Registry·Demo Registry ToolkitLive MonitorEcosystemLearnGuide Suggest a correction
Demonstration and educational project. Not medical, legal, or regulatory advice. Every participant, record, and organization shown is fictional or illustrative. Sample and template language must be reviewed and adapted with your own IRB and legal counsel before any real use. Not affiliated with, endorsed by, or representing any advocacy group, registry, company, or institution named.

Tab 1 · start here

Registry Toolkit

A planning aid for a community thinking about building a research registry. What a participant would experience, the reference material in one place, and two self-assessments that tell you where you actually are.

Where to start

A planning aid for a community thinking about building a research registry. It shows what a participant would experience, collects the reference material in one place, and gives you two self-assessments that tell you where you actually are rather than where you hope to be.

It is disease-agnostic on purpose. Nothing here assumes a particular condition, a particular platform, or a particular vendor. If you are forking this for a specific community, the places to add specificity are marked.

Read this before anything else

This is a demonstration. No page collects, stores, or transmits real participant data. Every record and person shown is fictional. Sample language is illustrative and has to be reviewed with your own IRB and legal counsel before it goes anywhere near a real participant.

Two different kinds of data, and the difference runs throughout

People arrive at this site for two different reasons, and the toolkit covers both. Almost every point of confusion in registry planning comes from mixing them up, so every section below is labelled.

Two different kinds of data

Survey & participant-reported data

What a person tells you directly: enrollment questions, survey modules, quality-of-life instruments, treatments they report taking. You design it, you own the instrument, and the person is the source.

Sometimes called patient-reported outcomes, or PROs.

Electronic health record (EHR) data

What clinicians recorded during care: diagnoses, medications, lab results, visits, clinical notes. You do not design it and you cannot change it. It arrives from a health system, and getting it is a separate project with its own cost, consent, and technical work.

Also called health records, clinical data, or real-world data.

Most registries need both, and they are not interchangeable. Survey data tells you what daily life is like and what someone believes happened. EHR data tells you what was documented, coded, and billed. Where they disagree, that disagreement is often the finding.

Where a section applies to only one of them, it carries a tag: Survey or EHR. Sections that apply to both carry Both.

The order that actually works

  1. Write the question. A registry is not a thing you have. It is an answer to a question you asked first. Groups that collect before deciding what the data must prove end up with datasets nobody can use for anything specific, including them.
  2. Inventory what you already hold. Most groups hold more than they think, and the gap is usually documentation rather than collection. The Asset & Evidence Map is an afternoon's work.
  3. Find your actual stage. Five tracks, five stages. The self-assessment tells you which track is blocking the others, which is rarely the one you were worried about.
  4. Learn what the pathways cost. There are several ways to get records, and they differ by orders of magnitude in cost and completeness. See Record acquisition pathways.
  5. Then talk to a platform or vendor. Not before. See Meeting a registry vendor.

What a participant sees Both

Everything below is illustrative. It exists so that a group evaluating platforms knows what to ask a vendor to demonstrate, and so that families can see what they would be agreeing to.

The flow

  1. Welcome and eligibility. Who the registry is for, who runs it, and what happens to the data. In plain language, before any account is created.
  2. Consent. The document, the plain-language summary, and, critically, the section describing future use and sharing. See the consent question.
  3. About the participant. Demographics, diagnosis, and how the diagnosis was made. Short. Every extra question here costs you completion.
  4. Survey modules. Survey Delivered over time rather than all at once. Typical modules: diagnostic history, symptom or event history, development and medical history, quality of life, treatments and supplements.
  5. Bring in the electronic health records. EHR Optional, separately consented, and the step most participants do not complete. Either a live connection to a health system or a download and upload. See EHR acquisition pathways.
  6. A dashboard back to the participant. What was received, what it says, and what the registry has learned. This is the part most registries skip and the part most participants remember.

The question to ask a vendor about this flow

Can results be returned to the participant? Families will ask you, and you want to know the answer before they do.

Survey design, briefly Survey

Two failure modes dominate. The first is asking everything at enrollment, which produces a long form, a high abandon rate, and a cohort biased toward the most motivated families. The second is writing your own instruments when validated ones exist, which produces data that cannot be compared to anything.

Where a validated instrument exists for what you want to measure, use it, even if it is imperfect. Where none exists, keep the question and flag it as locally developed in your data dictionary so downstream users know.

Record acquisition pathways

Five ways records reach a registry, roughly from least to most involved. Which one is right depends entirely on your use case, which is why the question comes first.

PathwayWhat you typically getBest used forCost and effort
Participant or caregiver portal download Portal-level notes and documents from each site they connect Confirming conditions, sketching the burden and the journey, learning what data types exist at all Free. You or a free tool do the analysis.
Vendor-mediated portal download Essentially the same portal-level data, combined across the sites the person connects The same, at more scale, with less manual effort per participant Paid, often bundled with surveys. You usually still analyze.
HIPAA authorization, third-party retrieval Much more comprehensive, multi-site records, often as PDFs A fuller picture including records outside the portal, when you can handle the volume and the noise Expensive. Comprehensive but harder to curate.
Clinician or therapeutic relationship access Higher-quality clinical data available to treating providers Rich collaborations with clinicians and academic centers Superior data, but you may not be allowed to co-own it.
Network exchange (TEFCA / individual access services) Records matched across participating providers via identity verification Broad reach in theory, as the networks mature Integration or platform cost. Identity verification and coverage gaps.

