DUA-NCBDDD AND MAC DATA USE AGREEMENT FOR SET-NET_2026_FOR_SIGNATURE_SG.PDF

Maricopa County — Formal (2026-04-22)

View PDF Item 54 Meeting page

Extracted text (via pymupdf) 28520 characters
CDC DATA USE AGREEMENT  
 
Incoming Data to CDC 
 
1. General Terms 
 1.1 Parties to Agreement 
This data use agreement (Agreement) is between the following parties: 
Data Provider: Maricopa County by and through Maricopa County Department of Public 
Health,1645 E Roosevelt Street, Phoenix, Arizona, 85006, United States 
 
 Data Recipient: Centers for Disease Control and Prevention ("CDC"), having its primary 
offices at 1600 Clifton Road, Atlanta, GA 30333. CDC is an agency within the Department 
of Health and Human Services ("HHS").  
These parties will collectively be considered the Parties or individually, a Party. 
 
 1.2. Period of Agreement, Amendment, and Termination 
 This Agreement will be effective as of the latest date signed below ("Effective Date") by the 
Data Provider and CDC. The term of this Agreement shall be 5 year(s), commencing from 
the date of the final signature. This Agreement may be renewed upon mutual written 
consent of the Parties.

Except as otherwise expressly provided herein, this Agreement may be amended only by 
the mutual written consent of the authorized representatives of each Party. Amendments 
to this Agreement must be made in writing and must be signed by all Parties to be effective.  
 Either Party may terminate this Agreement at any time by giving thirty (30) days' advance 
written notice addressed and delivered directly to the other Party. Termination will not alter 
the effect of any federal laws on data already provided to Data Recipient. Data Recipient 
agrees to use, maintain, store, protect, archive, and dispose of such data consistent with 
the terms of this Agreement. See Section 5.  
 
2. Purpose and Background 
 This Agreement establishes the terms and conditions under which the Data Provider will 
provide, and Data Recipient will receive and use, the data covered under this Agreement. 
This Agreement ensures adherence to guiding principles of accountability, privacy and 
confidentiality, stewardship, scientific practice, efficiency, and equity. Use and disclosure 
of the data must be consistent with this Agreement and with applicable law.  
 The Parties agree that the Data Recipient will use the data being shared for purpose(s) that 
include but are not limited to the following:  
Surveillance for Emerging Threats to Mothers and Babies Network (SET-NET) is an 
adaptation of existing surveillance systems, such as the US Zika Pregnancy and Infant 
Registry, to identify how health threats such as exposure to emerging infectious diseases 
during pregnancy can affect mothers and their babies. NCBDDD will collaborate with state, 
local and territorial health departments funded through the Epidemiology and Laboratory 
Capacity (ELC) for Prevention and Control of Emerging Infectious Diseases Notice of 
Funding Opportunity (NOFO CDC-RFA-CK24-0002) or DBDID NOFO (DD-23-0003). 
Emerging infectious diseases include cytomegalovirus, hepatitis C, mpox, syphilis, Zika, as 
well as other infections that may be a public health threat to mothers and babies. Data 
collected through SET-NET and held by CDC are covered by an Assurance of Confidentiality 
(see attached the Assurance of Confidentiality for SET-NET). 
 
3. Covered Data 
Data that are included within this Agreement will be referred to as "Covered Data" and will 
be further described in Appendix A. Data covered by this Agreement will generally not

include directly identifiable data, except where sharing of such data is allowed by 
applicable federal law and deemed necessary for the purposes stated above.  
 The Parties acknowledge that Covered Data are limited to those data specified in 
Appendix A, which identifies the complete set of data items to which the Data Recipient 
will have access to under this Agreement  
The Parties are permitted to transmit, access, receive, share and/or use any part of the 
Covered Data listed below as specified in the agreed purpose and uses, as set out herein:  
 
