State Operations Manual (Pub. 100-07), Ch. 2 § 2202.16
Fax Transmission of OASIS or Other Patient Identifiable
2202.16 - Fax Transmission of OASIS or Other Patient Identifiable
Information
(Rev. 125, Issued: 10-31-14, Effective: 10-31-14, Implementation: 10-31-14)
OASIS assessment data is personal information about home health recipients that HHAs
are required to collect and keep confidential in accordance with federal law. The use of
electronic means of communication is acceptable in HHAs, if appropriate safeguards are
in place. The fax machine provides a fast and inexpensive method to send and receive
patient specific information, such as patient referrals and physician orders. However, the
use of fax transmission can open up the possibility that confidential patient information
can be transmitted or handled in a manner that is not secure and does not protect the
patient’s confidential health information. For example, the use of an incorrect fax number
can allow the material being transmitted to persons who are not legally authorized to have
this information. CMS takes its responsibility seriously to protect patient specific
information once it has been transmitted to the State, and CMS expects HHAs to provide
the same protections to OASIS data while it is maintained at the HHA.
SAs must follow Federal requirements for systems that retain “Federal data” e.g., MDS data,
OASIS data. Additional information on information security (IS) can be found on the CMS
Information Security web pages at http://www.cms.gov/Research-Statistics-Data-and-
Systems/CMS-Information-
Technology/InformationSecurity/index.html?redirect=/informationsecurity in the CMS Policy
for the Information Security Program (PISP) and the CMS IS Acceptable Risk Safeguards
(ARS) found under “Policies” and “Standards.”
The home health CoP at §484.11, Release of Patient Identifiable OASIS information,
requires that HHAs and agents acting on behalf of the HHA in accordance with a written
contract must ensure the confidentiality of all patient identifiable information contained in
the clinical record, including OASIS data, and may not release patient identifiable
information to the public.
It is the responsibility of the HHA to make sure that it has a written contract providing its
agent with the legal authority to encode and transmit OASIS assessment data. The
contract should also ensure that the agent holds all OASIS data confidential. Each HHA
that uses fax transmission of OASIS information should develop its own policies and
procedures to assure confidentiality of patient information, as well as, comply with legal,
regulatory and accreditation requirements. It is also the responsibility of the HHA to
make sure that OASIS assessment data is transmitted to its agent by a secure method.
If the HHA chooses to use facsimile transmission of OASIS data, guidelines for use of
facsimile transmission of OASIS data are provided below:
• The HHA or agent should place fax machines in a secure area and limit access to
them.
• The HHA should identify one person in a department or unit to monitor incoming
documents on a fax machine, or to deliver the document information directly into a
secured data base system.
• The HHA should outline appropriate written policies that safeguard that
transmitted OASIS information is sent to the appropriate person and verify the
correct facsimile number to which the OASIS data is being transmitted. This
should include:
(a) Use of the of a cover sheet, either electronic or hard copy, accompanying
the faxed information that specifies that the OASIS information is
confidential and limits its use to the terms of the written contract;
(b) That the person who is the legal authority for the receipt of the OASIS
information is prohibited from disclosing this information to any other
party, any may use the data only for the purposes outlined in the written
contract; and
(c) The HHA should contact the agent to verify the correct fax number to use
prior to faxing.
The HHA should develop and enforce procedures to be followed in the case of a
misdirected transmission. This should include:
(a) A notice on the cover sheet that prohibits the disclosure, copying, or distribution of
the information by the unintentional receiver of the fax;
(b) A notice to the unintentional receiver of the fax to notify the sender immediately if
they have received this information in error to arrange for the return of the
information; and
(c) The name and phone number of the sender to contact.
HHAs shall only use or disclose patient identifiable records as permitted or required by
law.
State survey agencies should follow the CMS guidelines when sending and receiving
requests to correct errors to the OASIS data base.