42 CFR 401.713 - Ensuring the privacy and security of data.

Status message

There is 1 rule appearing in the Federal Register for 42 CFR Part 401. View below or at eCFR (GPOAccess)
§ 401.713 Ensuring the privacy and security of data.
(a) A qualified entity must comply with the data requirements in its data use agreement (DUA) with CMS. Contractors of qualified entities that are anticipated to have access to the Medicare claims data or beneficiary identifiable data in the context of this program are also required to execute and comply with the DUA. The DUA will require the qualified entity to maintain privacy and security protocols throughout the duration of the agreement with CMS and will ban the use of data for purposes other than those set out in this subpart. The DUA will also prohibit the use of unsecured telecommunications to transmit CMS data and will specify the circumstances under which CMS data must be stored and transmitted.
(b) A qualified entity must inform each beneficiary whose beneficiary identifiable data has been (or is reasonably believed to have been) inappropriately accessed, acquired, or disclosed in accordance with the DUA.
(c) Contractor(s) must report to the qualified entity whenever there is an incident where beneficiary identifiable data has been (or is reasonably believed to have been) inappropriately accessed, acquired, or disclosed.

Title 42 published on 2014-10-01.

The following are only the Rules published in the Federal Register after the published date of Title 42.

For a complete list of all Rules, Proposed Rules, and Notices view the Rulemaking tab.

  • 2015-02-17; vol. 80 # 31 - Tuesday, February 17, 2015
    1. 80 FR 8247 - Medicare Program; Reporting and Returning of Overpayments; Extension of Timeline for Publication of the Final Rule
      GPO FDSys XML | Text
      DEPARTMENT OF HEALTH AND HUMAN SERVICES, Centers for Medicare & Medicaid Services
      Extension of timeline for publication of a final rule.
      As of February 17, 2015, CMS extends by 1 year the timeline for publication of a final rule concerning policies and procedures for reporting and returning overpayments to the Medicare program for providers and suppliers of services under Parts A and B of title XVIII as outlined in the proposed rule published February 16, 2012, at 77 FR 9179.
      42 CFR Parts 401 and 405

This is a list of United States Code sections, Statutes at Large, Public Laws, and Presidential Documents, which provide rulemaking authority for this CFR Part.

This list is taken from the Parallel Table of Authorities and Rules provided by GPO [Government Printing Office].

It is not guaranteed to be accurate or up-to-date, though we do refresh the database weekly. More limitations on accuracy are described at the GPO site.


United States Code

Title 42 published on 2014-10-01

The following are ALL rules, proposed rules, and notices (chronologically) published in the Federal Register relating to 42 CFR Part 401 after this date.

  • 2015-02-17; vol. 80 # 31 - Tuesday, February 17, 2015
    1. 80 FR 8247 - Medicare Program; Reporting and Returning of Overpayments; Extension of Timeline for Publication of the Final Rule
      GPO FDSys XML | Text
      DEPARTMENT OF HEALTH AND HUMAN SERVICES, Centers for Medicare & Medicaid Services
      Extension of timeline for publication of a final rule.
      As of February 17, 2015, CMS extends by 1 year the timeline for publication of a final rule concerning policies and procedures for reporting and returning overpayments to the Medicare program for providers and suppliers of services under Parts A and B of title XVIII as outlined in the proposed rule published February 16, 2012, at 77 FR 9179.
      42 CFR Parts 401 and 405