Dataset Title Dataset Description 
From 
To 
PII 
PHI 
SET-NET 
The data to be part of SET-NET 
will be abstracted from existing 
data systems including medical 
records. These data include 
general information regarding the 
health of the pregnant woman 
(e.g., age, race/ethnicity, 
laboratory test results, reports 
from prenatal imaging, chronic or 
acute medical conditions), 
pregnancy exposures (e.g., 
medication use, infections, 
nutritional status), pregnancy 
outcome (e.g., miscarriage, 
stillbirth, livebirth), and child 
outcomes (e.g., date of delivery, 
gestational age, sex, birthweight, 
structural birth defects, results 
from screening tests and exams 
such as those for hearing and 
vision, and neurodevelopmental 
outcomes). Data will also be 
abstracted from existing data 
systems on postnatal morbidity 
and mortality up to 24 months of 
age depending on the infection. 
2020 
2028 
Yes 
Yes

The data system will be modular, 
such that a jurisdiction can adapt 
its system for a particular 
exposure at the onset and modify 
its system in the future to capture 
another threat, with relatively 
minor modifications. The data 
will include some essential 
variables that are considered 
private information, such as 
infant date of birth. CDC has an 
Assurance of Confidentiality for 
the data at CDC to ensure the 
highest protection of these data. 
Very limited PII or potential PII will 
be collected, to include infant’s 
date of birth, pregnancy-related 
dates (estimated date of delivery, 
date of last menstrual period, 
date of pregnancy loss), dates of 
death (maternal and child) and 
potentially geographic data such 
as zip code or census tract. CDC 
will provide technical assistance 
to partners regarding the data 
and information that can be 
submitted for the purposes of 
this project. Partners will be 
asked to remove all other PII 
(besides variables listed above) 
prior to secure data submission. 
(See attached SET-NET data 
dictionary)

4. Agreement Administration 
 The Parties agree that the Data Recipient will use the data being shared for purpose(s) that 
include but are not limited to the following:  
Where required by law, Data Recipient will ensure that the Authorized Users within Data 
Recipient's organization that are deemed authorized to access the Covered Data will 
receive appropriate security training and be aware of the terms of this Agreement. 
The Data Recipient designates the following individual(s) as the primary Data Custodian(s) 
point of contact: 
Megan Reynolds , Data Custodian , 4770 Buford Highway , Atlanta, Georgia , United 
States,30341 , 404-498-0604 , xah6@cdc.gov 
 
 If the individual(s) currently assigned as the primary Data Custodian(s) are no longer in 
their position(s) and are no longer responsible for acting as the primary Data Custodian(s), 
the responsibilities of the primary Data Custodian(s) will automatically be transferred to 
the individual(s) who replace them.  
Unless otherwise designated and agreed upon by the Parties, the Data Provider agrees to 
transmit the Covered Data to the Data Recipient and agrees to designate a "Data 
Administrator" of the Covered Data being transmitted. As Data Administrator, the Data 
Provider is responsible for the Covered Data being transmitted to the Data Recipient or 
granting appropriate access to authorized users for the Data Recipient.  
To the extent allowed by law, the Data Provider will ensure that the Covered Data may be 
transmitted to Data Recipient's organization consistent with the purposes set forth under 
this Agreement. 
The Data Provider designates the following individual(s) as the primary Data 
Administrator(s): 
Adam Berryhill , Data Administrator , 1645 E Roosevelt Street , Phoenix, Arizona , United 
States,85006 , +1480-318-0846 , Adam.Berryhill@maricopa.gov 
 
Jonathan Bell , Data Administrator , 1645 E Roosevelt Street , Phoenix, Arizona , United 
States,85006 , +1602-339-1509 , Jonathan.Bell@maricopa.gov

