Back to Top Skip to main content the official website of the Military Health System (MHS) and the Defense Health Agency (DHA)

Utility Navigation Links

Social Media Links

Submit a Data Sharing Application

Data Sharing Agreements (DSAs) are administrative controls used by the Defense Health Agency (DHA) to document that the requested use of data managed by DHA is in compliance with Federal law and implementing Department of Defense (DoD) policies. Note that the DHA Privacy Office does not provide data extractions or grant system access. The System Managers who grant access to data require a DSA. The DHA Privacy and Civil Liberties Office (Privacy Office) reviews and approves DSAs based upon compliance with these policies. The DSA:

  • Documents the responsibilities of the requestors, including the Government Sponsor and Applicant/Recipient
  • Provides the requestors with clear terms and conditions for approval

Who Needs a Data Sharing Agreement

Contractors or non-government researchers seeking to obtain Military Health System (MHS) data managed by DHA to perform a government-sponsored initiative, or government personnel conducting research, are required to submit a Data Sharing Agreement Application (DSAA), which must be approved before a DSA will be executed. 

How to Request a DSA

A DSA is requested by submitting a DSAA endorsed by both an Applicant and a Government Sponsor (the “requestors”). Once the DSAA is approved it becomes part of the final agreement provided to the requestors.

Submit DSAAs to the DHA Privacy Office via Email

Applicant Role

The Applicant is the individual, usually a contractor, who has primary oversight and responsibility for the data. 

  • For projects involving subcontractors, even when the data is solely handled by subcontractors, the DSAA Applicant must be an employee of the prime contractor
  • For projects with more than one prime contractor, a DSAA must be completed for each contracting organization that requires data for the project
  • The Applicant is referred to as the Recipient in the final approved DSA

Government Sponsor Role

The Government Sponsor is the point of contact who assumes responsibility for the project/data use described in the DSAA. This role can be filled by a civilian within DHA or a uniformed Service member. 

Memorandum of Agreement (MOA)

The DHA Privacy Office serves as the main point of contact for data sharing requests, data sharing arrangements with private entities, and research projects. The Support Agreements Manager (SAM) handles MOAs for recurring data sharing arrangements with other DoD agencies, Federal agencies, and state and local governments. The DHA Privacy Office and the SAM have established a process for reviewing MOAs which involve sharing personally identifiable information or protected health information (PII/PHI).

    Frequently Asked Questions


    Why is a Data Sharing Agreement required?


    The DHA requires an approved DSA when requestors ask to use DHA data. The DHA, as a covered entity, uses the DSA process to:

    • Confirm that data will be used as allowed under the regulations
    • Promote privacy responsibility in the MHS
    • Maintain documentation in case of an investigation or audit
    • Share only the minimum data necessary for the purpose

    Who needs a Data Sharing Agreement?

    • Business Associates who need DHA data to do work on behalf of the government
    • Government personnel who need DHA data for a research project or a survey
    • Researchers who need DHA data for a research project or survey
    • Students and professionals who need DHA data for an academic research project or for a dissertation

    How is the Data Sharing Agreement request process initiated?


    Requestors submit a Data Sharing Agreement Application (DSAA) endorsed by both the Applicant and Sponsor.


    How long will it take to obtain an approved Data Sharing Agreement?


    A DSA may be approved within 10 business days after a DSAA is approved.


    Who should be listed on the Data Sharing Agreement?


    The Applicant, Government Sponsor, and DHA Privacy and Civil Liberties Office (DHA Privacy Office) are listed on the DSA.


    Does the Data Sharing Agreement Sponsor need to be a member of the MHS?


    Yes, the DSA Sponsor needs to be a member of the MHS.


    How early should a Data Sharing Agreement Renewal Request be submitted?


    The DSA Renewal Request should not be submitted until the contract option year (as listed on the Renewal Request) has been granted.


    What is personally identifiable information, or PII?


    Under DoD 5400.11-R, "Department of Defense Privacy Program," May 14,2007, personally identifiable information (PII) is information about an individual that identifies, links, relates, or is unique to, or describes the individual. Examples are: a social security number; age; military rank; civilian grade; marital status; race; salary; home or office phone numbers; and other demographic, biometric, personnel, medical, and financial information.


    What is protected health information, or PHI?


    Under DoD 6025.18-R, "Department of Defense Health Information Privacy Regulation, protected health information (PHI) is a subset of PII. PHI is health information, including demographic information collected from an individual, created or received by a health care provider, health plan, employer, or health care clearinghouse, and relating to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual; and that identifies the individual; or with respect to which there is a reasonable basis to believe the information can be used to identify the individual.


    What is de-identified information?


    HIPAA defines de-identified data as:

    • Data that does not identify an individual
    • Data that has the 18 categories of direct identifiers removed
    • Data that allows no reason to believe it can be used, alone or in combination with other information to identify an individual

    What is a limited data set?


