Evidence Data use agreement
Evidence library · RUAIH focus area 2

Data use agreement

What it is

The Data use agreement is the artifact that satisfies RUAIH focus area 2 — Effective data management — at the control level.

Who signs it

The privacy officer.

A document without a signature is a draft. An assessor is checking that someone with authority put their name to it.

What an assessor asks for

The template, and the executed agreement for every vendor in the register that touches PHI.

What goes in it

  • Permitted uses, stated positively and exhaustively
  • Data minimisation
  • Prohibition of re-identification
  • Whether your data may be used to train or improve the vendor’s models, stated explicitly either way
  • Third-party and subprocessor obligations
  • Audit rights
  • Return or destruction on termination

The most common failure

A BAA treated as sufficient. A BAA governs permitted use of PHI; it says nothing about re-identification, model training on your data, or your right to audit. Those are separate clauses and vendors do not volunteer them.

Where this sits

See the RUAIH crosswalk for how this control maps across CHAI’s playbooks and the NIST AI RMF.

The drafted version. This page specifies the artifact. The Governance Artifact Pack ships it already drafted, one per RUAIH focus area, with the source files so you can put your own name on it.

Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.

Specified from the published RUAIH focus areas and the September 2025 Joint Commission and CHAI guidance, plus the failure modes we see most often in practice.

The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.