Data Use Agreement (DUA) Form, Research Identifiable Files Request Packet Packet, and Data Management Plan (CMS-R-235)

ICR 202204-0938-004

OMB: 0938-0734

Federal Form Document

Forms and Documents
ICR Details
0938-0734 202204-0938-004
Received in OIRA 202005-0938-003
HHS/CMS CM-CPC
Data Use Agreement (DUA) Form, Research Identifiable Files Request Packet Packet, and Data Management Plan (CMS-R-235)
Revision of a currently approved collection   No
Regular 04/27/2022
  Requested Previously Approved
36 Months From Approved 06/30/2023
9,655 9,200
3,876 2,900
0 0

CMS is permitted to disclose data files for approved research purposes in compliance with 45 45 CFR 164.512(i). Researchers requesting research identifiable files (RIF) must, as part of the request process, complete a research request packet that provides CMS with information pertaining to the research study, including describing how the research results/findings will be disseminated, as well as the data files being requested. Should CMS approve the research request, the data requestor enters into a Data Use Agreement (DUA). This data collection is necessary to ensure that disclosures of data for research purposes comply with federal laws and regulations as well as CMS policy. Researchers requesting RIF files also must complete a Data Management Plan Self-Attestation Questionnaire (DMP SAQ). A DMP SAQ is required each time a DUA is established. Both the DUA and the DMP SAQ forms are valid for one year from the date of approval and are renewable at expiration. If the environment described in a DMP SAQ is the same for multiple DUAs from a single organization, the same DMP SAQ can be used across the DUAs, provided it has not expired. The DMP SAQ is a technical, evidence basedevidence-based questionnaire that DUA users must complete as part of the data request packet. The DMP SAQ will enable CMS to evaluate researcher data systems to ensure that CMS data are adequately secured and appropriately protected, as per the Privacy Act and the HIPAA Privacy Rule. The DMP SAQ also allows CMS to measure compliance through the implementation of security and privacy controls as outlined in the National Institute of Standards and Technology (NIST) Special Publication 800-53 and the Centers for Medicare & Medicaid Services (CMS) Information Security and Acceptable Risk Safeguards (ARS). The second component of the DMP SAQ is to provide ongoing oversight. All organizations will be subject to routine audits of the environments used to store and process CMS data, as described in their organizational-level DMP SAQ.

US Code: 5 USC 552(a) Name of Law: The Privacy Act of 1974
  
None

Not associated with rulemaking

  86 FR 60245 11/01/2021
87 FR 24308 04/25/2022
No

  Total Request Previously Approved Change Due to New Statute Change Due to Agency Discretion Change Due to Adjustment in Estimate Change Due to Potential Violation of the PRA
Annual Number of Responses 9,655 9,200 0 455 0 0
Annual Time Burden (Hours) 3,876 2,900 0 976 0 0
Annual Cost Burden (Dollars) 0 0 0 0 0 0
Yes
Miscellaneous Actions
Yes
Miscellaneous Actions
First, the number of DUA forms has increased to include the forms in the research request packet that provide CMS with information pertaining to the research study. The language in the DUA has been revised to clarify CMS data release policies and updated data security requirements. Second, this package also now includes the DMP SAQ that was previously approved in a separate PRA package. The DMP SAQ was updated to collect information on a second point of contact. Third, there has been a decrease in the number of requesters for LDS datasets and therefore the number of respondents using Form 0235l DUA has been reduced. There has also been a decrease in the use of the Form 0235 DUA as many of the CMS programs that have historically used the form have transitioned to program specific documents that are tailored to the uses and disclosures for a specific CMS program. The hourly burden estimates have been updated to include the forms used in the RIF research request packets and the DMP SAQ.

$2,904,800
No
    No
    No
No
No
No
No
Stephan McKenzie 410 786-1943 [email protected]

  No

On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
 
 
 
 
 
 
 
    (i) Why the information is being collected;
    (ii) Use of information;
    (iii) Burden estimate;
    (iv) Nature of response (voluntary, required for a benefit, or mandatory);
    (v) Nature and extent of confidentiality; and
    (vi) Need to display currently valid OMB control number;
 
 
 
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.
04/27/2022


© 2024 OMB.report | Privacy Policy