A data use agreement template should cover twelve core elements: identification of the parties, a precise description of the data, permitted uses, the mandatory prohibitions on re-identification and re-contact, safeguarding standards, subcontractor controls, breach reporting duties, liability and indemnification, retention and destruction, term and termination, derivative-data ownership, and authorized signatures. Under HIPAA, any covered entity that discloses a Limited Data Set must have a signed agreement with every recipient before a single record moves.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information Missing or defective terms can expose an organization to civil penalties that start at $145 per violation and reach $2,190,294 in a single calendar year.2Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
When the Template Applies
The HIPAA trigger is the Limited Data Set: protected health information stripped of direct identifiers such as names, Social Security numbers, medical record numbers, phone numbers, and email addresses. What can remain are dates, zip codes, ages, and other indirect identifiers. That residual dataset may be shared only for research, public health activities, or health care operations, and only under a data use agreement.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information
Two boundaries are worth noting before drafting. A business associate agreement is a different instrument, covering any vendor that creates, receives, maintains, or transmits PHI on a covered entity’s behalf. Where the disclosure to that business associate is only a Limited Data Set for health care operations, the data use agreement alone satisfies HIPAA’s written-assurance requirement, and HHS allows the two documents to be combined.3U.S. Department of Health and Human Services. Business Associates Outside HIPAA, FERPA requires a similar written agreement when an educational agency shares personally identifiable student records with an outside organization for research, specifying purpose, scope, duration, use restrictions, and destruction of identifiable information at study end.4eCFR. 34 CFR 99.31 – Under What Conditions Is Prior Consent Not Required The template elements below carry across contexts; only the citations shift.
Parties and Data Scope
Name both organizations by their full legal names, registered business addresses, and administrative contacts. The regulation requires the agreement to establish who is permitted to use or receive the Limited Data Set, so “the recipient’s team” is not enough. List specific roles, departments, or named individuals.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information
Then define the dataset itself: the categories of information included (dates of service, zip codes, discharge dates, ages) and confirmation that specified direct identifiers have been removed. This creates an enforceable boundary and prevents later arguments about whether a given record fell inside or outside the agreement. When transfers will happen on a recurring basis, describe the cadence and volume so the recipient’s safeguards scale to the actual flow.
Permitted Uses and Mandatory Prohibitions
The regulation requires the agreement to establish the permitted uses and disclosures, and it adds a firm ceiling: the agreement cannot authorize the recipient to do anything the covered entity itself could not do under the Privacy Rule.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information Describe the approved project or operational purpose in concrete terms. “Analysis of readmission rates at Hospital X between 2023 and 2025” holds up. “General research” does not.
Two prohibitions are non-negotiable. The recipient must agree not to re-identify any individual in the dataset, and it must agree not to contact any individual whose information appears in the data.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information Add explicit bans on using the data for marketing, resale, or any purpose beyond what the agreement authorizes.
Safeguarding Standards
The regulation requires the recipient to use “appropriate safeguards to prevent use or disclosure of the information other than as provided for by the data use agreement.”1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information The word “appropriate” is deliberately flexible. HIPAA’s Security Rule treats encryption as an “addressable” specification, meaning organizations must evaluate whether it is reasonable and appropriate and document an equivalent alternative if they decide otherwise.5U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule In practice, most providers require encryption for data at rest and in transit because an unencrypted breach is very hard to defend to a regulator.
Beyond encryption, the template should require administrative safeguards (workforce training, role-based access controls, a written security policy) and technical safeguards (multi-factor authentication, audit logging, hardened server environments). If the recipient stores data on physical media, require locked facilities and access logs.
Include audit and inspection rights. Without them, the safeguarding clause is self-policed. With them, the provider can review the recipient’s practices through site visits, third-party assessments, or documentation requests, and can suspend access when it finds problems.
Subcontractors and Downstream Transfers
The regulation requires the recipient to ensure that any agent or subcontractor who touches the Limited Data Set agrees to the same restrictions and conditions that bind the recipient itself.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information A strong template does two things. First, it requires the recipient to obtain the provider’s written approval before sharing data with any subcontractor. Second, it requires flow-down of every material obligation (re-identification and contact prohibitions, safeguarding standards, breach reporting) into the subcontract, and it makes the recipient fully responsible for any subcontractor’s violations. The provider’s contractual relationship is with the recipient, not with a vendor it never chose.
Breach Reporting
The regulation requires the recipient to report any use or disclosure not permitted by the agreement as soon as it becomes aware of it.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information HIPAA’s Breach Notification Rule separately gives business associates up to 60 calendar days after discovering a breach to notify the covered entity.6eCFR. 45 CFR 164.410 – Notification by a Business Associate Sixty days is a regulatory ceiling, not a target. Most well-drafted agreements shorten it contractually to 24 to 72 hours.
