Medicare Claims Processing Manual (Pub. 100-04), Ch. 24 § 40.2.2.1
A/B MACs, DME MACs, and CEDI Data Security and
40.2.2.1 - A/B MACs, DME MACs, and CEDI Data Security and
Confidentiality Requirements
(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)
All Medicare beneficiary-specific information is confidential and subject to the
requirements of §1106(a) of the Act and implementing regulations at
http://www.gpo.gov/fdsys/browse/collectionCfr.action?collectionCode=CFR. Those
regulations specify that, as a general rule, every proposed disclosure of Medicare
information shall be subject to the Freedom of Information Act rules at 45 CFR Part 5.
Also all such information, to the extent that it is maintained in a “system of records,” is
protected under the provisions of the Privacy Act of 1974 (5 USC. 552a) and
implementing regulations at
http://www.gpo.gov/fdsys/browse/collectionCfr.action?collectionCode=CFR. Such
information is included in claims, remittance advice, eligibility information, online
claims corrections, and any other transactions where personal information applicable to a
beneficiary is processed or transported. Such information may not be disclosed to anyone
other than the provider or supplier that submitted a claim or to the beneficiary for whom a
claim was filed. A/B, MACs, DME MACs and CEDI must ensure the security of all EDI
transactions and data. See the CMS Business Partners System Security Manual and its
Core Security Requirements attachment for more detailed information on system security
requirements.
A/B, MACs, DME MACs and CEDI systems must include the following system security
capabilities:
• All data must be password protected and passwords modified at periodic but irregular
intervals, as well as when an individual having knowledge of the password changes
positions, and when a security breach is suspected or identified;
• Provide mechanisms to detect unauthorized users and prohibit access to anyone who
does not have an appropriate user ID and password;
• Maintain a record of operator-attempted system access violations;
• Maintain a multi-level system/user authorization to limit access to system functions,
files, databases, tables, and parameters from external and internal sources;
• Maintain updates of user controlled files, databases, tables, parameters, and retain a
history of update activity; and
• Protect data ownership and integrity from the detailed transaction level to the
summary file level.