State Operations Manual (Pub. 100-07), Ch. 4 § 4146.7

Privacy and Confidentiality

Last amended: 2004Year: 2004Length: 2,030 wordsOfficial source
4146.7 - Privacy and Confidentiality (Rev. 1, 05-21-04) 4146.7A - System of Records (Rev. 1, 05-21-04) The MDS database is operated and maintained by States as a Federal database and, as such, is subject to the requirements of the Federal Privacy Act. The text of the System of Records notice for the MDS, which follows, describes the legal requirements regarding privacy and disclosure of information by CMS or the State. The purpose of the Long Term Care Minimum Data Set (LTC MDS) System NO. 09-70-1517 is to aid in the administration of the survey and certification of Medicare/Medicaid long term care facilities and to study the effectiveness and quality of care given in those facilities. This system supports regulatory, reimbursement, policy and research functions. In addition, this system will enable Federal and State regulators to provide long term care facility staff with outcome data for provider’s internal quality improvement activities. This system shall contain clinical information found in the comprehensive assessments of persons residing in long term care facilities that are certified to participate in the Medicare and/or Medicaid programs (including private pay individuals). This information is found in the Long Term Care Minimum Data Set for Nursing Home Resident Assessment.” The CMS established this system in accordance with the principles and requirements of the Privacy Act. The Privacy Act allows the disclosure of information from this system without an individual’s consent if the information is to be used for a purpose that is compatible with the purposes for which the information was collected. Any such compatible use of data is known as a “routine use.” The proposed routine uses for this system meet the compatibility requirement of the Privacy Act since they are consistent with the purpose of analyzing data on the physical, mental, functional, and psychosocial status of nursing facility residents living in the State. The routine uses specify the circumstances under which CMS and the State in their roles as contractors representing CMS may release information from the long-term care MDS system without the consent of the individual to whom such information pertains. The CMS System Manager must evaluate each proposed disclosure of information under the routine uses and/or an individual authorized by CMS. The authority to release data is limited to the System Manager or authorized designee. 4146.7B - Procedures for Disclosure of Information Pursuant to Data Use Agreement (Rev. 1, 05-21-04) Releases of information must be evaluated to determine if disclosure is legally permissible by the CMS System Manager or authorized designee, including but not limited to ensuring that the purpose of the disclosure is compatible with the purpose for which the information was collected. Releases are generally only made for the routine uses specified in the system notice. The CMS System Manager or authorized designee must require each prospective recipient of LTC MDS system information to agree in writing to certain conditions to ensure the continuing confidentiality and to physically safeguard of the information. For each disclosure it is necessary for the System Manager or authorized designee to, as necessary and appropriate: 1. Determine that no other Federal statute specifically prohibits disclosure of the information; 2. Determine that the use or disclosure does not violate legal limitations under which the information was provided, collected, or obtained; 3. Determine the purpose for which the disclosure is to be made: a. Cannot reasonably be accomplished unless the information is provided in individually identifiable form; b. Is of sufficient importance to warrant the effect on or the risk to the privacy of the individual(s) that additional exposure of the record(s) might bring; c. There is a reasonable probability that the purpose of the disclosure will be accomplished; and d. The purpose is within the scope of a routine use. 4. Require the recipient of the information to: a. Establish reasonable administrative, technical, and physical safeguards to prevent unauthorized access, use, or disclosure of the record or any part thereof. The physical safeguards shall provide a level of security that is at least equivalent to the level of security contemplated in OMB Circular No. A-130 (revised), Appendix III, Security of Federal Automated Information Systems, which sets forth guidelines for security plans for automated information systems in Federal agencies; contemplated in OMB Circular No. A-130 (revised), Appendix III, Security of Federal Automated Information Systems, which sets forth guidelines for security plans for automated information systems in Federal agencies; b. Remove or destroy the information that allows subject individual(s) to be identified at the earliest time at which removal or destruction can be accomplished, consistent with the purpose of the request; c. Refrain from using or disclosing the information for any purpose other than the stated purpose under which the information was disclosed; and d. Make no further use or disclosure of the information except: ● To prevent or address an emergency directly affecting the health or safety of an individual; ● For use on another project under the same conditions, provided the System Manager or authorized designee has authorized the additional use(s) in writing; or ● When required by law. 5. Secure a written statement or agreement from the prospective recipient of the information whereby the prospective recipient attests to an understanding of, and willingness to abide by the foregoing provisions and any additional provisions that the System Manager deems appropriate in the particular circumstance. The System Manager or authorized designee must use a CMS-approved Data Release Agreement that cannot be modified; and 6. Determine whether the disclosure constitutes a computer “matching program” as defined in 5 U.S.C. §552a(a)(8). If the disclosure is determined to be a computer “matching program” the instructions regarding preparation and transmission of a matching agreement as stated in 5 U.S.C. §552a(o) must be followed. 