Quality Improvement Organization Manual (Pub. 100-10), Ch. 5 § 5115.5
General Quality of Care Review: Responsibility to Protect Information
5115.5 – General Quality of Care Review: Responsibility to Protect Information
and Destruction of Materials
(Rev. 28, Issued: 10-21-16, Effective: 10-21-16, Implementation: 10-21-16)
As specified at 42 CFR §480.115, a QIO is responsible for protecting information and must
implement reasonable security measures to ensure the integrity of information and prevent
unauthorized access. See Manual Chapter 10 for additional information.
The Initial Determination Peer Reviewer must follow the established QIO policy and procedures
that apply to security measures for protecting QIO electronic data and confidential information.
A QIO must maintain all medical record documentation in hard copy form or electronic files in
accordance with Manual Chapter 13.