42 CFR 401.713 - Ensuring the privacy and security of data.
(a) A qualified entity must comply with the data requirements in its data use agreement (DUA) with CMS. Contractors of qualified entities that are anticipated to have access to the Medicare claims data or beneficiary identifiable data in the context of this program are also required to execute and comply with the DUA. The DUA will require the qualified entity to maintain privacy and security protocols throughout the duration of the agreement with CMS and will ban the use of data for purposes other than those set out in this subpart. The DUA will also prohibit the use of unsecured telecommunications to transmit CMS data and will specify the circumstances under which CMS data must be stored and transmitted.
(b) A qualified entity must inform each beneficiary whose beneficiary identifiable data has been (or is reasonably believed to have been) inappropriately accessed, acquired, or disclosed in accordance with the DUA.
(c) Contractor(s) must report to the qualified entity whenever there is an incident where beneficiary identifiable data has been (or is reasonably believed to have been) inappropriately accessed, acquired, or disclosed.