Data Use Agreement
A Data Use Agreement (DUA) is a legally binding contract that governs how certain restricted data may be shared and used between the entity that controls the data and another party receiving it. In the HIPAA context, it is the mechanism a covered entity uses to permit the sharing of a limited data set while setting out who may use or receive the information and for what purposes. It generally must be in place before any such data is disclosed to an outside party.
Under the HIPAA Privacy Rule, a Data Use Agreement is the contractual instrument that a covered entity (or its business associate) must enter into before disclosing a limited data set (LDS) to a recipient. The agreement establishes who is permitted to use and receive the LDS and specifies the permitted uses and disclosures of the information by the recipient, typically limited to research, public health, or health care operations purposes. A limited data set is PHI from which specified direct identifiers have been removed, but it is not de-identified data, so the LDS remains PHI subject to the Privacy Rule; the DUA is what makes its disclosure permissible. The DUA should be established prior to any use or disclosure of the LDS to an outside institution or party. Note that a DUA is distinct from a business associate agreement, which governs a different set of relationships and obligations, and that state law, the HITECH Act, or institutional and research policies may impose additional requirements. The specific required content and identifier removal criteria should be verified against the current regulatory text.
Why it matters
A limited data set is not de-identified data. Even after specified direct identifiers are removed, an LDS remains protected health information subject to the HIPAA Privacy Rule. The Data Use Agreement is the specific mechanism that makes disclosing that still-protected information permissible. Without an executed DUA in place, a covered entity that shares a limited data set may be making an impermissible disclosure of PHI, which is why the agreement is not a formality but a compliance prerequisite.
The DUA also functions as a control on downstream conduct. By establishing who may use and receive the limited data set and constraining the permitted uses and disclosures, it limits the scope of how the recipient may handle the information, typically confining it to research, public health, or health care operations purposes. This contractual boundary is what allows a covered entity to extend the reach of PHI beyond its own walls while retaining an accountable, enforceable relationship with the recipient.
Because an LDS still carries privacy risk, timing matters: the agreement should generally be established before any use or disclosure to an outside institution or party occurs. Relying on a DUA does not by itself guarantee compliance, and state law, the HITECH Act, or institutional and research policies may impose additional requirements beyond the Privacy Rule's baseline. Readers should confirm the specific required content and identifier-removal criteria against the current regulatory text.
Who it's relevant to
Inside DUA
Common questions
Answers to the questions practitioners most commonly ask about DUA.