State Operations Manual (Pub. 100-07), Ch. 4 § 4146.7
Privacy and Confidentiality
4146.7 - Privacy and Confidentiality
(Rev. 1, 05-21-04)
4146.7A - System of Records
(Rev. 1, 05-21-04)
The MDS database is operated and maintained by States as a Federal database and, as
such, is subject to the requirements of the Federal Privacy Act. The text of the System of
Records notice for the MDS, which follows, describes the legal requirements regarding
privacy and disclosure of information by CMS or the State.
The purpose of the Long Term Care Minimum Data Set (LTC MDS)
System NO. 09-70-1517 is to aid in the administration of the survey and
certification of Medicare/Medicaid long term care facilities and to study
the effectiveness and quality of care given in those facilities. This system
supports regulatory, reimbursement, policy and research functions. In
addition, this system will enable Federal and State regulators to provide
long term care facility staff with outcome data for provider’s internal
quality improvement activities.
This system shall contain clinical information found in the comprehensive assessments of
persons residing in long term care facilities that are certified to participate in the
Medicare and/or Medicaid programs (including private pay individuals). This
information is found in the Long Term Care Minimum Data Set for Nursing Home
Resident Assessment.”
The CMS established this system in accordance with the principles and requirements of
the Privacy Act. The Privacy Act allows the disclosure of information from this system
without an individual’s consent if the information is to be used for a purpose that is
compatible with the purposes for which the information was collected. Any such
compatible use of data is known as a “routine use.” The proposed routine uses for this
system meet the compatibility requirement of the Privacy Act since they are consistent
with the purpose of analyzing data on the physical, mental, functional, and psychosocial
status of nursing facility residents living in the State.
The routine uses specify the circumstances under which CMS and the State in their roles
as contractors representing CMS may release information from the long-term care MDS
system without the consent of the individual to whom such information pertains. The
CMS System Manager must evaluate each proposed disclosure of information under the
routine uses and/or an individual authorized by CMS. The authority to release data is
limited to the System Manager or authorized designee.
4146.7B - Procedures for Disclosure of Information Pursuant to Data
Use Agreement
(Rev. 1, 05-21-04)
Releases of information must be evaluated to determine if disclosure is legally
permissible by the CMS System Manager or authorized designee, including but not
limited to ensuring that the purpose of the disclosure is compatible with the purpose for
which the information was collected. Releases are generally only made for the routine
uses specified in the system notice. The CMS System Manager or authorized designee
must require each prospective recipient of LTC MDS system information to agree in
writing to certain conditions to ensure the continuing confidentiality and to physically
safeguard of the information. For each disclosure it is necessary for the System Manager
or authorized designee to, as necessary and appropriate:
1. Determine that no other Federal statute specifically prohibits disclosure of the
information;
2. Determine that the use or disclosure does not violate legal limitations under which
the information was provided, collected, or obtained;
3. Determine the purpose for which the disclosure is to be made:
a. Cannot reasonably be accomplished unless the information is provided in
individually identifiable form;
b. Is of sufficient importance to warrant the effect on or the risk to the
privacy of the individual(s) that additional exposure of the record(s) might
bring;
c. There is a reasonable probability that the purpose of the disclosure will be
accomplished; and
d. The purpose is within the scope of a routine use.
4. Require the recipient of the information to:
a. Establish reasonable administrative, technical, and physical safeguards to
prevent unauthorized access, use, or disclosure of the record or any part
thereof. The physical safeguards shall provide a level of security that is at
least equivalent to the level of security contemplated in OMB Circular No.
A-130 (revised), Appendix III, Security of Federal Automated Information
Systems, which sets forth guidelines for security plans for automated
information systems in Federal agencies; contemplated in OMB Circular
No. A-130 (revised), Appendix III, Security of Federal Automated
Information Systems, which sets forth guidelines for security plans for
automated information systems in Federal agencies;
b. Remove or destroy the information that allows subject individual(s) to be
identified at the earliest time at which removal or destruction can be
accomplished, consistent with the purpose of the request;
c. Refrain from using or disclosing the information for any purpose other
than the stated purpose under which the information was disclosed; and
d. Make no further use or disclosure of the information except:
●
To prevent or address an emergency directly affecting the health or
safety of an individual;
●
For use on another project under the same conditions, provided the
System Manager or authorized designee has authorized the
additional use(s) in writing; or
●
When required by law.
5. Secure a written statement or agreement from the prospective recipient of the
information whereby the prospective recipient attests to an understanding of, and
willingness to abide by the foregoing provisions and any additional provisions
that the System Manager deems appropriate in the particular circumstance. The
System Manager or authorized designee must use a CMS-approved Data Release
Agreement that cannot be modified; and
6. Determine whether the disclosure constitutes a computer “matching program” as
defined in 5 U.S.C. §552a(a)(8). If the disclosure is determined to be a computer
“matching program” the instructions regarding preparation and transmission of a
matching agreement as stated in 5 U.S.C. §552a(o) must be followed.
4146.7C - Routine Uses
(Rev. 1, 05-21-04)
The following lists the routine uses published in the LTC MDS System NO. 09-70-1517
(current as of February 2002).