5. Data Safeguards 
5.1 Confidentiality, Security, and Transmission  
 This section describes the confidentiality, security, and transfer protections afforded 
generally by CDC to data in CDC's custody and control. CDC agrees to the following:  
a. Confidentiality: 
 CDC agrees to maintain the confidentiality of directly identifiable or potentially identifiable 
Covered Data to the fullest extent required by applicable federal law. When applicable, 
CDC will protect the confidentiality of the Covered Data consistent with the following 
federal laws: the Privacy Act of 1974; standards promulgated pursuant to the Health 
Insurance Portability and Accountability Act (HIPAA); and the Freedom of Information Act 
(FOIA). If more specific federal laws apply to the Covered Data, CDC will also comply with 
those laws.  
 CDC will assert relevant exemptions to disclosure available under federal law, most 
critically, when applicable, for: directly identifiable information; personal and/or private 
information of which the disclosure would constitute an invasion of privacy; trade secret 
and commercial or financial information that is private and confidential; or information 
exempted from release by federal statute. If required by law or if practicable, CDC agrees to 
notify the Data Provider before releasing Covered Data pursuant to a judicial, 
governmental, or other request under law, to allow Data Provider the opportunity to state 
any objection to the disclosure of the Covered Data. CDC will provide at least seven (7) 
days' notice unless the request legally requires a response sooner; in that case, CDC will 
use its best efforts to notify the Data Provider as soon as possible. In the event Covered 
Data is disclosed without notice to the Data Provider, CDC will notify the Data Provider as 
soon as possible after such disclosure is made.  
 Unless specified in this Agreement or otherwise legally required, CDC agrees not to use 
the Covered Data to link to other data for the purpose of determining identity or 
establishing contact with a named person or his/her family without prior written approval 
from the Data Provider.  
b. Data Security 
 CDC shall establish appropriate administrative, technical, procedural, and physical 
safeguards in accordance with CDC security policies and the National Institute of 
Standards and Technology (NIST) Risk Management Framework, including formal System 
Security Authorization for the transmission systems involved. CDC will set permissions to 
access or edit data commensurate with the level of sensitivity of the data and in

accordance with applicable federal law. In addition, consistent with CDC policies and 
procedures, CDC agrees to ensure that the individuals, in particular Authorized Users, 
within CDC receive appropriate data security training and are aware of the terms of this 
Agreement.  
 Data will be stored in accordance with applicable federal law and in compliance with 
CDC's security policies. Storage requirements may vary based on the nature of the data. 
Storage protections for directly identifiable data will include encryption or password 
protection, or other similar security feature to protect the data. As technology advances, 
appropriate data security provisions and access control methods for the storage location 
will be used.  
 If there is a data breach on or unauthorized disclosure of Covered Data from a CDC 
controlled platform, CDC will notify Data Provider of the incident as soon as practicable, 
without unreasonable delay. In the event of a suspected incident (loss, theft, compromise) 
affecting the security of data provided, the owner of the CDC controlled platform (CDC 
System Owner) will ensure that formal notice is provided to CDC's Cybersecurity Program 
Office (CSPO) via email at csirt@cdc.gov or telephone at 866-655-2245. CSPO personnel, 
with full assistance from the CDC System Owner , will then follow the established agency 
process for formal incident investigation, remediation, response, and communication as 
appropriate to all affected parties. Upon confirmation of an incident, CDC will ensure 
notification is made to impacted parties within required federal reporting timelines 
including, but not limited to, the Federal Information Security Modernization Act (FISMA) 
and Privacy Act.  
c. Transmission 
 Parties may coordinate to ensure the secure transmission of information. However, Data 
Provider is ultimately responsible for undertaking any necessary data security protections 
until data is in CDC's custody and control. Such protections may include limiting the 
submission of identifiable, potentially identifiable, privileged, sensitive, or confidential 
information, or encrypting data prior to submission. Transmission of the Covered Data from 
Data Provider to CDC shall be done in accordance with acceptable practices for ensuring 
the protection, confidentiality, and integrity of the contents  
5.2 Data Maintenance, Storage, and Deletion  
 CDC agrees to maintain, store, protect, archive, and/or dispose of Covered Data in 
accordance with applicable law and requirements. As a general matter, the disposition of 
records in CDC's custody and control is governed by the Federal Records Act and may only 
be accomplished in accordance with schedules for destruction as provided under law. In

addition, the Parties agree that CDC must comply with circumstances where a litigation 
hold or other legal process applies to the Covered Data. Finally, the Data Provider agrees 
that, to comply with relevant records retention requirements and/or for the purposes of 
research integrity and verification, an archival copy of the Covered Data may be retained by 
CDC. Obligations under law to maintain and secure Covered Data will continue to apply to 
the data while in CDC's custody and control and will survive termination of this Agreement.  
 
