Reminder: DUA and VRDC access needs to be extended or renewed annually. Read more.
Purpose of this document
The Data Management Plan Self-Attestation Questionnaire (DMP SAQ) for Federal Agencies allows for documentation that security and privacy controls have been implemented by the federal agency to protect the requested Identifiable Data File (IDFs) in the environment in which the data will be stored.
The DMP SAQ for Federal Agencies replaces the former Data Management Plan (DMP) requirement for CMS IDF requests. Unlike the DMP, which was specific to a single study, the DMP SAQ is an organizational-level plan and all studies using the approved environment can be covered by a single DMP SAQ.
The DMP SAQ for Federal Agencies is a short form with a few administrative requests. The form is for federal agencies who will be storing data within a system that has a current Authority to Operate (ATO) from the agency’s Authorizing Official (AO). The requesting federal agency must provide the ATO as evidence as required in Section 3 of the DMP SAQ. If any identifiable CMS data will be stored in a system that does not have a federal ATO, the federal agency must complete the standard DMP SAQ.
Approved DMP SAQs are valid for one year or until the expiration of the ATO, whatever comes first, after which organizations will need to recertify and update the DMP SAQ to capture any changes. Any changes prior to the recertification date require notification within 15 days of the change.
All federal agencies requesting CMS IDFs must have an approved DMP SAQ for the environment in which they intend to store the CMS data.
CMS’ Data Privacy Safeguard Program (DPSP) is responsible for reviewing and approving the completed DMP SAQ. More information on the DPSP can be found at https://resdac.org/articles/cmss-data-privacy-safeguard-program-dpsp and the DPSP team can be contacted at DPSP@cms.hhs.gov.
How to get started
Below you will find the DMP SAQ for Federal Agencies form. You will need to download the form, complete it, and provide it to the DPSP at dpsp@cms.hhs.gov along with your ATO.
If the system does not have an ATO, the standard DMP SAQ can be found at https://resdac.org/request-form/dmp-saq.