Quality Improvement Organization Manual (Pub. 100-10), Ch. 10 § 10090
Re-disclosure of QIO Information
10090 - Re-disclosure of QIO Information
(Rev. 15, Issued: 06-30-06; Effective/Implementation Dates: 06-30-06)
A. Re-disclosure of Non-confidential Information
There are no statutory or regulatory restrictions that limit a recipient's re-disclosure of
your non-confidential information.
B. Re-disclosure of Confidential Information
No recipient of your confidential information may re-disclose the information except
under the limited circumstances authorized by 42 CFR 480.107.
Recipients of your confidential information (beneficiaries, practitioners, and providers)
may re-disclose information about themselves provided the re-disclosure does not
explicitly or implicitly identify another individual.
C. Notifying Recipients About Re-disclosing Confidential Information
The regulation at 42 CFR 480.104(a)(2) requires you to inform recipients, in writing, that
they cannot re-disclose confidential information you disclose to them except as permitted
under 42 CFR 480.107. Your written notice should also advise the recipient of the
penalties for unauthorized disclosures.
Explain in your notice to the recipient that, except as authorized at 42 CFR 480.107,
confidential information cannot be re-disclosed unless the practitioner or provider who
initiated the request and who would be identified, consents to or requests the re-
disclosure. Otherwise, all confidential personal identifiers must be removed. The notice
can be a separate attachment to the information provided, or you can include the notice
in your response to the recipient. Beneficiaries do not have the right to consent to having
their information provided to a third party.
As part of your responsibility to educate practitioners and providers about your review
process (see 42 CFR 480.116), conduct activities that inform individuals and facilities in
your area of the rules and restrictions applicable to confidential information. Improper
re-disclosures of confidential information are generally inadvertent rather than
intentional. Accordingly, provide educational programs to avoid problems.
Exhibit 10-1 - Model Data Use Agreement
(Rev. 15, Issued: 06-30-06; Effective/Implementation Dates: 06-30-06)
Agreement for Use of Health Care Data:
In order to ensure the integrity, security, and confidentiality of information maintained by
the (QIO Name), in compliance with their Medicare Quality Improvement Organization
for (State Name) Contract #(Fill In) and with the confidentiality requirements as outlined
in 42 CFR 480 and clause H.8. of their Contract, and to permit appropriate disclosure and
use of such data as permitted by law, (QIO Name) and (Name of User) enter into this
agreement to comply with the following specific paragraphs:
1. This agreement is by and between the (QIO Name), a Federally-designated
Quality Improvement Organization under contract to the Centers for Medicare &
Medicaid Services (CMS) Contract #(Fill In), and (Name of User) hereinafter
termed "User."
2. This Agreement addresses the conditions under which (QIO Name) will disclose
and the User will obtain and use the (QIO Name) data file(s) specified in
paragraph 7. This agreement supersedes any and all agreements between the
parties with respect to the use of the data from the files specified in paragraph 7
specified herein. Further, the terms of this Agreement can be changed only by a
written modification to this agreement or by the parties adopting a new
agreement. The parties agree further that instructions or interpretations issued to
the User concerning this Agreement or the data specified herein, shall not be valid
unless issued in writing by the (QIO Name) point-of-contact specified in
paragraph 5 or the (QIO Name) signatory to this Agreement shown in paragraph
24.
3. The parties mutually agree that (QIO Name) retains all ownership rights to the
data file(s) referred to in this Agreement, and that the User does not obtain any
right, title, or interest in any of the data furnished by (QIO Name).
4. The parties mutually agree that the following named individual is designated as
"Custodian" of the file(s) on behalf of the User and will be personally responsible
for the observance of all conditions of use and for establishment and maintenance
of security arrangements as specified in this Agreement to prevent unauthorized
use. The User agrees to notify (QIO Name) within 15 days of any changes of
custodianship. The parties mutually agree that (QIO Name) may disapprove the
appointment of a custodian or may require the appointment of a new custodian at
any time.
• (Name of Custodian) (Title of Custodian)
• (Company/Organization)
• (Street Address)
• (City/State/ZIP Code)
• (Phone Number - Including Area Code) (Email Address)
5. The parties mutually agree that the following named individual will be designated
as "point-of-contact" for the Agreement on behalf of (QIO Name).
• (Name of Contact) (Title of Contact)
• (Company/Organization)
• (Street Address)
• (City/State/ZIP Code)
• (Phone Number - Including Area Code) (Email Address)
6. The User represents and warrants, and in furnishing the data file(s) specified in
paragraph 7 (QIO Name) relies upon such representation and warranty, that such
data file(s) will be used solely for the following purpose(s): (The following
material is included as an example)
• To support HSPH’s Agency for Healthcare Quality Research (AHQR)
grant "Validating Guidelines for the Care of AMI Patients."
