DUA-NCBDDD AND MAC DATA USE AGREEMENT FOR SET-NET_2026_FOR_SIGNATURE_SG.PDF
Extracted text (via pymupdf)
28520 characters
CDC DATA USE AGREEMENT
Incoming Data to CDC
1. General Terms
1.1 Parties to Agreement
This data use agreement (Agreement) is between the following parties:
Data Provider: Maricopa County by and through Maricopa County Department of Public
Health,1645 E Roosevelt Street, Phoenix, Arizona, 85006, United States
Data Recipient: Centers for Disease Control and Prevention ("CDC"), having its primary
offices at 1600 Clifton Road, Atlanta, GA 30333. CDC is an agency within the Department
of Health and Human Services ("HHS").
These parties will collectively be considered the Parties or individually, a Party.
1.2. Period of Agreement, Amendment, and Termination
This Agreement will be effective as of the latest date signed below ("Effective Date") by the
Data Provider and CDC. The term of this Agreement shall be 5 year(s), commencing from
the date of the final signature. This Agreement may be renewed upon mutual written
consent of the Parties.
Except as otherwise expressly provided herein, this Agreement may be amended only by
the mutual written consent of the authorized representatives of each Party. Amendments
to this Agreement must be made in writing and must be signed by all Parties to be effective.
Either Party may terminate this Agreement at any time by giving thirty (30) days' advance
written notice addressed and delivered directly to the other Party. Termination will not alter
the effect of any federal laws on data already provided to Data Recipient. Data Recipient
agrees to use, maintain, store, protect, archive, and dispose of such data consistent with
the terms of this Agreement. See Section 5.
2. Purpose and Background
This Agreement establishes the terms and conditions under which the Data Provider will
provide, and Data Recipient will receive and use, the data covered under this Agreement.
This Agreement ensures adherence to guiding principles of accountability, privacy and
confidentiality, stewardship, scientific practice, efficiency, and equity. Use and disclosure
of the data must be consistent with this Agreement and with applicable law.
The Parties agree that the Data Recipient will use the data being shared for purpose(s) that
include but are not limited to the following:
Surveillance for Emerging Threats to Mothers and Babies Network (SET-NET) is an
adaptation of existing surveillance systems, such as the US Zika Pregnancy and Infant
Registry, to identify how health threats such as exposure to emerging infectious diseases
during pregnancy can affect mothers and their babies. NCBDDD will collaborate with state,
local and territorial health departments funded through the Epidemiology and Laboratory
Capacity (ELC) for Prevention and Control of Emerging Infectious Diseases Notice of
Funding Opportunity (NOFO CDC-RFA-CK24-0002) or DBDID NOFO (DD-23-0003).
Emerging infectious diseases include cytomegalovirus, hepatitis C, mpox, syphilis, Zika, as
well as other infections that may be a public health threat to mothers and babies. Data
collected through SET-NET and held by CDC are covered by an Assurance of Confidentiality
(see attached the Assurance of Confidentiality for SET-NET).
3. Covered Data
Data that are included within this Agreement will be referred to as "Covered Data" and will
be further described in Appendix A. Data covered by this Agreement will generally not
include directly identifiable data, except where sharing of such data is allowed by
applicable federal law and deemed necessary for the purposes stated above.
The Parties acknowledge that Covered Data are limited to those data specified in
Appendix A, which identifies the complete set of data items to which the Data Recipient
will have access to under this Agreement
The Parties are permitted to transmit, access, receive, share and/or use any part of the
Covered Data listed below as specified in the agreed purpose and uses, as set out herein:
Dataset Title Dataset Description
From
To
PII
PHI
SET-NET
The data to be part of SET-NET
will be abstracted from existing
data systems including medical
records. These data include
general information regarding the
health of the pregnant woman
(e.g., age, race/ethnicity,
laboratory test results, reports
from prenatal imaging, chronic or
acute medical conditions),
pregnancy exposures (e.g.,
medication use, infections,
nutritional status), pregnancy
outcome (e.g., miscarriage,
stillbirth, livebirth), and child
outcomes (e.g., date of delivery,
gestational age, sex, birthweight,
structural birth defects, results
from screening tests and exams
such as those for hearing and
vision, and neurodevelopmental
outcomes). Data will also be
abstracted from existing data
systems on postnatal morbidity
and mortality up to 24 months of
age depending on the infection.
