Data governance and minimum necessary
The mapping
| Framework | Where this control sits |
|---|---|
| Joint Commission RUAIH | Focus area 2 — Effective data management |
| CHAI governance playbooks | Playbook 6 — Responsible data management and use |
| NIST AI RMF | MAP |
The artifact: Data use agreement and access policy
Who signs it: The privacy officer
What an assessor actually asks for
The data use agreement template and the executed agreement for every vendor in the register that touches PHI, with the five required clauses present.
Why the mapping is not obvious
The September 2025 guidance is unusually specific here and it is worth quoting into your own template: permitted uses, data minimisation, prohibition of re-identification, third-party obligations, and audit rights. Most standard vendor paper contains two of the five.
The most common failure
A BAA treated as sufficient. A BAA governs permitted use of PHI; it says nothing about re-identification, model training on your data, or your right to audit. Those are separate clauses and vendors do not volunteer them.
Where this sits in the whole map
This is one control in the RUAIH ↔ CHAI ↔ NIST crosswalk. The artifact itself is specified at Data use agreement and access policy.
Written and reviewed by Neel Chauhan, MD MBA, physician-executive and founder of the Healthcare AI Institute. Last reviewed 2026-07-30.
Generated from data/crosswalk.yaml, where the mapping and the commentary for each control are authored individually. Reviewed on each framework revision.
The Institute accepts no vendor sponsorship, holds no vendor equity and takes no referral fees.