When a data use agreement is required
Under the HIPAA Privacy Rule a covered entity may disclose a limited data set to a recipient only for research, public health, or health care operations, and only after obtaining satisfactory assurance in the form of a data use agreement. That is 45 CFR 164.514(e)(1) and (e)(3).
This matters for scoping. A DUA is not the right instrument for a use outside those three purposes, and it is not required at all for data de-identified under Safe Harbor or expert determination, because such data is no longer protected health information. A limited data set is still PHI. That is the whole reason the agreement exists.
The seven required terms
Below is each required term with its citation and the operational check it makes possible. Use it to audit a sample DUA you have been sent, or to confirm your own template is complete before it goes to counsel.
| Citation | Required term | What a reviewer checks on each release |
|---|---|---|
| 164.514(e)(4)(ii)(A) | Establish the permitted uses and disclosures of the information by the recipient, consistent with research, public health, or health care operations | Does the purpose stated on this request fall inside the permitted uses, and is that purpose one of the three allowed categories |
| 164.514(e)(4)(ii)(B) | Establish who is permitted to use or receive the limited data set | Is every named user on this release inside the permitted set |
| 164.514(e)(4)(ii)(C)(1) | The recipient will not use or further disclose the information other than as permitted by the agreement or as otherwise required by law | Does the stated redisclosure intent exceed the agreement, and is any onward transfer proposed |
| 164.514(e)(4)(ii)(C)(2) | The recipient will use appropriate safeguards to prevent use or disclosure other than as provided for by the agreement | Is the proposed environment and transfer method the one the safeguards clause names |
| 164.514(e)(4)(ii)(C)(3) | The recipient will report to the covered entity any use or disclosure not provided for by the agreement of which it becomes aware | Is there an open unreported incident, and is the notification contact current |
| 164.514(e)(4)(ii)(C)(4) | The recipient will ensure that any agents, including subcontractors, agree to the same restrictions and conditions | Is a subcontractor or downstream processor in scope for this release, and is it bound |
| 164.514(e)(4)(ii)(C)(5) | The recipient will not identify the information or contact the individuals | Does the proposed analysis include re-identification, linkage that enables it, or participant contact |
What the agreement must also handle when it is breached
45 CFR 164.514(e)(4)(iii) places an obligation on the covered entity, not the recipient. If the covered entity knows of a pattern of activity or practice that constitutes a material breach of the agreement, it must take reasonable steps to cure the breach or end the violation. If those steps fail, it must discontinue disclosure of protected health information to the recipient, and if that is not feasible, report the problem to the Secretary of HHS.
Operationally this means the disclosing side needs a record of what was released to whom under which agreement version. A DUA with no release log leaves the covered entity unable to perform its own regulatory duty.
Reading a data use agreement sample critically
Published samples from universities, NIH repositories, and state agencies are good starting documents, and they are the sources that actually rank for this search. Check any sample against these five questions before adopting it.
- Does it name the permitted purpose specifically, or does it say "research" and stop
- Does it identify users by name or by an exhibit that is maintained, or only by role
- Does it attach a field list, so that the limited data set actually has a definition
- Does it state an access end date and a maximum retention period, with destruction evidence
- Does it contain all five recipient undertakings at (C)(1) through (C)(5), not three or four of them
From sample document to enforced control
Every term in the table above is checkable, which is unusual for an agreement clause and is why HIPAA DUAs are a good place to start operationalizing agreements at all. Each term maps to a value: a purpose, a user list, a redisclosure flag, an environment, a contact, a subcontractor list, and a re-identification prohibition.
Audarel records those values as reviewer-confirmed controls carrying the clause citation, then evaluates each proposed release against them and preserves the decision, approvals, exceptions, and artifact hashes. See the data sharing agreement template for the general non-HIPAA clause set, and the limited data set identifier reference for what the dataset itself may contain.
Keep decisions human and evidence explicit.
Practical guidance that connects policy documents to observable release controls.
Confirm requirements against current source material.
Requirements and vendor capabilities change. Confirm the current source and your approved QC plan before changing a production process.