• The User represents and warrants further that the facts and statements
made in any study or research protocol or project plan submitted to the
(Name of Funding Entity) for each purpose are complete and accurate.
Further, the User represents and warrants that said study protocol(s) or
project plans, as have been approved by (Name of Funding Entity),
represent the total use(s) to which the data file(s) specified in paragraph
will be put.
• The User represents and warrants further that, except as specified in an
Attachment to this Agreement or except as (QIO Name) shall authorize in
writing, the User shall not disclose, release, reveal, show, or otherwise
grant access to the data covered by this Agreement to any person. The
User shall not sell, rent, lease, or loan the data covered by the Agreement
to any person. The User agrees that, within the User organization, access
to the data covered by this Agreement shall be limited to the minimum
number of individuals necessary to achieve the purpose stated in this
section and to those individuals on a need-to-know basis only.
• The User represents and warrants further that he shall not report any
analyses that would require using either a patient, practitioner, or provider
identifier (whether explicit or implicit) (e.g., physician specialty, hospital
bed size, etc.) to obtain additional information.
7. The following (QIO Name) furnished data file(s) is/are covered under this
Agreement: (The following material is included as an example)
• File: Year(s):
• CCP National Data Sample: 2/94 - 2/95
• CCP National Data Sample: 2/95 - 7/95
• Inpatient claims (Part A) for these beneficiaries identified in CCP National
Data Sample including claims for the index AMI Admissions and all
hospitalizations within a year of the index Admission: 1/1/93 - 12/31/96
8. The parties mutually agree that the aforesaid file(s) (and/or any derivative file(s))
may be retained by the User until (Enter Date), hereinafter known as the "end of
active analyses date." Should the active analyses be completed before that date,
the User agrees to notify (QIO Name) within 30 days of the completion of the
active analyses for the purpose specified in paragraph 6.
• The (QIO Name) agrees to archive an electronic, offline version of the
data and resulting datasets for a period not to exceed 5 years from the
completion of active analyses date and to provide the User with access to
the data during that period. The User agrees to request access to the
archived data in writing, to specify the purpose of the request and the
length of time the data will be needed, and acknowledges that all
provisions of this Data Use Agreement apply during any period in which
he has access to the archived data (This paragraph to be inserted only in
those cases where the User requests that the data be archived).
• At the end of the active analyses, (QIO Name) will notify the User either
to return all data files to (QIO Name) at the User’s expense or to destroy
such data. If (QIO Name) elects to have the User destroy the data, the
User agrees to certify the destruction of the files in writing within 30 days
of receiving (QIO Name) instruction. A statement certifying this action
must be sent to (QIO Name). If (QIO Name) elects to have the data
returned, the User agrees to return all files to (QIO Name) within 30 days
of receiving notice to that effect. The User agrees that no data, or any
parts thereof, furnished by (QIO Name) shall be retained when the
aforementioned file(s) are returned or destroyed unless authorization in
writing for the retention of such file(s) has been received from the QIO's
Project Officer and the person designated in paragraph 24 of this
Agreement. The User acknowledges that stringent adherence to the end of
active analyses date included in the first paragraph of Clause 8 is required,
and that the User shall ask (QIO Name) for instructions under this
paragraph if instructions have not been received after 30 days after the end
of active analyses date.
• If the (QIO Name) and User have agreed that the data are to be retained,
the QIO will destroy the data and datasets at or after the agreed-upon date
for termination of the archiving period.
9. The User agrees to establish appropriate administrative, technical, and physical
safeguards to protect the data and to prevent unauthorized use or access to it. The
safeguards shall provide a level and scope of security that is not less than the level
and scope of security established by the (QIO Name) Security and Confidentiality
Policy (attached). The User acknowledges that the use of unsecured
telecommunications, including the Internet, to transmit individually identifiable or
deducible information derived from the file(s) specified in paragraph 7 is
prohibited. Further, the User agrees that the data must not be physically moved or
transmitted in any way from the site indicated in paragraph 4 without written
approval from (QIO Name).
10. The User agrees that the authorized representatives of (QIO Name) will be
granted access to premises where the aforesaid file(s) are kept for the purpose of
inspecting security arrangements to confirm whether the User is in compliance
with the security requirements specified in paragraph 9.
