Data Sharing Agreements (DSAs) are administrative controls used by the Defense Health Agency (DHA) to document that the requested use of data managed by DHA is in compliance with Federal law and implementing Department of Defense (DoD) policies. Note that the DHA Privacy Office does not provide data extractions or grant system access. The System Managers who grant access to data require a DSA. The DHA Privacy and Civil Liberties Office (Privacy Office) reviews and approves DSAs based upon compliance with these policies. The DSA:
- Documents the responsibilities of the requestors, including the Government Sponsor and Applicant/Recipient
- Provides the requestors with clear terms and conditions for approval
Who Needs a Data Sharing Agreement
Contractors or non-government researchers seeking to obtain Military Health System (MHS) data managed by DHA to perform a government-sponsored initiative, or government personnel conducting research, are required to submit a Data Sharing Agreement Application (DSAA), which must be approved before a DSA will be executed.
How to Request a DSA
A DSA is requested by submitting a DSAA endorsed by both an Applicant and a Government Sponsor (the “requestors”). Once the DSAA is approved it becomes part of the final agreement provided to the requestors.
Submit DSAAs to the DHA Privacy Office via Email.
Applicant Role
The Applicant is the individual, usually a contractor, who has primary oversight and responsibility for the data.
- For projects involving subcontractors, even when the data is solely handled by subcontractors, the DSAA Applicant must be an employee of the prime contractor
- For projects with more than one prime contractor, a DSAA must be completed for each contracting organization that requires data for the project
- The Applicant is referred to as the Recipient in the final approved DSA
Government Sponsor Role
The Government Sponsor is the point of contact who assumes responsibility for the project/data use described in the DSAA. This role can be filled by a civilian within DHA or a uniformed Service member.
Memorandum of Agreement (MOA)
The DHA Privacy Office serves as the main point of contact for data sharing requests, data sharing arrangements with private entities, and research projects. The Support Agreements Manager (SAM) handles MOAs for recurring data sharing arrangements with other DoD agencies, Federal agencies, and state and local governments. The DHA Privacy Office and the SAM have established a process for reviewing MOAs which involve sharing personally identifiable information or protected health information (PII/PHI).
Frequently Asked Questions
Q1:
Why is a Data Sharing Agreement required?
A:
The DHA requires an approved DSA when requestors ask to use DHA data. The DHA, as a covered entity, uses the DSA process to:
- Confirm that data will be used as allowed under the regulations
- Promote privacy responsibility in the MHS
- Maintain documentation in case of an investigation or audit
- Share only the minimum data necessary for the purpose
Q2:
Who needs a Data Sharing Agreement?
A:
- Business Associates who need DHA data to do work on behalf of the government
- Government personnel who need DHA data for a research project or a survey
- Researchers who need DHA data for a research project or survey
- Students and professionals who need DHA data for an academic research project or for a dissertation
Q8:
What is personally identifiable information, or PII?
A:
Under DoD 5400.11-R, "Department of Defense Privacy Program," May 14,2007, personally identifiable information (PII) is information about an individual that identifies, links, relates, or is unique to, or describes the individual. Examples are: a social security number; age; military rank; civilian grade; marital status; race; salary; home or office phone numbers; and other demographic, biometric, personnel, medical, and financial information.
Q9:
What is protected health information, or PHI?
A:
Under DoD 6025.18-R, "Department of Defense Health Information Privacy Regulation, protected health information (PHI) is a subset of PII. PHI is health information, including demographic information collected from an individual, created or received by a health care provider, health plan, employer, or health care clearinghouse, and relating to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual; and that identifies the individual; or with respect to which there is a reasonable basis to believe the information can be used to identify the individual.
Q10:
What is de-identified information?
A:
HIPAA defines de-identified data as:
- Data that does not identify an individual
- Data that has the 18 categories of direct identifiers removed
- Data that allows no reason to believe it can be used, alone or in combination with other information to identify an individual
Q11:
What is a limited data set?
A:
DoD 6025.18-R defines a limited data set as PHI that excludes 16 of the 18 direct identifiers. A limited data set may still include the following (potentially identifying) information: admission dates, discharge dates, service dates, dates of birth, and, if applicable, age at time of death (including decedents age 90 or over). Also, five-digit zip code or any other geographic subdivision, such as state, county, city, precinct, and their equivalent geocodes (except street address) may also remain as part of a limited data set (LDS).
You also may be interested in...
Showing results 1 - 15
Page 1 of 2
Form/Template
10/19/2015
This template is used to request a 30 day extension in order to continue to use the data in accordance to the executed Data Sharing Agreement (DSA).
Recommended Content:
Submit a Data Sharing Application
Policy
This instruction reissues DoD 8580.02-R as a DoD instruction (DoDI), which establishes policy and assigns responsibilities for security of individually identifiable health information created, received, maintained, or transmitted in electronic form.
Form/Template
7/30/2015
The Data Sharing Agreement Application (DSAA) is used when requesting data from systems that are owned and/or managed by DHA.
Recommended Content:
Submit a Data Sharing Application
Training Material
11/14/2014
This Guide offers instructions and tips on how to submit a data sharing agreement application (DSAA).
Recommended Content:
Submit a Data Sharing Application
Fact Sheet
8/5/2014
This documents outlines the roles and responsibilities of the applicant/recipient as part of a Data Sharing Agreement (DSA).
Recommended Content:
Submit a Data Sharing Application
Fact Sheet
8/5/2014
This document outlines Frequently Asked Questions (FAQs) for the DHA Privacy and Civil Liberties Office's Data Sharing Agreement (DSA) program.
Recommended Content:
Submit a Data Sharing Application
Fact Sheet
8/5/2014
This documents outlines the roles and responsibilities of the government sponsor as part of a Data Sharing Agreement (DSA).
Recommended Content:
Submit a Data Sharing Application
Form/Template
6/3/2014
The Data Sharing Agreement Modification Request template is used when requesting the modification of an executed DSA.
Recommended Content:
Submit a Data Sharing Application
Form/Template
5/23/2014
The Data Sharing Agreement Renewal Request template is used when requesting the renewal of an executed DSA.
Recommended Content:
Submit a Data Sharing Application
Policy
The HIPAA Privacy Rule establishes national standards to protect individuals’ medical records and other personal health information and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically. The HIPAA Security Rule establishes national standards to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity. Refer to 45 C.F.R. Parts 160 and 164 for additional information.
Fact Sheet
5/1/2014
Personally identifiable information (PII) is information that identifies, links, relates, or is unique to, or describes you. This also includes information which can be used to distinguish or trace your identity and any other personal information which is linked or linkable to you.
Recommended Content:
Privacy Act at DHA, Privacy Impact Assessments, HIPAA Compliance within the MHS, How HIPAA Protects You, Submit a Data Sharing Application, Breaches of PII and PHI, Freedom of Information Act, DHA Privacy Contract Language, Protect Humans in Research, Privacy Act and HIPAA Privacy Training
Form/Template
4/30/2014
The Data Request Template for Access by Login for all DHA Systems is required for a Data Sharing Agreement Application.
Recommended Content:
Submit a Data Sharing Application
Showing results 1 - 15
Page 1 of 2