Human Research Protections
Definition: 

A limited data set could include the following (potentially identifying) information:

  • Admission, discharge, and service dates;
  • Dates of birth and, if applicable, death;
  • Age (including age 90 or over); and
  • Five-digit zip code or any other geographic subdivision, such as state, county, city, precinct and their equivalent geocodes (except street addresses).

Covered entities must condition the disclosure of the limited data set on execution of a "data use agreement," which

  • establishes the permitted uses and disclosures of such information by the recipient, consistent with the purposes of research, public health, or health care operations;
  • limits who can use or receive the data; and
  • requires the recipient to agree not to re-identify the data or contact the individuals.

In addition, the data use agreement must contain adequate assurances that the recipient will use appropriate physical, technical and administrative safeguards to prevent use or disclosure of the limited data set other than as permitted by HIPAA and the data use agreement, or as required by law.