2020
2028
Yes
Yes
The data system will be modular,
such that a jurisdiction can adapt
its system for a particular
exposure at the onset and modify
its system in the future to capture
another threat, with relatively
minor modifications. The data
will include some essential
variables that are considered
private information, such as
infant date of birth. CDC has an
Assurance of Confidentiality for
the data at CDC to ensure the
highest protection of these data.
Very limited PII or potential PII will
be collected, to include infant’s
date of birth, pregnancy-related
dates (estimated date of delivery,
date of last menstrual period,
date of pregnancy loss), dates of
death (maternal and child) and
potentially geographic data such
as zip code or census tract. CDC
will provide technical assistance
to partners regarding the data
and information that can be
submitted for the purposes of
this project. Partners will be
asked to remove all other PII
(besides variables listed above)
prior to secure data submission.
(See attached SET-NET data
dictionary)
4. Agreement Administration
The Parties agree that the Data Recipient will use the data being shared for purpose(s) that
include but are not limited to the following:
Where required by law, Data Recipient will ensure that the Authorized Users within Data
Recipient's organization that are deemed authorized to access the Covered Data will
receive appropriate security training and be aware of the terms of this Agreement.
The Data Recipient designates the following individual(s) as the primary Data Custodian(s)
point of contact:
Megan Reynolds , Data Custodian , 4770 Buford Highway , Atlanta, Georgia , United
States,30341 , 404-498-0604 , xah6@cdc.gov
If the individual(s) currently assigned as the primary Data Custodian(s) are no longer in
their position(s) and are no longer responsible for acting as the primary Data Custodian(s),
the responsibilities of the primary Data Custodian(s) will automatically be transferred to
the individual(s) who replace them.
Unless otherwise designated and agreed upon by the Parties, the Data Provider agrees to
transmit the Covered Data to the Data Recipient and agrees to designate a "Data
Administrator" of the Covered Data being transmitted. As Data Administrator, the Data
Provider is responsible for the Covered Data being transmitted to the Data Recipient or
granting appropriate access to authorized users for the Data Recipient.
To the extent allowed by law, the Data Provider will ensure that the Covered Data may be
transmitted to Data Recipient's organization consistent with the purposes set forth under
this Agreement.
The Data Provider designates the following individual(s) as the primary Data
Administrator(s):
Adam Berryhill , Data Administrator , 1645 E Roosevelt Street , Phoenix, Arizona , United
States,85006 , +1480-318-0846 , Adam.Berryhill@maricopa.gov
Jonathan Bell , Data Administrator , 1645 E Roosevelt Street , Phoenix, Arizona , United
States,85006 , +1602-339-1509 , Jonathan.Bell@maricopa.gov
5. Data Safeguards
5.1 Confidentiality, Security, and Transmission
This section describes the confidentiality, security, and transfer protections afforded
generally by CDC to data in CDC's custody and control. CDC agrees to the following:
a. Confidentiality:
CDC agrees to maintain the confidentiality of directly identifiable or potentially identifiable
Covered Data to the fullest extent required by applicable federal law. When applicable,
CDC will protect the confidentiality of the Covered Data consistent with the following
federal laws: the Privacy Act of 1974; standards promulgated pursuant to the Health
Insurance Portability and Accountability Act (HIPAA); and the Freedom of Information Act
(FOIA). If more specific federal laws apply to the Covered Data, CDC will also comply with
those laws.
