroyed in accordance with project requirements and applicable contractual obligations.
When a client requires written certification that project data has been destroyed, MDR provides documentation confirming completion of the process.
Governance and Standards
MDR’s information security program is aligned with Version 2.0 of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
A designated Information Security Officer oversees the program and reviews it regularly with senior leadership. Security policies and procedures are reviewed at least annually and updated as needed to address changes in technology, regulations, business operations, and client requirements.
The same expectations extend to our vendors. Vendors are inventoried, evaluated according to risk, and assigned an internal owner responsible for oversight. Vendor relationships involving technology or confidential information are reviewed as part of our information security program.
MDR is a member of the American Association for Public Opinion Research (AAPOR) and the Qualitative Research Consultants Association (QRCA), and we conduct our work in accordance with their professional standards and ethical guidelines.
If Something Goes Wrong
MDR maintains documented incident response and business continuity procedures. These procedures are reviewed regularly and tested through periodic tabletop exercises.
Employees are required to report suspected security incidents promptly. Our information security officer coordinates the response, investigation, documentation, and communication process, including engagement with external security partners and other advisors when appropriate.
If a security incident affects client data, we notify affected clients in accordance with contractual, legal, and regulatory requirements.
Participant Choice
Participation in MDR research is always voluntary. Participants may decline to answer any question or stop participating at any time.
Questions
If you have questions about how your information is handled, would like to be removed from a contact list, or wish to raise a concern about privacy or security, please contact us at research@marketdecisions.com