State Operations Manual (Pub. 100-07), Ch. 2 § 2202.13
Protection of the Confidentiality of OASIS Data
2202.13 - Protection of the Confidentiality of OASIS Data
(Rev. 1, 05-21-04)
2202.13A - OASIS System of Records
(Rev. 125, Issued: 10-31-14, Effective: 10-31-14, Implementation: 10-31-14)
The OASIS database is operated and maintained by States or CMS contractors as a
Federal database and, as such, is subject to the requirements of the Federal Privacy Act.
In general, the only records subject to the Privacy Act are records that are maintained in a
system of records (SOR). The idea of a “system of records” is unique to the Privacy Act
and requires explanation.
The Act defines a “record” to include most personal information maintained by an agency
about an individual. A record contains individually identifiable information, including but
not limited to information about education, financial transactions, medical history,
criminal history, or employment history. A SOR is a group of records from which
information is actually retrieved by name, social security number, or other identifying
symbol assigned to an individual.
The text of the SOR notice for the OASIS database describes the legal requirements
regarding privacy and disclosure of information by CMS or the State. The assigned
identifying number for this system is: System No. 09-70-0522.
The CMS established a new SOR, published June 18, 1999, in the “Federal Register” (64
FR 32992) containing data on the physical, mental, functional, and psychosocial status of
patients receiving the services of HHAs that are approved to participate in the Medicare
and/or Medicaid programs. The purpose of the system is to aid in the administration of
the survey and certification of Medicare/Medicaid HHAs and to study the effectiveness
and quality of care given by those agencies. This system also supports regulatory,
reimbursement, policy, and research functions, and enables CMS to provide HHAs with
outcome data for providers’ internal quality improvement activities.
The OASIS SOR was modified and published on December 27, 2001, (66 FR 66903) to
allow a new routine use authorizing disclosure to national accrediting organizations that
have been approved by CMS for deeming authority for Medicare requirements for home
health services. This SOR notice replaces the SOR notice published June 18, 1999. The
SOR was again updated November 13, 2007.
The HHA SOR contains individually identifiable clinical assessment information (OASIS
records) for all Medicare/Medicaid patients receiving the services of a Medicare and/or
Medicaid approved HHA, except prepartum and postpartum patients; patients under 18
years of age; patients receiving only housekeeping services and/or chore services
exclusively; and, until sometime in the future, patients receiving only personal care
services. The CMS established the system in accordance with the principles and
requirements of the Privacy Act.
2202.13B - Protection of Confidentiality Under the Privacy Act of 1974
(Rev. 125, Issued: 10-31-14, Effective: 10-31-14, Implementation: 10-31-14)
OASIS data are generally protected under the provisions of the Privacy Act of 1974. The
Privacy Act of 1974 protects the confidentiality of person-specific records that are
maintained by the Federal Government and retrieved by a unique indicator. It contains 12
conditions of disclosure under which these records may be released without the written
consent of the individual.
The system notice for the OASIS repository (HHA OASIS) was originally published in
the “Federal Register” on June 18, 1999, and modified on December 27, 2001 and
November 13, 2007. The system notice contains a listing of the prescribed limited
circumstances under which person-specific records contained in that system may be
released. These circumstances are called routine uses. Routine uses must be compatible
with the purpose for which the records are collected and maintained. The OASIS system
notice now contains nine routine uses.
Requests submitted to CMS for release of OASIS data are forwarded to the appropriate
data release authority. The authority to release data from the OASIS national repository
is limited to the System Manager and his or her designees. The OASIS System Manager
is the Director of the Survey and Certification Group at CMS, and as such has the sole
authority to grant or deny a request for access to, or disclosure of data contained in the
HHA OASIS system of records. It is the responsibility of the data release authority to
review these requests for adherence to Privacy Act requirements. Release of data from
any system is discretionary.
Release of data from the OASIS repository follows CMS policy and procedure for data
release. It is CMS policy that each requestor of Privacy Act protected data must sign a
CMS approved Data Use Agreement (DUA). A DUA is not required by the Privacy Act,
however; it is one safeguard CMS has instituted in order to protect the confidentiality of
identifiable data. DUAs are an integral part of the data use approval process. The
agreements delineate the confidentiality requirements of the Privacy Act and CMS’ data
use policies. The agreement serves as both a means of informing data users of these
requirements and a means of obtaining their agreement to abide by these requirements.
Additionally, the agreements serve as a control mechanism through which CMS can track
the location of its data and the reason for the release of the data. CMS’ Office of
Information Systems carries the functional responsibility to control guidelines and policies
for the language in the agreements and coordinates the requests for release of data.