Disclosure may be made:
1. To Agency contractors, or consultants who have been engaged by the Agency to
assist in accomplishment of a CMS function relating to the purposes for this
system and who need to have access to the records in order to assist CMS;
2. To another Federal or state agency, agency of a state government, and agency
established by state law, or its fiscal agent to:
a. Contribute to the accuracy of CMS’ proper payment of Medicare benefits;
b. Enable such agency to administer a Federal health benefits program, or as
necessary to enable such agency to fulfill a requirement of a Federal
statute or regulation that implements a health benefit program funded in
whole or in part with Federal funds, and/or;
c. Assist Federal/state Medicaid programs within the state.
3. To QIOs in connection with review of claims, or in connection with studies or
other review activities, conducted pursuant to Part B of Title XI of the Act and in
performing affirmative outreach activities to individuals for the purpose of
establishing and maintaining their entitlement to Medicare benefits or health
insurance plans;
4. To insurance companies, underwriters, third parties administrators (TPA),
employers, self-insurers, group health plans, health maintenance organizations
(HMO), health and welfare benefit funds, managed care organizations, other
supplemental insurers, non-coordinating insurers, multiple employer trusts,
liability insurers, no-fault medical automobile insurers, workers compensation
carriers or plans, other groups providing protection against medical expenses
without the beneficiary’s authorization, and any entity having knowledge of the
occurrence of any event affecting (a) an individual’s right to any such benefit or
payment, or (b) the initial right to any such benefit or payment, for the purpose of
coordinating of benefits with Medicare program and implementation of MSP
provision at 42 U.S.C. 1395y(b). Information to shall be limited to Medicare
utilization data necessary to perform that specific function. In order to receive the
information, they must agree to:
a. Certify that the individual about whom the information is being provided
is one of its insured or employees, or is insured and/or employed by
another entity for whom they serve as a TPA;
b. Utilize the information solely for the purpose of processing the
individual’s insurance claims; and
c. Safeguard the confidentiality of the data and prevent unauthorized access.
Other insurers may require LTCMDS information in order to support evaluations
and monitoring of Medicare clams, information of beneficiaries, including proper
reimbursement for services provided.
5. To an individual or organization for research, evaluation, or epidemiological
projects related to the prevention of disease or disability, the restoration or
maintenance of health, or payment related projects;
6. To a Member of Congress or congressional staff member in response to an
inquiry of the congressional office made at the written request of the constituent
about whom the record is maintained;
7. To the Department of Justice (DOJ), court or adjudicatory body when:
a. The Agency or any component thereof;
b. Any employee of the Agency in his or her official capacity;
c. Any employee of the Agency in his or her individual capacity where the
DOJ has agreed to represent the employee; or
d. The United State Government, is a party to litigation or has an interest in
such litigation, and by careful review, CMS determines that the records
are both relevant and necessary to the litigation.
8. To a CMS contractor (including, but not limited to fiscal intermediaries and
carriers) that assists in the administration of a CMS-administered health benefits
program, or to a grantee of a CMS-administered grant program, when disclosure
is deemed reasonably necessary by CMS to prevent, deter, discover, detect,
investigate, examine, prosecute, sue with respect to, defend against, correct,
remedy, or otherwise combat fraud or abuse in such program;
9. To another Federal agency or to an instrumentality of any governmental
jurisdiction within or under the control of the United States (including any state or
local government agency), that administers, or that has the authority to investigate
potential fraud or abuse in a health benefits program funded in whole or in part by
Federal funds, when disclosure is deemed reasonably necessary by CMS to
prevent, deter, discover, detect, investigate, examine, prosecute, sue with respect
to, defend against, correct, remedy, or otherwise combat fraud or abuse in such
programs. Other agencies may require LTCMDS information for the purpose of
combating fraud and abuse in such Federally funded programs; and
10. To a national accrediting organization whose accredited facilities are presumed to
meet certain Medicare requirements fro inpatient hospital (including swing beds)
services; e.g., the Joint Commission for the Accrediting of Healthcare
Organizations (JCAHO). Information will be released to accrediting
organizations only for those facilities that they accredit and that participate in the
Medicare program.
4146.7D - Access by an Individual to His or Her Own Records
(Rev. 1, 05-21-04)
Upon request by any individual with records contained in the system of records, the
System Manager or authorized designee shall permit the individual to review his/her
records and obtain a copy of all or any portion thereof (in a form comprehensible to the
individual) unless an exemption under the Privacy Act applies. Fees may be charged
only for the cost of copying the records, and not for time spent searching for the records
or determining whether to release the records. The individual may have another person
accompany him/her while reviewing the records, but must furnish a written statement
authorizing disclosure and discussion of the records in the accompanying person’s
presence. The individual may request amendment of any portion of his/her records which
is not accurate, relevant, timely or complete.
4146.7E - Criminal Penalties for Improper Disclosure
(Rev. 1, 05-21-04)
Under the Federal Privacy Act, the following criminal penalties may be applicable:
• Any officer or employee of the State who intentionally discloses individually
identifiable information prohibited from disclosure under the Privacy Act, shall be
guilty of a misdemeanor and fined not more than $5,000;
• Any officer or employee of the State who willfully maintains a system of records
without meeting the notice requirements of the Privacy Act shall be guilty of a
misdemeanor and fined not more than $5,000; and
• Any individual who knowingly and willfully requests or obtains any record
concerning an individual from an agency under false pretenses shall be guilty of a
misdemeanor and fined not more than $5,000.