Skip to main content
Category: De-identification and PHI Types

Data Use Agreement

Also known as: DUA, Data Use Agreement (DUA)
Simply put

A Data Use Agreement (DUA) is a legally binding contract that governs how certain restricted data may be shared and used between the entity that controls the data and another party receiving it. In the HIPAA context, it is the mechanism a covered entity uses to permit the sharing of a limited data set while setting out who may use or receive the information and for what purposes. It generally must be in place before any such data is disclosed to an outside party.

Formal definition

Under the HIPAA Privacy Rule, a Data Use Agreement is the contractual instrument that a covered entity (or its business associate) must enter into before disclosing a limited data set (LDS) to a recipient. The agreement establishes who is permitted to use and receive the LDS and specifies the permitted uses and disclosures of the information by the recipient, typically limited to research, public health, or health care operations purposes. A limited data set is PHI from which specified direct identifiers have been removed, but it is not de-identified data, so the LDS remains PHI subject to the Privacy Rule; the DUA is what makes its disclosure permissible. The DUA should be established prior to any use or disclosure of the LDS to an outside institution or party. Note that a DUA is distinct from a business associate agreement, which governs a different set of relationships and obligations, and that state law, the HITECH Act, or institutional and research policies may impose additional requirements. The specific required content and identifier removal criteria should be verified against the current regulatory text.

Why it matters

A limited data set is not de-identified data. Even after specified direct identifiers are removed, an LDS remains protected health information subject to the HIPAA Privacy Rule. The Data Use Agreement is the specific mechanism that makes disclosing that still-protected information permissible. Without an executed DUA in place, a covered entity that shares a limited data set may be making an impermissible disclosure of PHI, which is why the agreement is not a formality but a compliance prerequisite.

The DUA also functions as a control on downstream conduct. By establishing who may use and receive the limited data set and constraining the permitted uses and disclosures, it limits the scope of how the recipient may handle the information, typically confining it to research, public health, or health care operations purposes. This contractual boundary is what allows a covered entity to extend the reach of PHI beyond its own walls while retaining an accountable, enforceable relationship with the recipient.

Because an LDS still carries privacy risk, timing matters: the agreement should generally be established before any use or disclosure to an outside institution or party occurs. Relying on a DUA does not by itself guarantee compliance, and state law, the HITECH Act, or institutional and research policies may impose additional requirements beyond the Privacy Rule's baseline. Readers should confirm the specific required content and identifier-removal criteria against the current regulatory text.

Who it's relevant to

Privacy Officers at Covered Entities
Privacy officers are typically responsible for ensuring a compliant DUA is executed before a limited data set is disclosed. They should confirm the agreement identifies who may use or receive the LDS and restricts permitted uses, and should not treat an LDS as de-identified data exempt from the Privacy Rule.
Research and Sponsored Programs Offices
Because limited data sets are frequently shared for research purposes, research administration and sponsored programs staff often negotiate and manage DUAs. They should ensure the agreement is in place before any transfer to an outside institution and account for institutional or research policies that may add requirements beyond HIPAA.
Recipients of Limited Data Sets
Parties receiving an LDS are contractually bound by the permitted uses and disclosures set out in the DUA. They should understand that the data remains PHI and that their handling of it is constrained to the purposes the agreement specifies, generally research, public health, or health care operations.
Legal and Contracts Teams
Attorneys and contract managers drafting or reviewing DUAs should distinguish them from business associate agreements, which govern different relationships and obligations. They should also flag where state law, the HITECH Act, or other frameworks may impose additional requirements and verify content specifics against current regulatory text.

Inside DUA

Permitted Uses and Disclosures
A specification of the limited purposes for which the recipient may use or disclose the limited data set, which under the HIPAA Privacy Rule are generally restricted to research, public health, or health care operations.
Recipient Obligations
Provisions requiring the recipient to use or disclose the limited data set only as permitted by the agreement or as required by law, and not in a manner that would violate the Privacy Rule if done by the covered entity.
Prohibition on Re-Identification and Contact
A term requiring the recipient to agree not to identify the information or contact the individuals who are the subjects of the data.
Safeguards Requirement
A commitment by the recipient to use appropriate safeguards to prevent uses or disclosures of the limited data set other than those provided for in the agreement.
Reporting of Improper Uses
An obligation for the recipient to report to the covered entity any use or disclosure of the information not provided for by the agreement of which the recipient becomes aware.
Flow-Down to Agents and Subcontractors
A requirement that the recipient ensure any agents, including subcontractors, to whom it provides the limited data set agree to the same restrictions and conditions that apply to the recipient.
Limited Data Set Definition
The agreement applies specifically to a limited data set, which is PHI from which certain direct identifiers have been removed but which is not fully de-identified and therefore remains protected under the Privacy Rule.

Common questions

Answers to the questions practitioners most commonly ask about DUA.

