Medicare Program Integrity Manual (Pub. 100-08), § 3.2
Security
Length: 131 wordsOfficial source
3.2-Security
Each party agrees to adhere to the security requirements in the Business Partner System Security
Manual (BPSSM). Both parties agree to work together on all aspects of security in the BPSSM, or
as otherwise issued via Technical Direction Letter or other means by CMS, that require the joint
cooperation of both parties. Mail and email exchanges containing Personally Identifiable
Information (PII) will follow the requirements as outlined by the most current version of the ARS
which states the PII must be secured in an attachment that has been zipped using FIPS 140-2
validated software (i.e. SecureZip). Each party further agrees to adhere to CMS JSM/TDL-09323
and CMS JSM/TDL-11141: Guidelines for Implementing the Centers for Medicare & Medicaid
Services’ (CMS) Revised Information Security Incident Handling and Breach Analysis/Notification
Procedures.
4. Processes