4146.7C - Routine Uses (Rev. 1, 05-21-04) The following lists the routine uses published in the LTC MDS System NO. 09-70-1517 (current as of February 2002). Disclosure may be made: 1. To Agency contractors, or consultants who have been engaged by the Agency to assist in accomplishment of a CMS function relating to the purposes for this system and who need to have access to the records in order to assist CMS; 2. To another Federal or state agency, agency of a state government, and agency established by state law, or its fiscal agent to: a. Contribute to the accuracy of CMS’ proper payment of Medicare benefits; b. Enable such agency to administer a Federal health benefits program, or as necessary to enable such agency to fulfill a requirement of a Federal statute or regulation that implements a health benefit program funded in whole or in part with Federal funds, and/or; c. Assist Federal/state Medicaid programs within the state. 3. To QIOs in connection with review of claims, or in connection with studies or other review activities, conducted pursuant to Part B of Title XI of the Act and in performing affirmative outreach activities to individuals for the purpose of establishing and maintaining their entitlement to Medicare benefits or health insurance plans; 4. To insurance companies, underwriters, third parties administrators (TPA), employers, self-insurers, group health plans, health maintenance organizations (HMO), health and welfare benefit funds, managed care organizations, other supplemental insurers, non-coordinating insurers, multiple employer trusts, liability insurers, no-fault medical automobile insurers, workers compensation carriers or plans, other groups providing protection against medical expenses without the beneficiary’s authorization, and any entity having knowledge of the occurrence of any event affecting (a) an individual’s right to any such benefit or payment, or (b) the initial right to any such benefit or payment, for the purpose of coordinating of benefits with Medicare program and implementation of MSP provision at 42 U.S.C. 1395y(b). Information to shall be limited to Medicare utilization data necessary to perform that specific function. In order to receive the information, they must agree to: a. Certify that the individual about whom the information is being provided is one of its insured or employees, or is insured and/or employed by another entity for whom they serve as a TPA; b. Utilize the information solely for the purpose of processing the individual’s insurance claims; and c. Safeguard the confidentiality of the data and prevent unauthorized access. Other insurers may require LTCMDS information in order to support evaluations and monitoring of Medicare clams, information of beneficiaries, including proper reimbursement for services provided. 5. To an individual or organization for research, evaluation, or epidemiological projects related to the prevention of disease or disability, the restoration or maintenance of health, or payment related projects; 6. To a Member of Congress or congressional staff member in response to an inquiry of the congressional office made at the written request of the constituent about whom the record is maintained; 7. To the Department of Justice (DOJ), court or adjudicatory body when: a. The Agency or any component thereof; b. Any employee of the Agency in his or her official capacity; c. Any employee of the Agency in his or her individual capacity where the DOJ has agreed to represent the employee; or d. The United State Government, is a party to litigation or has an interest in such litigation, and by careful review, CMS determines that the records are both relevant and necessary to the litigation. 8. To a CMS contractor (including, but not limited to fiscal intermediaries and carriers) that assists in the administration of a CMS-administered health benefits program, or to a grantee of a CMS-administered grant program, when disclosure is deemed reasonably necessary by CMS to prevent, deter, discover, detect, investigate, examine, prosecute, sue with respect to, defend against, correct, remedy, or otherwise combat fraud or abuse in such program; 9. To another Federal agency or to an instrumentality of any governmental jurisdiction within or under the control of the United States (including any state or local government agency), that administers, or that has the authority to investigate potential fraud or abuse in a health benefits program funded in whole or in part by Federal funds, when disclosure is deemed reasonably necessary by CMS to prevent, deter, discover, detect, investigate, examine, prosecute, sue with respect to, defend against, correct, remedy, or otherwise combat fraud or abuse in such programs. Other agencies may require LTCMDS information for the purpose of combating fraud and abuse in such Federally funded programs; and 10. To a national accrediting organization whose accredited facilities are presumed to meet certain Medicare requirements fro inpatient hospital (including swing beds) services; e.g., the Joint Commission for the Accrediting of Healthcare Organizations (JCAHO). Information will be released to accrediting organizations only for those facilities that they accredit and that participate in the Medicare program. 4146.7D - Access by an Individual to His or Her Own Records (Rev. 1, 05-21-04) Upon request by any individual with records contained in the system of records, the System Manager or authorized designee shall permit the individual to review his/her records and obtain a copy of all or any portion thereof (in a form comprehensible to the individual) unless an exemption under the Privacy Act applies. Fees may be charged only for the cost of copying the records, and not for time spent searching for the records or determining whether to release the records. The individual may have another person accompany him/her while reviewing the records, but must furnish a written statement authorizing disclosure and discussion of the records in the accompanying person’s presence. The individual may request amendment of any portion of his/her records which is not accurate, relevant, timely or complete. 4146.7E - Criminal Penalties for Improper Disclosure (Rev. 1, 05-21-04) Under the Federal Privacy Act, the following criminal penalties may be applicable: • Any officer or employee of the State who intentionally discloses individually identifiable information prohibited from disclosure under the Privacy Act, shall be guilty of a misdemeanor and fined not more than $5,000; • Any officer or employee of the State who willfully maintains a system of records without meeting the notice requirements of the Privacy Act shall be guilty of a misdemeanor and fined not more than $5,000; and • Any individual who knowingly and willfully requests or obtains any record concerning an individual from an agency under false pretenses shall be guilty of a misdemeanor and fined not more than $5,000.
State Operations Manual (Pub. 100-07), Ch. 4 § 4146.7: Privacy and Confidentiality | Justis AI