State Operations Manual (Pub. 100-07), Ch. 2 § 2202.16

Fax Transmission of OASIS or Other Patient Identifiable

Last amended: 2014Year: 2014Length: 725 wordsOfficial source
2202.16 - Fax Transmission of OASIS or Other Patient Identifiable Information (Rev. 125, Issued: 10-31-14, Effective: 10-31-14, Implementation: 10-31-14) OASIS assessment data is personal information about home health recipients that HHAs are required to collect and keep confidential in accordance with federal law. The use of electronic means of communication is acceptable in HHAs, if appropriate safeguards are in place. The fax machine provides a fast and inexpensive method to send and receive patient specific information, such as patient referrals and physician orders. However, the use of fax transmission can open up the possibility that confidential patient information can be transmitted or handled in a manner that is not secure and does not protect the patient’s confidential health information. For example, the use of an incorrect fax number can allow the material being transmitted to persons who are not legally authorized to have this information. CMS takes its responsibility seriously to protect patient specific information once it has been transmitted to the State, and CMS expects HHAs to provide the same protections to OASIS data while it is maintained at the HHA. SAs must follow Federal requirements for systems that retain “Federal data” e.g., MDS data, OASIS data. Additional information on information security (IS) can be found on the CMS Information Security web pages at http://www.cms.gov/Research-Statistics-Data-and- Systems/CMS-Information- Technology/InformationSecurity/index.html?redirect=/informationsecurity in the CMS Policy for the Information Security Program (PISP) and the CMS IS Acceptable Risk Safeguards (ARS) found under “Policies” and “Standards.” The home health CoP at §484.11, Release of Patient Identifiable OASIS information, requires that HHAs and agents acting on behalf of the HHA in accordance with a written contract must ensure the confidentiality of all patient identifiable information contained in the clinical record, including OASIS data, and may not release patient identifiable information to the public. It is the responsibility of the HHA to make sure that it has a written contract providing its agent with the legal authority to encode and transmit OASIS assessment data. The contract should also ensure that the agent holds all OASIS data confidential. Each HHA that uses fax transmission of OASIS information should develop its own policies and procedures to assure confidentiality of patient information, as well as, comply with legal, regulatory and accreditation requirements. It is also the responsibility of the HHA to make sure that OASIS assessment data is transmitted to its agent by a secure method. If the HHA chooses to use facsimile transmission of OASIS data, guidelines for use of facsimile transmission of OASIS data are provided below: • The HHA or agent should place fax machines in a secure area and limit access to them. • The HHA should identify one person in a department or unit to monitor incoming documents on a fax machine, or to deliver the document information directly into a secured data base system. • The HHA should outline appropriate written policies that safeguard that transmitted OASIS information is sent to the appropriate person and verify the correct facsimile number to which the OASIS data is being transmitted. This should include: (a) Use of the of a cover sheet, either electronic or hard copy, accompanying the faxed information that specifies that the OASIS information is confidential and limits its use to the terms of the written contract; (b) That the person who is the legal authority for the receipt of the OASIS information is prohibited from disclosing this information to any other party, any may use the data only for the purposes outlined in the written contract; and (c) The HHA should contact the agent to verify the correct fax number to use prior to faxing. The HHA should develop and enforce procedures to be followed in the case of a misdirected transmission. This should include: (a) A notice on the cover sheet that prohibits the disclosure, copying, or distribution of the information by the unintentional receiver of the fax; (b) A notice to the unintentional receiver of the fax to notify the sender immediately if they have received this information in error to arrange for the return of the information; and (c) The name and phone number of the sender to contact. HHAs shall only use or disclose patient identifiable records as permitted or required by law. State survey agencies should follow the CMS guidelines when sending and receiving requests to correct errors to the OASIS data base.
State Operations Manual (Pub. 100-07), Ch. 2 § 2202.16: Fax Transmission of OASIS or Other Patient Identifiable | Justis AI