CDC will assert relevant exemptions to disclosure available under federal law, most
critically, when applicable, for: directly identifiable information; personal and/or private
information of which the disclosure would constitute an invasion of privacy; trade secret
and commercial or financial information that is private and confidential; or information
exempted from release by federal statute. If required by law or if practicable, CDC agrees to
notify the Data Provider before releasing Covered Data pursuant to a judicial,
governmental, or other request under law, to allow Data Provider the opportunity to state
any objection to the disclosure of the Covered Data. CDC will provide at least seven (7)
days' notice unless the request legally requires a response sooner; in that case, CDC will
use its best efforts to notify the Data Provider as soon as possible. In the event Covered
Data is disclosed without notice to the Data Provider, CDC will notify the Data Provider as
soon as possible after such disclosure is made.
Unless specified in this Agreement or otherwise legally required, CDC agrees not to use
the Covered Data to link to other data for the purpose of determining identity or
establishing contact with a named person or his/her family without prior written approval
from the Data Provider.
b. Data Security
CDC shall establish appropriate administrative, technical, procedural, and physical
safeguards in accordance with CDC security policies and the National Institute of
Standards and Technology (NIST) Risk Management Framework, including formal System
Security Authorization for the transmission systems involved. CDC will set permissions to
access or edit data commensurate with the level of sensitivity of the data and in
accordance with applicable federal law. In addition, consistent with CDC policies and
procedures, CDC agrees to ensure that the individuals, in particular Authorized Users,
within CDC receive appropriate data security training and are aware of the terms of this
Agreement.
Data will be stored in accordance with applicable federal law and in compliance with
CDC's security policies. Storage requirements may vary based on the nature of the data.
Storage protections for directly identifiable data will include encryption or password
protection, or other similar security feature to protect the data. As technology advances,
appropriate data security provisions and access control methods for the storage location
will be used.
If there is a data breach on or unauthorized disclosure of Covered Data from a CDC
controlled platform, CDC will notify Data Provider of the incident as soon as practicable,
without unreasonable delay. In the event of a suspected incident (loss, theft, compromise)
affecting the security of data provided, the owner of the CDC controlled platform (CDC
System Owner) will ensure that formal notice is provided to CDC's Cybersecurity Program
Office (CSPO) via email at csirt@cdc.gov or telephone at 866-655-2245. CSPO personnel,
with full assistance from the CDC System Owner , will then follow the established agency
process for formal incident investigation, remediation, response, and communication as
appropriate to all affected parties. Upon confirmation of an incident, CDC will ensure
notification is made to impacted parties within required federal reporting timelines
including, but not limited to, the Federal Information Security Modernization Act (FISMA)
and Privacy Act.
c. Transmission
Parties may coordinate to ensure the secure transmission of information. However, Data
Provider is ultimately responsible for undertaking any necessary data security protections
until data is in CDC's custody and control. Such protections may include limiting the
submission of identifiable, potentially identifiable, privileged, sensitive, or confidential
information, or encrypting data prior to submission. Transmission of the Covered Data from
Data Provider to CDC shall be done in accordance with acceptable practices for ensuring
the protection, confidentiality, and integrity of the contents
5.2 Data Maintenance, Storage, and Deletion
CDC agrees to maintain, store, protect, archive, and/or dispose of Covered Data in
accordance with applicable law and requirements. As a general matter, the disposition of
records in CDC's custody and control is governed by the Federal Records Act and may only
be accomplished in accordance with schedules for destruction as provided under law. In
addition, the Parties agree that CDC must comply with circumstances where a litigation
hold or other legal process applies to the Covered Data. Finally, the Data Provider agrees
that, to comply with relevant records retention requirements and/or for the purposes of
research integrity and verification, an archival copy of the Covered Data may be retained by
CDC. Obligations under law to maintain and secure Covered Data will continue to apply to
the data while in CDC's custody and control and will survive termination of this Agreement.
