A CMS Data Use Agreement (DUA) is the legal agreement between the Centers for Medicare & Medicaid Services (CMS) and a requesting institution that governs access to Medicare and Medicaid research data files. It is a distinct instrument from the general-purpose data use agreements covered in CASRAI’s Data Use Agreement (DUA) entry and the Data Sharing Agreements Between Collaborators and Institutions guide: it has its own application intermediary (the Research Data Assistance Center, ResDAC), its own file taxonomy, its own security infrastructure, and its own permitted-use terms, layered on top of the general HIPAA Privacy Rule obligations that already apply to any covered entity handling patient-level health data.
What CMS research data actually is
CMS makes Medicare and Medicaid claims, enrollment, and assessment data available to external researchers in two broad tiers, distinguished by identifiability:
- Limited Data Sets (LDS) — data with direct identifiers (name, address, Social Security number) removed but that may still contain dates and geographic detail more granular than a HIPAA “de-identified” data set permits. An LDS is exactly the kind of file the HIPAA Privacy Rule contemplates at 45 CFR §164.514(e), and CMS requires a signed data use agreement before releasing one, consistent with that rule.
- Research Identifiable Files (RIFs) — the fully identifiable underlying claims and enrollment files (e.g., Medicare fee-for-service Part A/B claims, Part D prescription drug event data, the Master Beneficiary Summary File, and Medicaid’s T-MSIS/TAF analytic files). RIFs carry the strictest DUA terms and, since CMS’s security-modernization push, are increasingly required to be analyzed only inside CMS’s own secure computing environment rather than downloaded to an institutional server.
Which tier a given research question needs determines which DUA package applies — an LDS DUA is a materially lighter-weight agreement than a RIF DUA.
Who administers the process
CMS itself sets policy and is the ultimate signatory, but as of ResDAC’s 2023 process consolidation, ResDAC now serves as the single point of contact for all CMS DUA actions — new requests, DUA extensions, and requestor/custodian contact changes — rather than researchers routing paperwork to CMS directly. ResDAC also runs a “Request Forms Generator” tool that determines exactly which documents a given study needs based on the data files and identifiability level requested.
The application process
At a general level, a CMS DUA request package includes:
- A research study description covering the study’s aims, the specific data files/years/geography needed, and why the requested identifiability level (LDS vs. RIF) is necessary for the analysis.
- Evidence of human-subjects and privacy review — typically institutional IRB approval or exemption determination, and, for identifiable data, documentation addressing the HIPAA authorization or waiver of authorization under which the data will be used.
- The DUA and related CMS forms themselves, identified via ResDAC’s Request Forms Generator, completed and routed for institutional-official signature (as with the general DUA pattern described in CASRAI’s Data Use Agreement entry, the agreement binds the requesting institution, not the individual researcher, even though a named principal investigator/custodian is designated).
- Payment of the applicable data fee, where one applies — CMS publishes current per-file fee schedules; fees and exact processing timelines change periodically, so a requester should confirm current figures directly with ResDAC or CMS rather than relying on a fixed number from secondary sources.
Processing is not instantaneous: CMS/ResDAC review both the research justification and the security plan, and RIF requests in particular can take substantially longer than LDS requests to approve.
Security requirements: the VRDC and beyond
CMS data security obligations sit on top of, and are more prescriptive than, an institution’s general HIPAA security-rule safeguards. Two mechanisms matter most:
- The CCW Virtual Research Data Center (VRDC) — a secure, CMS-managed cloud enclave operated through the Chronic Conditions Warehouse (CCW). Rather than downloading RIF data to an institutional server, an approved researcher logs into the VRDC and analyzes the data inside that controlled environment; only aggregate, disclosure-reviewed output leaves the enclave. This mirrors the “secure enclave” access pattern described more generally in CASRAI’s Secure Data Enclave entry, but the VRDC is CMS’s own specific implementation of it.
- Direct-file security requirements for data still delivered outside the VRDC (largely LDS files, and some legacy RIF arrangements) — encryption at rest and in transit, restricted physical and logical access limited to the individuals named on the DUA, and prohibition on storing data on portable media or personal devices.
CMS has periodically moved to expand mandatory VRDC use for identifiable files rather than physical/file-transfer delivery; a requester should check current ResDAC guidance for which delivery model applies to the specific files and year requested rather than assuming file-transfer delivery is still available.