    DoD 6025.18-R defines a limited data set as PHI that excludes 16 of the 18 direct identifiers. A limited data set may still include the following (potentially identifying) information: admission dates, discharge dates, service dates, dates of birth, and, if applicable, age at time of death (including decedents age 90 or over). Also, five-digit zip code or any other geographic subdivision, such as state, county, city, precinct, and their equivalent geocodes (except street address) may also remain as part of a limited data set (LDS).

    You also may be interested in...

    Showing results 16 - 27 Page 2 of 2

    General Data Request Template (DRT) Extractions (for all other DHA Systems)


    The Data Request Template for General Extractions is required for a Data Sharing Agreement Application.

    Recommended Content:

    Submit a Data Sharing Application

    Data Request Template (DRT) - Military Health System Data Repository (MDR) Extractions


    The Data Request Template for Military Health System Data Repository Extractions is required for a Data Sharing Agreement Application.

    Recommended Content:

    Submit a Data Sharing Application

    System Security Verification (SSV)


    The System Security Verification (SSV) template is used when data obtained through a DSAA will be stored, transmitted, processed, or otherwise maintained on an information system that has not been granted a Department of Defense (DoD) Authorization to Operate (ATO) or an Interim Authorization to Operate (IATO).

    Recommended Content:

    Submit a Data Sharing Application

    System Security Verification (SSV) Renewal


    The System Security Verification (SSV) Renewal template is used when renewing an executed data sharing agreement along with a previously submitted system security verification.

    Recommended Content:

    Submit a Data Sharing Application

    Guide for DoD Researchers on Using MHS Data

    Training Material

    This document is a guide for Department of Defense (DoD) researchers who plan to request Military Health System (MHS) data for research purposes, in particular, for database research. This guide provides an overview of the MHS as well as guidance regarding the types of research data available within the MHS, reviews specific to the protection of human subjects, and requirements of the Defense Health Agency (DHA) Privacy and Civil Liberties Office (Privacy Office) for requesting MHS data.

    Recommended Content:

    Submit a Data Sharing Application, Protect Humans in Research

    HIPAA Compliant Business Associate Agreement


    The HIPAA Compliant Business Associate Agreement complies with the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, Breach and Enforcement Rules (HIPAA Rules).

    DoDI 4000.19, Interservice and Intragovernmental Support


    In accordance with the authority in DoD Directive (DoDD) 5134.01 (Reference (a)), this Instruction reissues and renames DoD Instruction (DoDI) 4000.19 (Reference (b)) to establish policy, assign responsibilities, and prescribe procedures for support agreements.

    The Privacy Act of 1974 (Privacy Act)


    The Privacy Act of 1974 (Privacy Act) requires agencies to inform the public of the existence of systems of records containing personal information, to give individuals access to records about themselves in a system of records, and to manage those records in a way to ensure fairness to individuals in agency programs.

    DoDI 6025.18: Privacy of Individually Identifiable Health Information in DoD Health Care Programs


    This Instruction reissues DoD Directive (DoDD) 6025.18 as a DoD Instruction in accordance with the authority in DoD Directive 5124.02. It also establishes policy and assigns responsibilities for implementation of the standards for privacy of individually identifiable health information in accordance with parts 160 and 164 of title 45, Code of Federal Regulations.

    DoD 5400.11-R, Department of Defense Privacy Program


    This Regulation is reissued under the authority of DoD Directive 5400.11, “DoD Privacy Program,” May 8, 2007. It provides guidance on section 552a of title 5 United States Code (U.S.C.), the Privacy Act of 1974, as amended, and prescribes uniform procedures for implementation of the DoD Privacy Program.

    DoDD 5400.11, DoD Privacy Program


    This Directive reissues DoD Directive 5400.11, “DoD Privacy Program,” November 16, 2004 (hereby canceled) to update the policies and responsibilities of the DoD Privacy Program under Section 552a of title 5, United States Code and Office of Management and Budget Circular No. A-130, “Management of Federal Information Resources,” February 8, 1996; authorizes the Defense Privacy Board, the Defense Privacy Board Legal Committee, and the Defense Data Integrity Board; continues to authorize the publication of DoD 5400.11-R, “Department of Defense Privacy Program,” May 14, 2007; and continues to delegate authorities and responsibilities for the effective administration of the DoD Privacy Program.

    DoD 6025.18-R, DoD Health Information Privacy Regulation


    This Regulation is issued under the authority of DoD Directive 6025.18, “Privacy and Individually Identifiable Health Information in DoD Health Care Programs,” December 19, 2002. It prescribes the uses and disclosures of protected health information.

    << < 1 2 > >> 
    Showing results 16 - 27 Page 2 of 2

    DHA Address: 7700 Arlington Boulevard | Suite 5101 | Falls Church, VA | 22042-5101

    Some documents are presented in Portable Document Format (PDF). A PDF reader is required for viewing. Download a PDF Reader or learn more about PDFs.