As previously announced, CMS is implementing updated security requirements to better protect patient information while still meeting researchers’ needs starting today, 8/11/26:
- Updated Data Management Plan Self-Attestation Questionnaire (DMP SAQ). CMS has updated the DMP SAQ to reflect the latest security standards, CMS Acceptable Risk Safeguards (ARS) 5.1. New DMP SAQs and DMP SAQ recertifications must comply with these updated standards. DMP SAQ 5.1 requirements and other guidance materials, including a description of changes from ARS 3.1 to 5.1, are available on the CMS website here.
- New Extension Form Requirement. CMS is collecting information on researchers’ publicly disseminated findings each year to ensure that CMS data is being used for research that contributes to generalizable knowledge. Researchers must submit a Data Use Agreement (DUA) Extension Request form with this information in order for CMS to approve a DUA extension request. The form is available on the ResDAC website here.
- New Media Disposition Requirement. CMS is requiring physical media containing RIF data to be destroyed within 90 days of shipment. Researchers must submit a certificate of disposition (COD) to close out each shipment. The new COD form with the option “I am destroying all physical media but leaving the DUA and all files open” is available on the ResDAC website here.