6. Applicable Legal Authorities 
Applicable federal, state, Tribal, local, and territorial laws and regulations may govern the 
collection, use, sharing, maintenance, and disclosure of Covered Data. The Parties 
recognize that Data Provider may be subject to its jurisdiction or other laws, which may 
limit its ability to share data. Before entering into this Agreement, Data Provider will inform 
CDC about any jurisdictional or other laws that restrict or limit the sharing of data. 
Throughout the duration of this Agreement, Data Provider will also notify CDC of any 
changes to these laws, if applicable.  
 The Parties further acknowledge that CDC, as a federal agency, is not subject to the 
application of state, Tribal, local, or territorial laws or regulations or the internal policies or 
procedures of the other party with respect to data in CDC's custody and control, except 
where consistent with federal law. While Covered Data is in the custody and control of 
CDC, the Parties agree that this Agreement does not act to change ownership of the 
Covered Data.  
 Further, as applicable to the Covered Data, CDC is a "public health authority" as defined at 
45 C.F.R. 164.501 and as used in 45 C.F.R 164.512(b), Standards for Privacy of Individually 
Identifiable Health Information, promulgated under the Health Insurance Portability and 
Accountability Act of 1996 ("HIPAA"). CDC, as a public health authority, is authorized by 45 
C.F.R. 164.512(b) to receive Protected Health Information ("PHI").  
 
7. Data Uses by CDC 
 CDC will use Covered Data only as consistent with CDC's authorities. To reduce 
duplicative data submission by Data Provider and maximize use of the Covered Data for 
appropriate public health purposes, uses of Covered Data include, but are not limited to:  
 7.1 Analyzing and visualizing the Covered Data to provide an ongoing understanding of the 
nation's health at the federal and appropriate jurisdictional level, supporting local and

regional public health practice at the jurisdictional level, and facilitating a seamless 
transition into response operations, when necessary;  
 7.2 Analyzing and visualizing the Covered Data to inform and improve distribution of HHS, 
CDC, and other federal resources and other assets;  
 7.3 Analyzing and visualizing the Covered Data to improve detecting, characterizing, 
monitoring, responding to, and recovering from cases and incidence of disease, 
conditions, and outbreaks  
7.4 Analyzing and visualizing the Covered Data to improve the monitoring of routine and 
response-related vaccination and vaccine-related activities, including vaccine safety and 
assessment of vaccine effectiveness;  
 7.5 Analyzing and visualizing the Covered Data to improve the monitoring of routine and 
response-related testing and diagnostic-related activities, including testing and diagnostic 
safety and assessment of testing and diagnostic effectiveness;  
 7.6 Sharing the Covered Data and analyses thereof with official federal, state, local, Tribal, 
and territorial governmental health agencies, or entities collaborating with them in the 
execution of their public health role or their outbreak response responsibilities, consistent 
with applicable federal law and their own statutory authorities;  
 7.7 Developing analytic methods using the Covered Data to identify immediate public 
health events or concerns at the federal, state, local, Tribal, and territorial level that 
warrant further public health investigation or immediate public health intervention actions;  
 7.8 Enabling public health and outbreak response officials, and other appropriate 
authorized users, to query the Covered Data within CDC or CDC-designated secure data 
platforms as may be necessary to carry out critical public health functions; and  
 7.9 Publishing findings and conclusions related to their analyses of the Covered Data 
provided in coordination with Data Provider as described in Section 6.  
 
 CDC further agrees that it shall notify the Data Provider of the need to use the Covered 
Data beyond the specific uses listed above as soon as practicable.  
 The Parties also acknowledge that CDC, as a federal agency and as part of its mission, has 
a responsibility to make certain data available more broadly to the public. To that end, the 
Parties acknowledge that, where possible with the relevant Covered Data, CDC intends to 
make certain data publicly available, taking into consideration protecting privacy and 
confidentiality. CDC does not release directly identifiable information unless legally

compelled to do so. CDC will not use data for commercial purposes. CDC will adhere to its 
Institutional Review Board policies and practices prior to use of data for research 
purposes, if applicable.  
 Finally, in a Public Health Emergency (PHE), an event likely to become a PHE, or an event 
where CDC has undertaken an agency-led response effort consistent with CDC's authority, 
CDC may expand the use the Covered Data beyond the listed uses above, but only as 
consistent with HHS's and CDC's authorities under applicable federal law. If the nature of 
the event is such that expanded use is necessary, CDC will limit the use as much as 
possible to that necessary to address the response. CDC will protect individual privacy and 
confidential business or financial information to the fullest extent allowed by federal law. 
CDC further agrees that it will notify the Data Provider of the need to use the Covered Data 
beyond the uses listed above as soon as practicable and will work collaboratively with the 
Data Provider throughout the response to ensure coordination where possible and 
appropriate.  
 
