36C77620Q0042-014.pdf

PDF Posted

Attached to
R408--National Data Systems (NDS) Federal contract opportunity
Solicitation number
36C77620Q0042
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This document is a data use agreement template between the Department of Veterans Affairs Veterans Health Administration and an external data requestor. The agreement outlines terms for sharing a limited data set containing protected health information from VA patients to support analyses by the data requestor of veterans' health outcomes. Key details include specifying that 15 data elements would be removed from health records to de-identify patients before sharing. The data requestor must establish security safeguards to protect the confidentiality of records and notify VA of any data breaches. Permitted uses are limited to the pre-approved analysis purpose. The agreement may be terminated by either party with 30 days' notice, at which point the data requestor must destroy or return all protected health information received from VA.

36C77620Q0042 S02 - Attachment F DUA template LDS Federal.pdf

View the file

Other files for this federal contract opportunity

Other files attached to R408--National Data Systems (NDS), newest first.
File Type Posted
36C77620Q0042-0001000.docx DOCX document
36C77620Q0042-017.pdf PDF
36C77620Q0042-016.pdf PDF
36C77620Q0042-013.pdf PDF
36C77620Q0042-012.pdf PDF
36C77620Q0042-010.pdf PDF
36C77620Q0042-019.pdf PDF
36C77620Q0042-008.pdf PDF
36C77620Q0042-018.pdf PDF
36C77620Q0042-009.pdf PDF
36C77620Q0042-015.pdf PDF
36C77620Q0042-011.pdf PDF
36C77620Q0042-007.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DATA USE AGREEMENT FOR A LIMITED DATA SET WITH FEDERAL ENTITIES

AGREEMENT FOR DATA EXCHANGE BETWEEN VETERANS HEALTH

ADMINISTRATION (VHA), <INSERT FACILITY OR PROGRAM OFFICE NAME>

AND <INSERT FEDERAL ENTITY NAME>

This Data Use Agreement (Agreement) is entered into as of this ____ day of _____, <INSERT YEAR>, by and between the Department of Veterans Affairs (VA) Veterans Health Administration (VHA), <INSERT FACILITY OR PROGRAM OFFICE NAME> (”Covered Entity”), and <INSERT FEDERAL ENTITY NAME> (“Data Requestor”).

WHEREAS, the Covered Entity and the Data Requestor are committed to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations of Title 45 Code of Federal Regulations (CFR) Parts 160 and 164 (“HIPAA Privacy Rule”); and

WHEREAS, the purpose of this Agreement is to satisfy the obligations of the Covered Entity under the HIPAA Privacy Rule, and to ensure the integrity and confidentiality of the limited data set (LDS) disclosed by the Covered Entity to the Data Requestor under this Agreement (“Data”) in the form of a Limited Data Set, as defined by the HIPAA Privacy Rule at 45 CFR § 164.514(e); and

WHEREAS, the parties acknowledge and recognize that the Data will not be disclosed to the Data Requestor until the parties execute this Agreement pursuant to 45 CFR § 164.514(e)(4)(ii).

TERMS OF THE AGREEMENT:

1. All provisions of this Agreement that apply to the Data Requestor also apply to any employee, contractor, subcontractor, or other agent of the Data Requestor. The Data Requestor will ensure that its employees, contractors, subcontractors and other agents to whom it provides the Limited Data set abide by the terms and conditions of this Agreement. The Covered Entity may request verification of compliance.

2. The Data Requestor will use the Data provided by the Covered Entity under this Agreement to <PROVIDE BRIEF DESCRIPTION OF PROJECT INCLUDING TYPE OF DATA AND HOW IT WILL BE USED>. The specific VHA data-elements being provided to the Data Requestor to support these analyses, and specific data elements to be excluded from the limited data set are listed in Attachment A.

3. For the purpose described in paragraph 2, the Covered Entity will provide the Data Requestor with a Limited Data Set for <SELECT ONE – public health, research or health care operations>, defined by the HIPAA Privacy Rule as Protected Health Information (PHI) from which the following direct identifiers of the individual have been removed: names, addresses (other than town or city, state, or zip code), phone numbers, fax numbers, e-mail addresses, Social Security Numbers, medical record numbers, health plan numbers, account numbers, certificate and/or license numbers, vehicle identifiers or serial numbers, device identifiers or serial numbers, web universal resource locators, internet protocol address numbers, biometric identifiers, and full-face photographic images and any comparable images. The Covered Entity and the Data Requestor acknowledge and affirm that a Limited Data Set does not meet the standard for de-identified information as provided by the HIPAA Privacy Rule and is therefore still subject to its requirements.

