Research Data Request Policy Changes – Effective 8/11/26
Centers for Medicare & Medicaid Services

CMS has implemented updated security requirements to better protect patient information while still meeting researchers needs. As previously announced, the following changes apply to applicable Research Identifiable File (RIF) requests, extensions, and amendments starting today, 8/11/26: 

1. Updated Data Management Plan Self-Attestation Questionnaire (DMP SAQ): CMS has updated the DMP SAQ to reflect the latest security standards, CMS Acceptable Risk Safeguards (ARS) 5.1. DMP SAQ 5.1 is now required for all new RIF DUA requests and when renewing an existing DMP SAQ.  

2. New DUA extension form requirement: CMS now collects information on researchers’ publicly disseminated findings each year to ensure that CMS data is being used for research that contributes to generalizable knowledge. Researchers must submit a DUA Extension Request form with this information for CMS to approve an RIF DUA extension request.

3. New media disposition requirement: CMS now requires the destruction of physical media shipped to RIF DUA requesters. After shipment of physical media containing RIF data is received, you must attest that the physical media was disposed of within 90 calendar days from shipment. Researchers must submit a completed Certificate of Disposition (COD) to DataRequests@cms.hhs.gov for each shipment.  

For more information on this announcement and the new requirements, please visit the ResDAC website. 

Centers for Medicare & Medicaid Services (CMS) has sent this update. To contact Centers for Medicare & Medicaid Services (CMS) go to our contact us page.

This email was sent to NPxrji73qy@niepodam.pl using Granicus Communications Cloud 7500 Security Boulevard · Baltimore MD 21244