6. Applicable Legal Authorities
Applicable federal, state, Tribal, local, and territorial laws and regulations may govern the
collection, use, sharing, maintenance, and disclosure of Covered Data. The Parties
recognize that Data Provider may be subject to its jurisdiction or other laws, which may
limit its ability to share data. Before entering into this Agreement, Data Provider will inform
CDC about any jurisdictional or other laws that restrict or limit the sharing of data.
Throughout the duration of this Agreement, Data Provider will also notify CDC of any
changes to these laws, if applicable.
The Parties further acknowledge that CDC, as a federal agency, is not subject to the
application of state, Tribal, local, or territorial laws or regulations or the internal policies or
procedures of the other party with respect to data in CDC's custody and control, except
where consistent with federal law. While Covered Data is in the custody and control of
CDC, the Parties agree that this Agreement does not act to change ownership of the
Covered Data.
Further, as applicable to the Covered Data, CDC is a "public health authority" as defined at
45 C.F.R. 164.501 and as used in 45 C.F.R 164.512(b), Standards for Privacy of Individually
Identifiable Health Information, promulgated under the Health Insurance Portability and
Accountability Act of 1996 ("HIPAA"). CDC, as a public health authority, is authorized by 45
C.F.R. 164.512(b) to receive Protected Health Information ("PHI").
7. Data Uses by CDC
CDC will use Covered Data only as consistent with CDC's authorities. To reduce
duplicative data submission by Data Provider and maximize use of the Covered Data for
appropriate public health purposes, uses of Covered Data include, but are not limited to:
7.1 Analyzing and visualizing the Covered Data to provide an ongoing understanding of the
nation's health at the federal and appropriate jurisdictional level, supporting local and
regional public health practice at the jurisdictional level, and facilitating a seamless
transition into response operations, when necessary;
7.2 Analyzing and visualizing the Covered Data to inform and improve distribution of HHS,
CDC, and other federal resources and other assets;
7.3 Analyzing and visualizing the Covered Data to improve detecting, characterizing,
monitoring, responding to, and recovering from cases and incidence of disease,
conditions, and outbreaks
7.4 Analyzing and visualizing the Covered Data to improve the monitoring of routine and
response-related vaccination and vaccine-related activities, including vaccine safety and
assessment of vaccine effectiveness;
7.5 Analyzing and visualizing the Covered Data to improve the monitoring of routine and
response-related testing and diagnostic-related activities, including testing and diagnostic
safety and assessment of testing and diagnostic effectiveness;
7.6 Sharing the Covered Data and analyses thereof with official federal, state, local, Tribal,
and territorial governmental health agencies, or entities collaborating with them in the
execution of their public health role or their outbreak response responsibilities, consistent
with applicable federal law and their own statutory authorities;
7.7 Developing analytic methods using the Covered Data to identify immediate public
health events or concerns at the federal, state, local, Tribal, and territorial level that
warrant further public health investigation or immediate public health intervention actions;
7.8 Enabling public health and outbreak response officials, and other appropriate
authorized users, to query the Covered Data within CDC or CDC-designated secure data
platforms as may be necessary to carry out critical public health functions; and
7.9 Publishing findings and conclusions related to their analyses of the Covered Data
provided in coordination with Data Provider as described in Section 6.
CDC further agrees that it shall notify the Data Provider of the need to use the Covered
Data beyond the specific uses listed above as soon as practicable.
The Parties also acknowledge that CDC, as a federal agency and as part of its mission, has
a responsibility to make certain data available more broadly to the public. To that end, the
Parties acknowledge that, where possible with the relevant Covered Data, CDC intends to
make certain data publicly available, taking into consideration protecting privacy and
confidentiality. CDC does not release directly identifiable information unless legally
compelled to do so. CDC will not use data for commercial purposes. CDC will adhere to its
Institutional Review Board policies and practices prior to use of data for research
purposes, if applicable.
