§ 401.713Ensuring the privacy and security of data.
(a) A qualified entity must comply with the data requirements in its data use agreement (DUA) with CMS. Contractors of qualified entities that are anticipated to have access to the Medicare claims data or beneficiary identifiable data in the context of this program are also required to execute and comply with the DUA. The DUA will require the qualified entity to maintain privacy and security protocols throughout the duration of the agreement with CMS and will ban the use of data for purposes other than those set out in this subpart. The DUA will also prohibit the use of unsecured telecommunications to transmit CMS data and will specify the circumstances under which CMS data must be stored and transmitted.
(b) A qualified entity must inform each beneficiary whose beneficiary identifiable data has been (or is reasonably believed to have been) inappropriately accessed, acquired, or disclosed in accordance with the DUA.
(c) Contractor(s) must report to the qualified entity whenever there is an incident where beneficiary identifiable data has been (or is reasonably believed to have been) inappropriately accessed, acquired, or disclosed.
Title 42 published on 2014-10-01
The following are only the Rules published in the Federal Register after the published date of Title 42.
For a complete list of all Rules, Proposed Rules, and Notices view the Rulemaking tab.
This is a list of United States Code sections, Statutes at Large, Public Laws, and Presidential Documents, which provide rulemaking authority for this CFR Part.