State Operations Manual (Pub. 100-07), Ch. 2 § 2202.13

Protection of the Confidentiality of OASIS Data

Last amended: 2014Year: 2014Length: 867 wordsOfficial source
2202.13 - Protection of the Confidentiality of OASIS Data (Rev. 1, 05-21-04) 2202.13A - OASIS System of Records (Rev. 125, Issued: 10-31-14, Effective: 10-31-14, Implementation: 10-31-14) The OASIS database is operated and maintained by States or CMS contractors as a Federal database and, as such, is subject to the requirements of the Federal Privacy Act. In general, the only records subject to the Privacy Act are records that are maintained in a system of records (SOR). The idea of a “system of records” is unique to the Privacy Act and requires explanation. The Act defines a “record” to include most personal information maintained by an agency about an individual. A record contains individually identifiable information, including but not limited to information about education, financial transactions, medical history, criminal history, or employment history. A SOR is a group of records from which information is actually retrieved by name, social security number, or other identifying symbol assigned to an individual. The text of the SOR notice for the OASIS database describes the legal requirements regarding privacy and disclosure of information by CMS or the State. The assigned identifying number for this system is: System No. 09-70-0522. The CMS established a new SOR, published June 18, 1999, in the “Federal Register” (64 FR 32992) containing data on the physical, mental, functional, and psychosocial status of patients receiving the services of HHAs that are approved to participate in the Medicare and/or Medicaid programs. The purpose of the system is to aid in the administration of the survey and certification of Medicare/Medicaid HHAs and to study the effectiveness and quality of care given by those agencies. This system also supports regulatory, reimbursement, policy, and research functions, and enables CMS to provide HHAs with outcome data for providers’ internal quality improvement activities. The OASIS SOR was modified and published on December 27, 2001, (66 FR 66903) to allow a new routine use authorizing disclosure to national accrediting organizations that have been approved by CMS for deeming authority for Medicare requirements for home health services. This SOR notice replaces the SOR notice published June 18, 1999. The SOR was again updated November 13, 2007. The HHA SOR contains individually identifiable clinical assessment information (OASIS records) for all Medicare/Medicaid patients receiving the services of a Medicare and/or Medicaid approved HHA, except prepartum and postpartum patients; patients under 18 years of age; patients receiving only housekeeping services and/or chore services exclusively; and, until sometime in the future, patients receiving only personal care services. The CMS established the system in accordance with the principles and requirements of the Privacy Act. 2202.13B - Protection of Confidentiality Under the Privacy Act of 1974 (Rev. 125, Issued: 10-31-14, Effective: 10-31-14, Implementation: 10-31-14) OASIS data are generally protected under the provisions of the Privacy Act of 1974. The Privacy Act of 1974 protects the confidentiality of person-specific records that are maintained by the Federal Government and retrieved by a unique indicator. It contains 12 conditions of disclosure under which these records may be released without the written consent of the individual. The system notice for the OASIS repository (HHA OASIS) was originally published in the “Federal Register” on June 18, 1999, and modified on December 27, 2001 and November 13, 2007. The system notice contains a listing of the prescribed limited circumstances under which person-specific records contained in that system may be released. These circumstances are called routine uses. Routine uses must be compatible with the purpose for which the records are collected and maintained. The OASIS system notice now contains nine routine uses. Requests submitted to CMS for release of OASIS data are forwarded to the appropriate data release authority. The authority to release data from the OASIS national repository is limited to the System Manager and his or her designees. The OASIS System Manager is the Director of the Survey and Certification Group at CMS, and as such has the sole authority to grant or deny a request for access to, or disclosure of data contained in the HHA OASIS system of records. It is the responsibility of the data release authority to review these requests for adherence to Privacy Act requirements. Release of data from any system is discretionary. Release of data from the OASIS repository follows CMS policy and procedure for data release. It is CMS policy that each requestor of Privacy Act protected data must sign a CMS approved Data Use Agreement (DUA). A DUA is not required by the Privacy Act, however; it is one safeguard CMS has instituted in order to protect the confidentiality of identifiable data. DUAs are an integral part of the data use approval process. The agreements delineate the confidentiality requirements of the Privacy Act and CMS’ data use policies. The agreement serves as both a means of informing data users of these requirements and a means of obtaining their agreement to abide by these requirements. Additionally, the agreements serve as a control mechanism through which CMS can track the location of its data and the reason for the release of the data. CMS’ Office of Information Systems carries the functional responsibility to control guidelines and policies for the language in the agreements and coordinates the requests for release of data.
State Operations Manual (Pub. 100-07), Ch. 2 § 2202.13: Protection of the Confidentiality of OASIS Data | Justis AI