Finally, in a Public Health Emergency (PHE), an event likely to become a PHE, or an event
where CDC has undertaken an agency-led response effort consistent with CDC's authority,
CDC may expand the use the Covered Data beyond the listed uses above, but only as
consistent with HHS's and CDC's authorities under applicable federal law. If the nature of
the event is such that expanded use is necessary, CDC will limit the use as much as
possible to that necessary to address the response. CDC will protect individual privacy and
confidential business or financial information to the fullest extent allowed by federal law.
CDC further agrees that it will notify the Data Provider of the need to use the Covered Data
beyond the uses listed above as soon as practicable and will work collaboratively with the
Data Provider throughout the response to ensure coordination where possible and
appropriate.
8. Reporting of Data Used in Publications and Presentations
8.1 Publication:
CDC agrees to coordinate with the Data Provider in advance of publishing data or
analyses, consistent with applicable federal law and Office of Management and Budget
(OMB) directives. CDC further agrees that, in such publications as noted below, it will not
publish, or make publicly available, data which is directly identifiable or present minimal
risk of re-identification in the context of its use, using standard industry practices to test for
identifiability. Specifics as to the release of data elements and the level of specificity for
release will be included in the relevant addendum.
Manuscripts, Reports, Presentations, and Other Single-Instance Publications: CDC
agrees to allow the Data Provider thirty (30) business days to review and provide comments
for consideration on those manuscripts, reports, presentations, or single-instance
publications. If publication needs to occur sooner than 30 days, CDC agrees to notify the
Data Provider, who will expedite review consistent with the need to publish. The Data
Provider has the option to waive this provision by providing a written waiver directly to CDC.
Alternatively, if the Data Provider does not respond within five (5) business days to the
CDC's request for coordination or review of draft publications or analyses, it will be
considered as waiving the provision.
8.2 Recurring Publications
The Parties acknowledge that in furtherance of CDC's public health authorities and
mission, Covered Data may be used to develop regularly updated dashboards and other
publicly available, electronically accessible materials. In circumstances where a recurring
publication is regularly updated, such as an online dashboard, CDC will coordinate with
the Data Provider prior to the first publication on determining any concerns related to
privacy. CDC will not notify the Data Provider prior to each subsequent cycle of posting
where no changes are anticipated.
8.3 Publication in a PHE or similar event:
The Parties acknowledge that a PHE or similar event as set out in the "Data Uses by CDC"
section above, may require the rapid publication of meaningful, real-time information. In
that circumstance, CDC will provide the Data Provider as much notice as possible, as
specified in (a) and (b) above, which may be less than 30 days.
8.4 Attribution
Where appropriate or required, CDC will factually acknowledge the Data Provider in any
paper, publication, or presentation as the source of the Covered Data.
8.5 Representation
To the extent permitted by applicable federal law, CDC agrees to assume full responsibility
for its analysis and interpretation of the data in publications, and, where not otherwise
publicly available, will provide a copy of the CDC report, publication, or presentation to the
Data Provider.
8.6 Intellectual Property
Intellectual property rights on material arising from the use of the Covered Data will be
determined by applicable federal law. Per mutual agreement between the Parties and
where the Data Provider may retain any rights in resultant materials, the Data Provider
grants full permission and a royalty-free, non-exclusive, irrevocable license to HHS and
CDC to use, reproduce, publish, distribute, and exhibit materials arising from this
Agreement for educational, training, and other purposes consistent with HHS's and CDC's
mission. This license applies only to the material arising from the Covered Data and does
not impact the Data Provider's ability to use data remaining in its custody and control.
8.7 Provider-Specific Requirements
Notice is hereby given of Arizona Revised Statutes § 38-511, as applicable to this DUA.
8.8 Disclaimers
Except as provided herein, the Data Provider makes no representations with respect to
data quality or fitness of the Covered Data for a particular purpose. However, the Data
Provider agrees to maintain, consistent with its record retention schedule and
jurisdictional law, documentation related to its collection or generation of the Covered
Data and its transmission to CDC that may document steps taken to address data quality
and completeness. Interpretations, conclusions, and opinions that CDC reaches as a
result of analyses of the data are the CDC's interpretations, conclusions, and opinions, and
do not constitute the findings, policies, or recommendations of the Data Provider. As
appropriate or required, CDC will add disclaimers on publications where data provided
under this Agreement are used.