Is a Data Use Agreement the same thing as a Business Associate Agreement?
No. Although both are contractual instruments used under the HIPAA Privacy Rule, they serve different purposes and apply in different situations. A Data Use Agreement (DUA) is generally required when a covered entity discloses a limited data set to a recipient for research, public health, or health care operations. A Business Associate Agreement (BAA) applies when a person or entity creates, receives, maintains, or transmits protected health information on behalf of a covered entity to perform a covered function or service. The two are not interchangeable, and the presence of one does not satisfy the requirement for the other. Readers should verify the specific circumstances against the current regulatory text, because a given relationship may require a BAA, a DUA, or both.
Does a Data Use Agreement mean the data being shared is fully de-identified and therefore outside HIPAA?
No. A DUA is used with a limited data set, which is not the same as de-identified data. A limited data set still contains certain direct or indirect identifiers that a fully de-identified data set would have removed, and it therefore generally remains PHI subject to the HIPAA Privacy Rule. Because it is still PHI, its use and disclosure remain restricted, which is precisely why a DUA is required to establish the permitted uses and safeguards. De-identified data, by contrast, is generally not subject to the Privacy Rule and does not require a DUA. Treating a limited data set as if it were de-identified is a common and consequential error.
Who is typically responsible for putting a Data Use Agreement in place before data is shared?
The covered entity disclosing the limited data set is generally responsible for obtaining satisfactory assurances, through a DUA, that the recipient will use and disclose the data only for permitted purposes. In practice, this obligation is often coordinated by privacy officers, research compliance offices, or legal counsel within the disclosing organization. The DUA should be executed before the limited data set is disclosed. Organizations should confirm their internal roles and the specific regulatory requirements against current guidance.
What terms should a Data Use Agreement typically include?
A DUA generally establishes the permitted uses and disclosures of the limited data set, identifies who may use or receive the data, and requires the recipient to implement appropriate safeguards to prevent uses or disclosures not permitted by the agreement. It typically also requires the recipient to hold agents and subcontractors to the same restrictions, to report improper uses or disclosures it becomes aware of, and to refrain from attempting to identify or contact the individuals. The exact required elements should be confirmed against the current text of the HIPAA Privacy Rule, and organizations should be aware that state law or other frameworks may impose additional terms.
How does a Data Use Agreement fit into a broader HIPAA compliance program?
A DUA is one contractual control that supports permissible disclosures of limited data sets, but it does not by itself constitute a complete compliance program. It typically works alongside policies governing minimum necessary use, access controls, workforce training, and, where applicable, Security Rule safeguards for any electronic protected health information involved. A DUA addresses the terms of a specific disclosure and generally does not substitute for the disclosing entity's broader Privacy Rule and, where relevant, Security Rule obligations. Note also that frameworks such as the HITRUST CSF may be used to help operationalize controls, but adherence to any such framework does not by itself establish HIPAA compliance.
What should an organization do if a recipient breaches the terms of a Data Use Agreement?
When a covered entity becomes aware of a pattern of activity or practice by the recipient that constitutes a material breach or violation of the DUA, it is generally expected to take reasonable steps to cure the breach or end the violation, and, if such steps are unsuccessful, to discontinue the disclosure and, as applicable, report the problem. The specific steps and any reporting obligations should be confirmed against the current regulatory text, and organizations should also assess whether the incident triggers separate obligations under the Breach Notification Rule, the HITECH Act, or applicable state law, which may impose additional requirements.

Common misconceptions

A Data Use Agreement is the same thing as a Business Associate Agreement (BAA).
These are distinct instruments under the HIPAA Privacy Rule. A Data Use Agreement governs the sharing of a limited data set for research, public health, or health care operations, while a BAA governs a business associate performing functions or services on behalf of a covered entity. The obligations, triggering relationships, and scope differ, and readers should confirm which instrument applies to a given arrangement.
A limited data set shared under a Data Use Agreement is de-identified and therefore no longer protected.
A limited data set is not de-identified. It has certain direct identifiers removed but may retain elements such as dates and some geographic detail, so it generally remains PHI subject to the Privacy Rule. Only information meeting the Privacy Rule's de-identification standard falls outside protection.
A Data Use Agreement covers all forms of data sharing and satisfies every applicable legal requirement.
A Data Use Agreement addresses the Privacy Rule's conditions for disclosing a limited data set and does not by itself address Security Rule safeguards for ePHI, state law requirements, HITECH provisions, or contractual arrangements outside its scope. Practitioners should evaluate whether additional agreements or controls are needed.

Best practices

Confirm that the data being shared actually qualifies as a limited data set by verifying that the required direct identifiers have been removed before relying on a Data Use Agreement.
Clearly enumerate the permitted uses and disclosures, generally limited to research, public health, or health care operations, and avoid overly broad language that could exceed what the Privacy Rule permits.
Include explicit terms prohibiting re-identification of the information and any attempt to contact the individuals who are subjects of the data.
Ensure the agreement requires appropriate safeguards, prompt reporting of any use or disclosure not permitted by the agreement, and flow-down of the same restrictions to any agents or subcontractors.
Assess whether a separate Business Associate Agreement or additional Security Rule safeguards are also required, since a Data Use Agreement alone does not address every obligation.
Verify the specific requirements against the current text of the HIPAA Privacy Rule and consider whether applicable state law or HITECH provisions impose additional obligations.