# SpectOcular Google Drive Pilot Intake SOP

## Purpose
This pilot workflow uses the website only to populate a printable packet. The official consent record is the wet-ink signed packet scanned into a BAA-covered Google Workspace / Google Drive environment.

## Required controls before storing PHI
1. Confirm Google Workspace BAA is signed and applies to the covered services used.
2. Require 2-Step Verification for every user with access to PHI.
3. Use a restricted Shared Drive or restricted folder; no public links.
4. Share folders and files only with named authorized users.
5. Keep the Master Linkage file separate from de-identified research exports.
6. Use no-PHI email notifications: Subject ID only, no patient name, DOB, MRN, or attachments.

## Folder structure
- SpectOcular Research - Secure Pilot Intake
  - 01_Uploaded Signed Packets
  - 02_Master Linkage Restricted
  - 03_Deidentified Exports

## Enrollment workflow
1. OD/staff opens Authorized Research Workflow.
2. Enter patient data and generate Study Subject ID.
3. Select medical release categories.
4. Print the populated packet.
5. Patient signs the SpectOcular Patient Services Consent, Medical Release, and Research Consent/HIPAA authorization where required.
6. Consentor/site staff signs where applicable.
7. Scan packet as PDF.
8. Upload scanned packet to the restricted Google Drive signed-packet folder.
9. Add/update a row in the Master Linkage sheet.
10. Send no-PHI notification to central SpectOcular personnel using Study Subject ID only.

## File naming
Use: SubjectID_YYYYMMDD_signed-packet.pdf
Example: 01-00001_20260626_signed-packet.pdf

## Master linkage
The Master Linkage sheet contains PHI. Access should be limited to central research personnel and authorized site staff who need linkage access. De-identified exports should use Study Subject ID only.