What survey data gives you that records never will

State this plainly, because groups sometimes treat EHR acquisition as the "real" data and surveys as a stopgap. It is not that simple.

Records will not tell you what daily life is like, what someone stopped taking and why, what they buy over the counter, what they tried that no clinician knows about, how long they waited for a diagnosis, or what outcome they would actually trade something for. None of that is documented in a clinical record, and much of it is exactly what a rare disease community can uniquely contribute.

Records will tell you what was diagnosed, coded, prescribed, measured, and billed, reliably, longitudinally, and in a form other researchers can combine with their own data.

A separate channel: recordings and imaging EHR

None of the pathways above reliably deliver the actual imaging studies or raw physiological recordings, only their reports. Those are requested separately from the imaging library and from whichever department holds the raw studies, each with its own form and its own phone number. Sometimes it is still physical media.

Find out early whether your question needs them. If it does, budget the time separately and do not assume any records vendor will produce them.

What a free download actually looks like

A caregiver portal download for a single person routinely produces hundreds of individual files. Parsed, they can surface documentation errors that have been carried forward for years, which is useful to know both as a research finding and as a reason participants may want their own copy.

The hard part is not the download. It is knowing which button to press: portals commonly offer to share with a provider, share with another person, or download everything, and those are three different actions producing three different results.

The consent question to ask this week

Pull your current consent form. Find the language about future use and sharing. Does it permit sharing with partners you have not yet named?

If it does not, everything you collect between now and an amendment is limited to what the current language allows. Re-consenting a community is far harder, slower, and more damaging to trust than getting the language right once.

What a governance package actually contains

"You will need a governance framework" sounds like a consulting engagement. It is really a set of documents, most of which have public templates you can adapt. Every one still needs your IRB and your lawyer, but you can arrive with drafts rather than a blank page.

DocumentWhat it does
Information for researchersA public page explaining how someone requests data and what happens next. This is the front door, and most groups do not have one.
Data use agreementThe terms a requester signs: what they may do, what they may not, what happens at project end, and who owns what comes out.
Data access committee SOPWho decides, how often they meet, how a request moves through. Three volunteers with a written process is a functioning committee.
Evaluation rubricWhat requests are scored against. This does more work than the roster, it is what makes decisions consistent and defensible.
IRB and ethics documentationProtocol, consent, and whether that consent permits future sharing.
Data dictionaryField-level documentation. Could an outsider understand your dataset from this alone? If not, it is not shareable yet.
Derived fields documentationHow computed variables were calculated. Undocumented derived fields are the most common reason a dataset cannot be reused.
Readiness assessmentAn honest inventory before you publish anything, the document that stops you announcing a portal you cannot staff.

Meeting a registry vendor Both

You may be buying two different things

A registry platform hosts your survey instruments, consent, and participant portal. An EHR records service retrieves clinical records from health systems. Some vendors sell one, some sell both, and the pricing questions are completely different, platform pricing is usually per participant or per seat, while records pricing is usually per retrieval.

Ask at the start of the call which one you are being quoted for. The vendor comparison worksheet separates them: sections 1 to 4 cover the platform, section 5 covers EHR data.

You will get more out of a vendor conversation if you ask the right things and hold reasonable expectations. None of this is adversarial, there is real, sometimes hidden cost on their side in project management and activation, and a vendor charging for that is charging for something. The goal is a number attached to a nameable unit of work.

On money, be specific EHR

These questions are about records retrieval pricing. For platform pricing, ask instead about per-participant or per-seat cost, what counts as an active participant, and what happens when enrollment grows.

  • What is the activation fee, separately from any per-unit fee?
  • Operationalize "per record" out loud: does one person seen at ten sites count as one record or ten? Does a failed retrieval attempt count?
  • Are there monthly fees? Is pricing tied to scale or to volume?
  • If you will pull a few dozen records a year and their pricing assumes tens of thousands of people, say so and ask whether there is a version scaled to you. There often is, but nobody offers it to a group that does not ask.

On stability and security

  • How long have you been in business?
  • What happens to our data if you go out of business or change your model? You do not want to be stranded holding a contract and no export.
  • Can you provide a completed HECVAT, the Higher Education Community Vendor Assessment Toolkit from EDUCAUSE? It is free, widely adopted, and covers cybersecurity, privacy, accessibility, and now AI use. Most established vendors have one. Hand it to someone with IT expertise.
  • Can we speak with two groups of roughly our size that you work with?

On governance

If it seems too complicated for you, it probably is. If you cannot tell what is expected of you legally, that is a signal, and you need a lawyer to review it regardless. This space has some fly-by-night operators, and a governance problem found afterward is far worse than a slow contract review.

Ask for a demonstration

Ask them to walk you through a test patient. You do not need a real person. Show me what a pull looks like, what the output file is, what the participant sees, and whether results can be returned to them.