Permitted-use restrictions
A CMS DUA is more restrictive than a typical inter-institutional data sharing agreement in several specific ways:
- Purpose limitation — data may be used only for the specific research project described and approved in the DUA package, not for any other study, even a closely related one, without a separate request or amendment.
- No re-identification and no re-disclosure — the requestor may not attempt to identify individuals from an LDS, and may not transfer any CMS data, in whole or in part, to any party not named on the agreement.
- Named users only — only individuals specifically listed on the DUA (and, for VRDC access, individually credentialed) may access the data.
- Publication/output review — for VRDC-hosted analyses, output intended to leave the enclave typically goes through a disclosure review to confirm it meets CMS’s cell-size-suppression and re-identification-risk rules before release.
- Data destruction or return — at the end of the approved study period, the requestor must certify destruction of the data (or, for VRDC access, the access is simply terminated since no local copy exists) and, per ResDAC guidance, a DUA is generally issued for a defined term and must be extended before it lapses if the study continues.
How this interacts with general HIPAA obligations
The CMS DUA process does not replace an institution’s HIPAA obligations — it adds a second, funder/data-source-specific layer on top of them. Two points of overlap matter for research administrators structuring a request:
- CMS’s own LDS terms are built directly on the HIPAA Privacy Rule’s limited-data-set provision (45 CFR §164.514(e)), so an LDS DUA is, in effect, CMS acting as the HIPAA-required “data use agreement” party for that specific disclosure.
- For fully identifiable RIF data, the requesting institution still needs its own IRB/Privacy Board determination addressing HIPAA authorization or a waiver of authorization for the use of protected health information, separate from and in addition to the CMS DUA itself — the CMS agreement governs CMS’s release of the data; the institution’s own human-subjects/privacy review governs the institution’s use of it. See CASRAI’s HIPAA in Clinical Research and HIPAA entries for the general framework this sits within.
Frequently asked questions
What is the difference between an LDS DUA and a RIF DUA?
An LDS (Limited Data Set) DUA covers data with direct identifiers removed but some dates/geography retained; it is a lighter-weight agreement consistent with HIPAA’s limited-data-set provision. A RIF (Research Identifiable File) DUA covers fully identifiable claims and enrollment data and carries stricter security terms, typically including a requirement to analyze the data inside CMS’s Virtual Research Data Center rather than downloading it.
Do I have to use the VRDC to access CMS data?
Increasingly, yes, for identifiable (RIF) data — CMS has been moving RIF access toward its Virtual Research Data Center secure enclave model rather than direct file transfer. Some Limited Data Sets may still be delivered outside the VRDC. Confirm the current delivery model for the specific files requested with ResDAC, since CMS policy in this area has changed more than once.
Does ResDAC issue the DUA, or does CMS?
CMS is the legal party to the agreement, but ResDAC is the operational point of contact for the entire process — new requests, extensions, and DUA administration — so in practice researchers work through ResDAC rather than directly with CMS for most of the process.
How long does a CMS DUA last, and can it be renewed?
CMS DUAs are issued for a defined term rather than indefinitely; per ResDAC’s published guidance, agreements are generally renewed on an annual cycle, and the requestor or data custodian must submit an extension request before the current term lapses if the study is ongoing.
Is there a fee for CMS research data?
Fees generally apply to CMS research data files and vary by file type; CMS and ResDAC publish current fee schedules. Because fee amounts change periodically, confirm the current schedule directly with ResDAC rather than relying on a fixed figure from a secondary source.
Does a CMS DUA replace the need for IRB approval?
No. The CMS DUA governs CMS’s release of the data to the institution; it does not substitute for the institution’s own IRB/Privacy Board review, which addresses human-subjects protection and HIPAA authorization or waiver requirements for the institution’s use of the data. Most CMS DUA request packages require evidence of that institutional review as a supporting document.
Related CASRAI content
- Data Use Agreement (DUA) — the general controlled-vocabulary definition this page builds on.
- Data Sharing Agreements Between Collaborators and Institutions — inter-institutional data sharing mechanics.
- HIPAA Privacy Rule and HIPAA in Clinical Research — the general privacy framework CMS DUA terms sit on top of.
- Secure Data Enclave — the general access-control pattern the CCW VRDC implements.
- Data Sharing Agreement vs. Data Processing Agreement — how CMS’s DUA fits within the broader family of data agreement types.