8. Reporting of Data Used in Publications and Presentations 
8.1 Publication: 
 CDC agrees to coordinate with the Data Provider in advance of publishing data or 
analyses, consistent with applicable federal law and Office of Management and Budget 
(OMB) directives. CDC further agrees that, in such publications as noted below, it will not 
publish, or make publicly available, data which is directly identifiable or present minimal 
risk of re-identification in the context of its use, using standard industry practices to test for 
identifiability. Specifics as to the release of data elements and the level of specificity for 
release will be included in the relevant addendum.  
Manuscripts, Reports, Presentations, and Other Single-Instance Publications: CDC 
agrees to allow the Data Provider thirty (30) business days to review and provide comments 
for consideration on those manuscripts, reports, presentations, or single-instance 
publications. If publication needs to occur sooner than 30 days, CDC agrees to notify the 
Data Provider, who will expedite review consistent with the need to publish. The Data 
Provider has the option to waive this provision by providing a written waiver directly to CDC. 
Alternatively, if the Data Provider does not respond within five (5) business days to the 
CDC's request for coordination or review of draft publications or analyses, it will be 
considered as waiving the provision.  
8.2 Recurring Publications

The Parties acknowledge that in furtherance of CDC's public health authorities and 
mission, Covered Data may be used to develop regularly updated dashboards and other 
publicly available, electronically accessible materials. In circumstances where a recurring 
publication is regularly updated, such as an online dashboard, CDC will coordinate with 
the Data Provider prior to the first publication on determining any concerns related to 
privacy. CDC will not notify the Data Provider prior to each subsequent cycle of posting 
where no changes are anticipated.  
8.3 Publication in a PHE or similar event:  
 The Parties acknowledge that a PHE or similar event as set out in the "Data Uses by CDC" 
section above, may require the rapid publication of meaningful, real-time information. In 
that circumstance, CDC will provide the Data Provider as much notice as possible, as 
specified in (a) and (b) above, which may be less than 30 days.  
8.4 Attribution 
 Where appropriate or required, CDC will factually acknowledge the Data Provider in any 
paper, publication, or presentation as the source of the Covered Data.  
8.5 Representation 
 To the extent permitted by applicable federal law, CDC agrees to assume full responsibility 
for its analysis and interpretation of the data in publications, and, where not otherwise 
publicly available, will provide a copy of the CDC report, publication, or presentation to the 
Data Provider.  
8.6 Intellectual Property 
 Intellectual property rights on material arising from the use of the Covered Data will be 
determined by applicable federal law. Per mutual agreement between the Parties and 
where the Data Provider may retain any rights in resultant materials, the Data Provider 
grants full permission and a royalty-free, non-exclusive, irrevocable license to HHS and 
CDC to use, reproduce, publish, distribute, and exhibit materials arising from this 
Agreement for educational, training, and other purposes consistent with HHS's and CDC's 
mission. This license applies only to the material arising from the Covered Data and does 
not impact the Data Provider's ability to use data remaining in its custody and control.  
8.7 Provider-Specific Requirements 
Notice is hereby given of Arizona Revised Statutes § 38-511, as applicable to this DUA. 
8.8 Disclaimers

Except as provided herein, the Data Provider makes no representations with respect to 
data quality or fitness of the Covered Data for a particular purpose. However, the Data 
Provider agrees to maintain, consistent with its record retention schedule and 
jurisdictional law, documentation related to its collection or generation of the Covered 
Data and its transmission to CDC that may document steps taken to address data quality 
and completeness. Interpretations, conclusions, and opinions that CDC reaches as a 
result of analyses of the data are the CDC's interpretations, conclusions, and opinions, and 
do not constitute the findings, policies, or recommendations of the Data Provider. As 
appropriate or required, CDC will add disclaimers on publications where data provided 
under this Agreement are used.  
 