11. The User agrees that no findings, listing, or information derived from the file(s)
specified in paragraph 7 may be released if such findings, listing, or information
contains any combination of data elements that might allow the deduction of a
beneficiary’s, practitioner's, or provider's identification without first obtaining
written authorization from the appropriate Project Officer or the person
designated in paragraph 24 of this Agreement. Examples of such data elements
include, but are not limited to, geographic indicator, age, sex, diagnosis,
procedure, admission/discharge date(s), date of death, medical specialty, provider
zip code, profit/non-profit status of provider, etc. The User agrees further that
(QIO Name) shall be the sole judge as to whether any finding, listing,
information, or any combination of data extracted or derived from (QIO Name)’s
files identifies or would, with reasonable effort, permit one to identify a
beneficiary, practitioner, or provider or to deduce the identity of a beneficiary,
practitioner, or provider to a reasonable degree of certainty.
12. The User agrees that, absent express written authorization from the appropriate
Project Officer or the person designated in paragraph 24 of this Agreement to do
so, the User shall make no attempt to link records included in the file(s) specified
in paragraph 7 to any other identifiable source of information. This includes
attempts to link to other (QIO Name) data file(s). The inclusion of linkage of
specific files in a study protocol approved in accordance with paragraph 6 is
considered express written authorization from (QIO Name).
13. The User agrees to submit to (QIO Name) a copy of all findings within 30 days of
making such findings. The parties mutually agree that the User has "made
findings" with respect to the data covered by this Agreement when the User
prepares any report or other writing for submission to any third party (including,
but not limited to, any manuscript to be submitted for publication) concerning any
purpose specified in paragraph 6 (regardless of whether the report or other writing
expressly refers to such purpose, to (QIO Name) or the files specified in
paragraph 7 or any data derived from such files). The User agrees not to submit
such findings to any third party until receiving CMS and the (QIO Name)
approval to do so. CMS and the (QIO Name) agree to make determination about
approval and to notify the User within 4 to 6 weeks after receipt of findings. CMS
and the (QIO Name) review of the findings is for the sole purpose of assuring that
data confidentiality is maintained and that individual beneficiaries could not be
identified. CMS and the (QIO Name) may withhold approval for publication only
if it determines that the format in which data are presented may result in
identification of individual beneficiaries. The User agrees further to submit its
findings to (QIO Name) within 30 days of receiving notice from (QIO Name) to
do so.
14. The User agrees to include the following statement in any report of findings:
• "The author acknowledges the assistance of the (QIO Name) and the
Centers for Medicare & Medicaid Services (CMS) in providing data which
made this research possible. The conclusions presented are solely those of
the author and do not represent those of (QIO Name) or CMS."
15. The User understands and agrees that they may not reuse original or derivative
data file(s) without prior written approval from the appropriate Project Officer or
the person designated in paragraph 24 of this Agreement.
16. The parties mutually agree that the following specified Attachments are part of
this Agreement.
17. The User agrees that in the event (QIO Name) determines or has a reasonable
belief that the User has made or may have made disclosure of the aforesaid file(s)
that is not authorized by this Agreement or other written authorization from the
appropriate Project Officer or the person designated in paragraph 24 of this
Agreement, (QIO Name), in its sole discretion, may require the User to:
• Promptly investigate and report to (QIO Name) the User’s determination
regarding any alleged or actual unauthorized disclosure;
• Promptly resolve any problems identified by the investigation to the
satisfaction of the QIO’s Project Officer;
• If requested by (QIO Name), submit a formal response to an allegation of
unauthorized disclosure;
• If requested by (QIO Name), submit a corrective action plan with steps
designed to prevent any future unauthorized disclosures; and
• If requested by (QIO Name), return data files to (QIO Name).
18. The User understands that as a result of (QIO Name)’s determination or
reasonable belief that unauthorized disclosures have taken place, (QIO Name)
may refuse to release further data to the User for a period of time to be determined
by (QIO Name). The User further understands that (QIO Name) will advise other
QIOs of the situation and enlist their participation in this refusal to release data to
the User.
19. The User hereby acknowledges that if the information specified in this agreement
is being utilized for research purposes supported by an award of an agency of the
Department of Health & Human Services (DHHS), and if the User materially fails
to fulfill its confidentiality obligations under the terms of its award agreement
with that agency, DHHS has the authority under 45 CFR Part 74 to temporarily
withhold cash payments, disallow funding and matching credit for all or part of
the cost of the grant activity, suspend or terminate the grant in whole or in part,
withhold further awards for the grant project or program, and other available legal
remedies (see 45 CFR 74.62(a)(1)-(5)). DHHS officials may also attach special
award conditions on future grants when a grantee has not conformed to the terms
and conditions of a previous award, or "is not otherwise responsible" (see 45 CFR
74.14(a)(4)-(5)), and may place the name of the grantee on a "Departmental Alert
List," to be consulted by all DHHS Grants Management Officials and program
officials prior to awarding grants (See Grants Policy Directive Part 2.01.C.1).