A pilot with real participants across several vendors can work, but it burdens families and requires IRB approval, so a test patient is usually the better first step.

Do not ask for this

Do not ask a vendor to guarantee they will find every mention of a device or a symptom in a narrative note. Detailed extraction from free text is usually outside their scope, and a vendor who promises completeness there is the one to worry about. Ask instead what is reliably populated.

Will anyone actually use it?

The hardest part of a registry is not building it. It is whether it survives the launch, the grant, and the founder.

The one idea, if you take nothing else

Implementation science calls this maintenance, and it is reliably the hardest dimension for small organizations to hold. That is why sustainability sits at the top of the maturity model rather than the bottom.

Three frameworks useful to know

FrameworkWhat it gives youUse it when
RE-AIMReach, Effectiveness, Adoption, Implementation, Maintenance, a planning checklist that forces you to name who you will actually reach and whether the work will lastAt the planning stage, before you commit to a design
CFIRA map of the factors that determine whether people engage, the intervention itself, the setting, the individuals, and the processWhen enrollment or clinician participation is lower than expected and you need to know why
PARIHSThe insight that even good evidence needs a facilitator, a named person whose job is to make adoption happenWhen you have the evidence and the tool and it still is not being used

The six-month test

If the person who started this stepped away in six months, what would still be running? The platform, probably. Enrollment, maybe. The relationships, the governance rationale, and the institutional knowledge walk out the door.

Three things to write down before you need them: why you chose this vendor over the others; what your consent does and does not permit, in one paragraph a board member can read; and what you would do with the data if the grant ended tomorrow.

Research readiness maturity model

Most landscapes describe what exists. This one describes a path. Every community moves, at its own pace, from an informal group toward sharing standardized data that outlives any single organization. This model names the stages, so a group can see where it stands, where it is ahead, and where it is behind. It is populated by self-assessment, never assigned from outside.

The five stages

StageMeaning
1 · EmergingAn informal community exists. No legal or research infrastructure.
2 · OrganizedIncorporated and governed. Beginning to think about research.
3 · ConnectedPlugged into the broader research ecosystem. Collecting structured information.
4 · Data GeneratingOperating a registry or natural history infrastructure. Producing data with intent.
5 · Data SharingContributing standardized, documented data or metadata for use beyond the organization.

The rule that catches everyone

Your composite stage is roughly the lowest stage you have reliably reached, not the highest. You cannot be Data Sharing if you have no governance. A group running a registry with excellent longitudinal data, no consent framework, and no data dictionary is not a stage 4 organization. It is a stage 1 organization holding a liability.

The five tracks

Each track runs through the same five stages. Reading across a track shows what good looks like one step ahead.

Track12345
Organizational FoundationInformal communityUnincorporated associationIncorporated nonprofitStaffed and resourcedSustainable
Scientific and Community EngagementPeer supportAwareness and educationConveningResearch participationNamed partner
Ecosystem IntegrationIsolatedAwareConnectedActive in shared infrastructureShaping the ecosystem
Data InfrastructureNo structured dataContact registryParticipant-reported registryNatural history and longitudinalHarmonized to standards
Data Governance and Sharing
the north star
No governanceInternal governanceDocumented and standardizedShared with a partnerOpen and broadly accessible

Maturity self-assessment

Select the highest step your organization has reliably reached on each track, not the one you are working toward, and not the one you reached once. Nothing is saved or sent anywhere. About ten minutes.

Asset & evidence map Both

Before choosing what to build next, map what you already hold against the evidence you want to produce. Every column is a data asset. Every row is a question your program is trying to answer. The empty and unknown cells are your roadmap.

Marks stay in your browser and are not saved or sent anywhere. Use Export CSV to keep a copy.

The default columns deliberately include both streams, survey data and EHR data are separate assets that answer different questions, and a map that merges them hides your real gaps. There is a fuller version of this worksheet, with a filled-in example, in Tools & downloads.

Assets people forget they hold

Conference abstracts and posters. Meeting minutes recording what families reported. Email threads with clinicians. A community group's pinned documents. Past survey exports sitting in someone's downloads folder. Newsletters. None of these are research-grade on their own; several are evidence that a question is asking.

Where to get help

"Where to get help" means the wider ecosystem, not any single organization, peer groups, rare disease and condition-specific networks, technical and data partners, and pro bono experts. What is available differs by stage.

If you are atThe kind of help that tends to exist
Stage 1–2Plain-language orientation on nonprofit formation. Pro bono legal services for incorporation and bylaws. Governance templates. Introductions to founders who have made the leap.
Stage 2–3Strategic planning facilitation. Grant writing support. Advice on consent for re-contact. Help selecting a registry platform, if you decide you want one.
Stage 3–4Instrument design and validation. Recruitment and retention strategy. Biostatistics consultation. Natural history study design. Clinical data management.
Stage 4–5Data harmonization. Common data element mapping. Informatics support. Drafting data sharing and use agreements. Setting up a data access committee.
Stage 5Making data FAIR. Deposit into recognized repositories. Publishing discoverable metadata even when raw data stays controlled. Succession and governance maturity review.