9. Additional Terms and Conditions
9.1 Entire Agreement
Except where a funding award (e.g., grant, cooperative agreement, contract) is associated
with the collection or generation of the Covered Data, this Agreement constitutes the entire
agreement and understanding between the Parties and supersedes all prior oral or written
agreements and understandings between them with respect to the Covered Data.
For funding awards, the Parties agree that the terms of this Agreement must be read as
consistent with the terms of that award. In the event that a specific funding award for
Covered Data requires more granular or more frequent data or has more specific details
about the data, the terms of the award should prevail. The parties agree that, if a funding
award for Covered Data requires data less granular than agreed to in this Agreement, the
Data Provider will still provide the more granular data as specified in this Agreement.
9.2 Assignment
No party may assign or transfer any or all of its rights or obligations under this Agreement or
any part of it, nor any benefit or interest in or under it, to any third party without the prior
written consent of all Parties, which shall not be unreasonably withheld.
9.3 Mutual Representations
Each Party to this Agreement represents to the other Party that, at all times during the term
and at such other times as may be indicated, it shall comply with, and as applicable, shall
require its directors, officers, employees, contractors, and others over whom it may exert
legal control that have access to Covered Data to comply with its duties and obligations
pursuant to applicable law and this Agreement, including but not limited to duties and
obligations which survive the termination of this Agreement.
9.4 Use of Electronic Signatures and Electronic Records
The Parties may elect to establish processes for the management of and to facilitate
compliance with this Agreement. This may include the development of procedural
information, notices, and any other documents, which may be electronically developed or
transmitted, arising from or pertaining to this Agreement.
The Parties permit mutually acceptable electronic signatures, to the extent permitted and
consistent with applicable laws.
9.5 Disagreements
Disagreements between the Parties arising under or relating to this Agreement will be
resolved by consultation between the Parties and referral of the dispute to appropriate
management officials of the Parties whenever possible
9.6 Public Document
This Agreement may be made publicly available.
9.7 Funding
This Agreement is not an obligation or a commitment of funds, or a basis for the transfer of
funds, and does not create an obligation or commitment to transfer data, but rather is a
statement of understanding between the parties concerning the sharing and use of
Covered Data. Expenditures by each party are subject to its budgetary processes and to the
availability of funds and resources pursuant to applicable laws, regulations, and policies.
9.8 Notices
All notices or any other communication provided for herein shall be provided to the
identified Data Administrator or Custodian: by registered or certified mail, return receipt
requested; by receipted hand delivery; by courier or other similar and reliable carrier; or by
email.
10. Signatories
The undersigned individuals represent that they have competent authority on behalf of
their respective agencies to enter into the obligations set out in this Agreement. Signature
indicates that an understanding of the terms of this Agreement and an agreement to
comply with its terms, to the extent allowed by law.
DATA PROVIDER REPRESENTATIVE
Signature:
Printed Name: Kate Brophy McGee
Title: Chair, Board of Supervisors
Organization: Maricopa County Department of Public Health
Date:
DATA RECIPIENT REPRESENTATIVE
Signature:
Printed Name: Suzanne M. Gilboa
Title: Acting Center Director
Organization: NCBDDD - NATIONAL CENTER ON BIRTH DEFECTS AND DEVELOPMENTAL
DISABILITIES
Date:
APPENDIX A: LIST OF SUPPORTING DOCUMENTS
Supporting File: SETNET_Assurance_of_Confidentiality_2025_08.pdf – SET-NET Assurance
of Confidentiality.
Supporting File: SYP_SETNET_DD_Streamline_2025_02.pdf – SET-NET Exposure Data
Dictionary.