The strongest sanctions available to a DHHS agency responding to grantee
misconduct are debarment or suspension, which preclude a grantee from receiving
awards not just from DHHS, but government-wide (See 45 CFR 74.13).
20. If (QIO Name) ceases to serve as a QIO contractor before the expiration of the
term of this agreement, (QIO Name) shall provide a copy of this agreement and
all data or datasets in its possession to the successor QIO. It is the parties'
understanding that, should (QIO Name) cease to serve as the QIO for (Name of
State) before the expiration of the term of this agreement, the Centers for
Medicare & Medicaid Services will direct the successor QIO to execute a new
Data Use Agreement prior to the cessation of (QIO Name) Agreement containing
terms and conditions substantially identical to those contained herein. The User
agrees to execute a new Data Use Agreement prior to the cessation of the contract
between the Centers for Medicare & Medicaid Services and (QIO Name). Upon a
failure to timely execute a new agreement, the User shall return any data or
datasets in the User's possession to (QIO Name).
21. By signing this Agreement, the User agrees to abide by all provisions set out in
this Agreement for protection of the data file(s) specified in paragraph 7, and
acknowledges having received notice of potential penalties for violation of the
terms of the Agreement.
22. On behalf of the User, the undersigned individual hereby attests that he or she is
authorized to enter into this Agreement and agrees to all the terms specified
herein.
• (Name of Authorized Individual) (Title of Authorized Individual)
• (Company/Organization)
• (Street Address)
• (City/State/ZIP Code)
• (Phone Number - Including Area Code) (Email Address)
• (Signature) (Date)
23. The Custodian, as named in paragraph 4, hereby acknowledges his/her
appointment as Custodian of the aforesaid file(s) on behalf of the User, and agrees
personally and in a representative capacity to comply with all of the provisions of
this Agreement on behalf of the User.
• (Name of User)
• (Signature) (Date)
24. On behalf of (QIO Name), the undersigned individual hereby attests that he or she
is authorized to enter into this Agreement and agrees to all the terms specified
herein.
• (Name of (QIO Name) Representative)
• (Title of (QIO Name) Representative)
(Signature) (Date)
Exhibit 10-2 - Model Letter
(Rev. 15, Issued: 06-30-06; Effective/Implementation Dates: 06-30-06)
Request for a QIO or ESRD Network to Disclose Information to a Facility’s Agent:
[Name of Provider/ESRD Facility] (The Facility) has entered into an agreement, in
accordance with State law, with [e.g., Name of Corporate Owner] for [Name of
Corporate Owner] to serve as the agent (the Agent) of the Facility for purposes of
receiving certain kinds of data on the Facility’s behalf from [Name of the Quality
Improvement Organization/ESRD Network]. The Agent is subject to the same
requirements under Federal law as the Facility for purposes of receiving and re-disclosing
the data. I request that [Name of Quality Improvement Organization/ESRD Network]
send the following data to the Agent.
(List Specific Reports) for provider number ____________________
I have designated [Name of the Corporate Owner] as the Agent for the purpose described
above for a period of 3 years from the date of my signature unless this designation is
rescinded in writing before that date.
[Signature of Facility Administrator]
Attachment
Exhibit 10-3 - Model Language
(Rev. 15, Issued: 06-30-06; Effective/Implementation Dates: 06-30-06)
Important Information About Disclosing and Re-disclosing Data Received from a
Quality Improvement Organization or ESRD Network:
Under Federal law, a Quality Improvement Organization or ESRD Network must hold in
confidence and not disclose to any person data or information that it has acquired in
exercising its duties and functions, except as provided under various specific exceptions
that appear in §1160 of the Social Security Act (the Act) (42 U.S.C. §1320c-9), the
Quality Improvement Organization confidentiality regulations at 42 CFR 480 and
accompanying Manual Provisions.
A Quality Improvement Organization or ESRD Network can provide to an Agent only
that data which it is authorized to disclose to the Facility under Federal law.
There are specific limitations on re-disclosing any data received from a Quality
Improvement Organization or ESRD Network under §1160 of the Act and at 42 CFR
§§480.107, and 480.140. Any person who discloses information not authorized under
these provisions will, if convicted, be subject to a fine of up to $1000, or be imprisoned
for no more than 6 months, or both, and will pay the costs of prosecution.