4. The following named individuals are designated as their agency’s Point-of-Contact (POC) for performance of the terms of the Agreement. The Data Requestor agrees to notify the Covered Entity within fifteen (15) calendar days of any change in the named contact.

Point-of-Contact on behalf of <INSERT NAME OF FEDERAL ENTITY>:

<INSERT NAME, PHONE NUMBER AND EMAIL OF FEDERAL ENTITY POC>

Point-of-Contact on behalf of VHA:

<INSERT NAME, PHONE NUMBER AND EMAIL OF VHA POC>

5. Although <INSERT NAME OF FEDERAL ENTITY> will own the copy of VHA LDS transferred under this Agreement, it agrees not to disclose the VHA LDS to any person outside the <INSERT NAME OF FEDERAL ENTITY> except pursuant to a Freedom of Information Act (FOIA) request, as authorized by Federal statute or regulation, or pursuant to a court order from a court of competent jurisdiction.

6. [TO BE MODIFIED FOR SPECIFIC AGREEMENT] The parties mutually agree that any derivative data, analyses, or findings created from the Data may be retained by the Data Requestor. The Data Requestor agrees to share any findings or outcomes from the analysis of the Data with the Covered Entity at no charge and with no conditions.

7. The Data Requestor agrees that it will not identify, contact, or attempt to identify or contact the individuals whose information is contained in the Data. The Data Requestor also agrees that it will not link or attempt to link the Data with other data sources for such purposes.

8. The Data Requestor shall establish appropriate administrative, technical, procedural, and physical safeguards in accordance with the common information security laws and regulations, such as the Federal Information Security Management Act (FISMA) and Federal Information Processing Standards (FIPS), to protect the Data confidentiality and to prevent unauthorized access to, or use or disclosure of, the Data.

(a) Data will be <INSERT MEANS OF SECURE TRANSMISSION OF DATA> by the Covered Entity to <INSERT FEDERAL ENTITY POINT OF CONTACT> at <INSERT

FEDERAL ENTITY NAME AND ADDRESS>.

10. If a Data Requestor’s employee, contractor, subcontractor, or agent becomes aware of the theft, loss, or compromise of any device used to transport, access, or store the Data, or of the theft, loss, or other unauthorized access, use, or disclosure of any of the Data, such employee, contractor, subcontractor, or agent must immediately report the incident to his or her supervisor. Should any security incident or event involve the Data (i.e. the theft, loss, or other unauthorized access, use, or disclosure of any of the Covered Entity’s data or the destruction of any device used to transport, access, or store such data), the Data Requestor will notify the VHA POC along with VA OI&T Information Security Officer (ISO) by phone or in writing within one (1) hour of detection. The VHA POC will contact VHA’s Privacy Officer. The Data Requestor will provide details of the security event, the potential risk to the individuals whose information is contained in the Data, and the actions that have been or are being taken by the Data Requestor to remediate the incident or event. The Data Requestor will also provide the Covered Entity with status updates upon request and a written closing action report once the security event or incident has been resolved.

11. Access to the Data shall be restricted to authorized employees, contractors, subcontractor, and agents of the Data Requestor requiring access to perform their official duties related to <SELECT ONE – public health, research or health care operations> as authorized by this Agreement. The Data Requestor shall inform such personnel of: (1) the confidential nature of the information; (2) safeguards required to protect the information; (3) the administrative, civil, and criminal penalties for noncompliance contained in applicable Federal laws; and (4) that their actions can lead to the immediate termination of this Agreement by the Covered Entity. The Data Requestor agrees to limit access to, disclosure of, and use of Data provided under this Agreement to the minimum number of individuals needing access to the data provided by the Covered Entity to perform their duties as authorized by this Agreement.

12. In the event that the Covered Entity suspects or determines that the Data Requestor accessed, used, or disclosed any part of the Data other than as authorized by this Agreement or other written authorization from the person designated in Paragraph 4 of this Agreement, or as required by law, the Covered Entity in its sole discretion may require the Data Requestor to:

(a) Promptly investigate and report to the Covered Entity the Data Requestor’s determinations regarding any alleged or actual unauthorized use or disclosure;

(b) Promptly resolve any problems identified by the investigation; and

(c) Submit a formal response to an allegation of unauthorized disclosure.

