Quality Improvement Organization Manual (Pub. 100-10), Ch. 5 § 5060.5
Beneficiary Complaint: Responsibility to Protect Information and
5060.5 – Beneficiary Complaint: Responsibility to Protect Information and
Destruction of Materials
(Rev. 28, Issued: 10-21-16, Effective: 10-21-16, Implementation: 10-21-16)
As specified at 42 CFR §480.115, a QIO is responsible for protecting information and must
implement reasonable security measures to ensure the integrity of information and prevent
unauthorized access (See Manual Chapter 10 for additional information).
The Initial Determination Peer Reviewer must follow the established QIO policy and procedures
that apply to security measures for protecting QIO electronic data and confidential information.