Spell out what the notification must include: a description of the incident, the categories and approximate number of records affected, containment steps already taken, and a point of contact for follow-up. Covered entities have their own duty to mitigate harmful effects of privacy violations they become aware of, and faster notice directly affects the provider’s ability to meet that duty.7eCFR. 45 CFR 164.530 – Administrative Requirements
Liability and Indemnification
Safeguarding clauses tell the recipient what to do. Indemnification clauses tell the recipient what it pays for when something goes wrong. A standard provision shifts the breaching party’s costs: legal fees, forensic investigation, regulatory fines, notification expenses, and credit monitoring for affected individuals. Costs compound quickly when notification obligations run into the thousands of people.
Some agreements make indemnification mutual, so each side answers for breaches it causes. Others cap financial exposure or limit indemnification to third-party claims. The right choice depends on the parties’ bargaining power and the sensitivity of the data. What the section should not be is blank. Without it, the provider’s only recourse after a recipient-caused breach is litigation, which is slower and less certain than a contractual duty to pay.
Derivative Data and Intellectual Property
New datasets, reports, and statistical models built from the original data create ownership disputes when the agreement is silent. State clearly whether derivatives belong to the provider, the recipient, or both, and define what counts as a derivative. A workable line: if the original data can be reverse-engineered from the output, it is a copy, not a derivative.
Consider restricting the recipient’s ability to build derivatives that could substitute for the original dataset or hand the recipient a competitive edge. When derivatives are authorized, require the same safeguards and use restrictions to apply to them.
Retention and Destruction
Data should not sit on the recipient’s servers after the project ends. Set a retention period tied to the project timeline and require the recipient to either return the data or destroy it using methods that make recovery impossible. For digital records, destruction commonly follows NIST 800-88 guidelines, which cover clearing, purging, and physical destruction and include a sample certificate of sanitization.8National Institute of Standards and Technology. NIST SP 800-88 Rev. 1 – Guidelines for Media Sanitization
Require written certification of destruction within a specified number of days after the retention period expires. That certification closes the provider’s exposure. Under FERPA, destruction is a regulatory requirement, and the written agreement itself must specify the time period within which identifiable information will be destroyed.4eCFR. 34 CFR 99.31 – Under What Conditions Is Prior Consent Not Required
Term, Termination, and Enforcement
Every agreement needs a start date, an end date, and rules for what happens between them. Align the term with the approved project’s timeline, with renewal only by mutual agreement. That prevents agreements from running indefinitely as personnel and technology change.
The termination clause protects the provider against a recipient that violates the agreement. HIPAA’s organizational requirements for business associate contracts offer a useful model: the provider should have the right to terminate for material breach, and where the provider knows of a pattern of violations, it has an affirmative duty to act, first by attempting a cure and then by terminating if the cure fails.9eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements Ignoring known violations can make the provider itself noncompliant.
Address the data on termination. The standard approach mirrors the destruction clause: return or destroy all copies and certify in writing. If the recipient must retain certain records for legal or regulatory reasons, require ongoing compliance with all safeguarding and use restrictions for as long as the data exists.
Signatures and Execution
Both parties should have the agreement reviewed and signed by someone with actual authority to bind the organization: an officer, director, compliance officer, or in a university, a dean or authorized official. A signature from someone without that authority can render the document unenforceable. Each party keeps a copy in permanent records, and the effective date should be logged in the contract-management system used by the organization. That log sets the clock on the term and the deadline for return or destruction.
What Happens When the Template Falls Short
HIPAA’s civil penalty structure has four tiers based on culpability. The base statutory amounts set by Congress were $100 per violation at the lowest tier and $50,000 at the highest.10Office of the Law Revision Counsel. 42 USC 1320d-5 – General Penalty for Failure to Comply Annual inflation adjustments have pushed the 2026 figures substantially higher:
- Lack of knowledge: $145 to $73,011 per violation, calendar-year cap of $2,190,294.
- Reasonable cause, not willful neglect: $1,461 to $73,011 per violation, same annual cap.
- Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
- Willful neglect, not corrected: $73,011 to $2,190,294 per violation, same annual cap.
Penalties apply per violation, and each affected record can count as a separate violation, so a single incident involving thousands of records can produce exposure that dwarfs the cost of drafting a proper agreement.2Federal Register. Annual Civil Monetary Penalties Inflation Adjustment The Office for Civil Rights investigates complaints and conducts compliance reviews, and it has pursued enforcement actions against organizations that failed to have required agreements in place, not only against those that suffered breaches.