Under HIPAA, researchers must obtain authorization from study participants before collecting their PHI, unless the data collection qualifies for an exemption or waiver. This generally involves securing informed consent where participants are made aware of how their data will be used. Additionally, data must be de-identified wherever possible to protect the identity of individuals.