Data Use Agreement (DUA)
Form, Research Identifiable Files Request Packet Packet, and Data
Management Plan (CMS-R-235)
Revision of a currently approved collection
No
Regular
04/27/2022
Requested
Previously Approved
36 Months From Approved
06/30/2023
9,655
9,200
3,876
2,900
0
0
CMS is permitted to disclose data
files for approved research purposes in compliance with 45 45 CFR
164.512(i). Researchers requesting research identifiable files
(RIF) must, as part of the request process, complete a research
request packet that provides CMS with information pertaining to the
research study, including describing how the research
results/findings will be disseminated, as well as the data files
being requested. Should CMS approve the research request, the data
requestor enters into a Data Use Agreement (DUA). This data
collection is necessary to ensure that disclosures of data for
research purposes comply with federal laws and regulations as well
as CMS policy. Researchers requesting RIF files also must complete
a Data Management Plan Self-Attestation Questionnaire (DMP SAQ). A
DMP SAQ is required each time a DUA is established. Both the DUA
and the DMP SAQ forms are valid for one year from the date of
approval and are renewable at expiration. If the environment
described in a DMP SAQ is the same for multiple DUAs from a single
organization, the same DMP SAQ can be used across the DUAs,
provided it has not expired. The DMP SAQ is a technical, evidence
basedevidence-based questionnaire that DUA users must complete as
part of the data request packet. The DMP SAQ will enable CMS to
evaluate researcher data systems to ensure that CMS data are
adequately secured and appropriately protected, as per the Privacy
Act and the HIPAA Privacy Rule. The DMP SAQ also allows CMS to
measure compliance through the implementation of security and
privacy controls as outlined in the National Institute of Standards
and Technology (NIST) Special Publication 800-53 and the Centers
for Medicare & Medicaid Services (CMS) Information Security and
Acceptable Risk Safeguards (ARS). The second component of the DMP
SAQ is to provide ongoing oversight. All organizations will be
subject to routine audits of the environments used to store and
process CMS data, as described in their organizational-level DMP
SAQ.
US Code:
5
USC 552(a) Name of Law: The Privacy Act of 1974
First, the number of DUA forms
has increased to include the forms in the research request packet
that provide CMS with information pertaining to the research study.
The language in the DUA has been revised to clarify CMS data
release policies and updated data security requirements. Second,
this package also now includes the DMP SAQ that was previously
approved in a separate PRA package. The DMP SAQ was updated to
collect information on a second point of contact. Third, there has
been a decrease in the number of requesters for LDS datasets and
therefore the number of respondents using Form 0235l DUA has been
reduced. There has also been a decrease in the use of the Form 0235
DUA as many of the CMS programs that have historically used the
form have transitioned to program specific documents that are
tailored to the uses and disclosures for a specific CMS program.
The hourly burden estimates have been updated to include the forms
used in the RIF research request packets and the DMP SAQ.
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.