9. Additional Terms and Conditions 
9.1 Entire Agreement  
 Except where a funding award (e.g., grant, cooperative agreement, contract) is associated 
with the collection or generation of the Covered Data, this Agreement constitutes the entire 
agreement and understanding between the Parties and supersedes all prior oral or written 
agreements and understandings between them with respect to the Covered Data.  
 For funding awards, the Parties agree that the terms of this Agreement must be read as 
consistent with the terms of that award. In the event that a specific funding award for 
Covered Data requires more granular or more frequent data or has more specific details 
about the data, the terms of the award should prevail. The parties agree that, if a funding 
award for Covered Data requires data less granular than agreed to in this Agreement, the 
Data Provider will still provide the more granular data as specified in this Agreement.  
9.2 Assignment 
No party may assign or transfer any or all of its rights or obligations under this Agreement or 
any part of it, nor any benefit or interest in or under it, to any third party without the prior 
written consent of all Parties, which shall not be unreasonably withheld.  
9.3 Mutual Representations  
Each Party to this Agreement represents to the other Party that, at all times during the term 
and at such other times as may be indicated, it shall comply with, and as applicable, shall 
require its directors, officers, employees, contractors, and others over whom it may exert 
legal control that have access to Covered Data to comply with its duties and obligations

pursuant to applicable law and this Agreement, including but not limited to duties and 
obligations which survive the termination of this Agreement.  
9.4 Use of Electronic Signatures and Electronic Records  
The Parties may elect to establish processes for the management of and to facilitate 
compliance with this Agreement. This may include the development of procedural 
information, notices, and any other documents, which may be electronically developed or 
transmitted, arising from or pertaining to this Agreement.  
The Parties permit mutually acceptable electronic signatures, to the extent permitted and 
consistent with applicable laws.  
9.5 Disagreements  
 Disagreements between the Parties arising under or relating to this Agreement will be 
resolved by consultation between the Parties and referral of the dispute to appropriate 
management officials of the Parties whenever possible  
9.6 Public Document  
This Agreement may be made publicly available.  
9.7 Funding 
This Agreement is not an obligation or a commitment of funds, or a basis for the transfer of 
funds, and does not create an obligation or commitment to transfer data, but rather is a 
statement of understanding between the parties concerning the sharing and use of 
Covered Data. Expenditures by each party are subject to its budgetary processes and to the 
availability of funds and resources pursuant to applicable laws, regulations, and policies.  
9.8 Notices 
All notices or any other communication provided for herein shall be provided to the 
identified Data Administrator or Custodian: by registered or certified mail, return receipt 
requested; by receipted hand delivery; by courier or other similar and reliable carrier; or by 
email.  
 
10. Signatories 
 The undersigned individuals represent that they have competent authority on behalf of 
their respective agencies to enter into the obligations set out in this Agreement. Signature

indicates that an understanding of the terms of this Agreement and an agreement to 
comply with its terms, to the extent allowed by law.  
 
DATA PROVIDER REPRESENTATIVE    
    
         
Signature: 
 
 
 Printed Name: Kate Brophy McGee 
Title: Chair, Board of Supervisors    
Organization: Maricopa County Department of Public Health    
Date: 
 
 
DATA RECIPIENT REPRESENTATIVE    
    
      
Signature:
 
 
 
Printed Name: Suzanne M. Gilboa    
Title: Acting Center Director    
Organization: NCBDDD - NATIONAL CENTER ON BIRTH DEFECTS AND DEVELOPMENTAL 
DISABILITIES    
Date:

APPENDIX A: LIST OF SUPPORTING DOCUMENTS 
Supporting File: SETNET_Assurance_of_Confidentiality_2025_08.pdf – SET-NET Assurance 
of Confidentiality.    
 
Supporting File: SYP_SETNET_DD_Streamline_2025_02.pdf – SET-NET Exposure Data 
Dictionary.