Further, if the Covered Entity suspects or determines that the Data in the possession of the Data Requestor has been accessed, used, or disclosed other than as authorized by this Agreement, the Covered Entity in its sole discretion may suspend further releases of the data to the Data Requestor or may terminate this Agreement in its entirety.

13. The Data Requestor hereby acknowledges that criminal penalties under § 1106(a) of the Social Security Act (42 U.S.C. § 1306(a)), including a fin imprisonment not exceeding 5 years, or both, may apply to disclosures of information covered by §1106 and not authorized by regulation or by Federal law. Finally, the Data Requestor acknowledges that criminal penalties may be imposed under 18 U.S.C. § 641 if it is determined that the Data Requestor, or any individual employed or affiliated therewith, embezzles, steals, purloins, or knowingly converts to his use or the use of another, or without authority, sells, conveys, or disposes of any Data provided under this Agreement.

14. This Agreement may be terminated by either party at any time for any reason upon 30 days written notice. Once this Agreement is terminated, the Data Requestor has no legal authority to access, use, disclose, or retain the Data. Upon receipt of the Notice of Termination of the Agreement, the Data Requestor within 15 days must, at its own expense, destroy or return the limited data set. The Media Destruction guidance can be found at the NSA site:

http://www.nsa.gov/ia/mitigation_guidance/media_destruction_guidance/index.shtml. If the Data Requestor chooses to destroy the Data, a Certificate of Destruction signed by the Security point of contact (POC) and the agency approving official must be provided to the VHA POC listed in Paragraph 4.

15. All questions of interpretation or compliance with the terms of this Agreement should be referred to the Covered Entity’s official named in Paragraph 4 (or his or her successor).

16. Authority for the Covered Entity to disclose this data to the Data Requestor for the purpose indicated is provided by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule, 45 CFR 164.514(e). The Privacy Act and 38 USC §§ 5701 and 7332 do not apply, as a Limited Data Set is not considered individually identifiable under these statutes.

17. This Agreement supersedes any and all previous agreements related to this project. The terms of this Agreement can only be changed by written modification to this Agreement or adoption of a new agreement in place of this Agreement.

18. On behalf of both parties, the undersigned individuals hereby attest that he or she is authorized to enter into this Agreement and agrees to all of the terms specified herein.

<INSERT NAME OF FEDERAL ENTITY SIGNER> Date

<INSERT TITLE OF FEDERAL ENTITY SIGNER>

<INSERT PROGRAM OFFICE OF FEDERAL ENTITY>

<INSERT NAME OF FEDERAL ENTITY>

<INSERT NAME OF VHA SIGNER> Date

<INSERT TITLE OF VHA SIGNER>

http://www.nsa.gov/ia/mitigation_guidance/media_destruction_guidance/index.shtml

<INSERT VHA PROGRAM OFFICE>

Veterans Health Administration

Concur/Non-Concur:

<INSERT NAME OF VHA PROGRAM OFFICE ISO>

Signature and Date

Concur/Non-Concur:

<INSERT NAME OF VHA PROGRAM OFFICE PRIVACY OFFICER>

Signature and Date

ATTACHMENT A

DATA ELEMENTS TO BE PROVIDED TO <INSERT NON-FEDERAL ENTITY

NAME> FOR < PROVIDE BRIEF DESCRIPTION OF PROJECT>

The following identifiers must be removed from health information if the data are to qualify as a limited data set:

1. Names

2. Postal address information, other than town or city, state and Zip Code

3. Telephone Numbers

4. Fax numbers

5. Electronic mail addresses

6. Social security numbers

7. Medical record numbers

8. Health plan beneficiary numbers

9. Account numbers

10. Certificate/license numbers

11. Vehicle identifiers and serial numbers, including license plate numbers

12. Device identifiers and serial numbers

13. Web universal resource locators (URLs)

14. Internet protocol (IP) address numbers

15. Biometric identifiers, including fingerprints and voiceprints

16. Full-face photographic images and any comparable images

Note: The above data elements apply to the individual, the individual’s relatives, employer, and household members.

<INSERT LIST OF DATA ELEMENTS TO BE PROVIDED>

DATA USE AGREEMENT FOR A LIMITED DATA SET WITH FEDERAL ENTITIES

File details come from the government source that posted it. Updated .