Sie sind auf Seite 1von 5

63902 Federal Register / Vol. 72, No.

218 / Tuesday, November 13, 2007 / Notices

Prevention (CDC), and the Director, National provide guidance on the Institute’s research planned to provide a centralized user
Centers for Injury Prevention and Control activities related to developing and provisioning and administration service
(NCIPC) regarding feasible goals for the evaluating hypotheses, systematically that supports the creation, deletion, and
prevention and control of injury. The documenting findings and disseminating lifecycle management of enterprise
committee makes recommendations results. The Board shall evaluate the degree
regarding policies, strategies, objectives, and to which the activities of the National identities. This service creates accounts,
priorities, and reviews progress toward injury Institute for Occupational Safety and Health: supports Role Based Access Control
prevention and control. (1) Conform to appropriate scientific (RBAC), and provides business
Matters to be Discussed: The meeting will standards, (2) address current, relevant application integration points. RBAC is
open to the public. The Advisory Committee needs, and (3) produce intended results. a form flow approval process and
for Injury Prevention and Control (ACIPC) Matters To Be Discussed: NIOSH Response enterprise identity audit and
will be discussing partnership activities and to the National Academies of Science recertification based on the role of the
how the ACIPC can advance the field of Program Reviews. individual. The business application
injury prevention and control. Agenda items Agenda items are subject to change as
are subject to change as priorities dictate. integration point allows business
priorities dictate.
Contact Person for More Information: Ms. For Further Information Contact: Roger application owners to use the form flow
Amy Harris, Executive Secretary, ACIPC, Rosa, Executive Secretary, BSC, NIOSH, CDC, process of the user provisioning service
NCIPC, CDC, 4770 Buford Highway, NE., 395 E Street, SW., Suite 9200, Patriots Plaza to approve or deny requests for access
M/S K61, Atlanta, Georgia 30341–3724, Building, Washington, DC 20201, telephone to business applications. This
telephone (770) 488–4936. (202) 245–0655, fax (202) 245–0664. modification will permit CMS to
The Director, Management Analysis and The Director, Management Analysis and implement a unified framework for
Services Office, has been delegated the Services Office, has been delegated the managing user information and access
authority to sign Federal Register notices authority to sign Federal Register notices
pertaining to announcements of meetings and rights, for those individuals who apply
pertaining to announcements of meetings and
other committee management activities, for for and are granted access across
other committee management activities for
both CDC and the Agency for Toxic both the CDC and the Agency for Toxic multiple CMS systems and business
Substances and Disease Registry. Substances and Disease Registry. contexts.
Dated: November 5, 2007.
We propose to modify existing routine
Dated: November 5, 2007. use number 1 that permits disclosure to
Elaine L. Baker, Elaine L. Baker, agency contractors and consultants to
Director, Management Analysis and Services Director, Management Analysis and Services include disclosure to CMS grantees who
Office, Centers for Disease Control and Office, Centers for Disease Control and perform a task for the agency. CMS
Prevention. Prevention (CDC). grantees, charged with completing
[FR Doc. E7–22149 Filed 11–9–07; 8:45 am] [FR Doc. E7–22155 Filed 11–9–07; 8:45 am] projects or activities that require CMS
BILLING CODE 4163–18–P BILLING CODE 4163–18–P data to carry out that activity, are
classified separate from CMS
contractors and/or consultants. The
DEPARTMENT OF HEALTH AND DEPARTMENT OF HEALTH AND modified routine use will remain as
HUMAN SERVICES HUMAN SERVICES routine use number 1. We will delete
Centers for Disease Control and routine use number 2 authorizing
Centers for Medicare & Medicaid disclosure to support constituent
Prevention Services requests made to a congressional
Board of Scientific Counselors, representative. If an authorization for
Privacy Act of 1974; Report of a
National Institute for Occupational the disclosure has been obtained from
Modified System of Records
Safety and Health (BSC, NIOSH) the data subject, then no routine use is
AGENCY: Centers for Medicare & needed. The Privacy Act allows for
In accordance with section 10(a)(2) of Medicaid Services (CMS), Department disclosures with the ‘‘prior written
the Federal Advisory Committee Act of Health and Human Services (HHS). consent’’ of the data subject. Finally, we
(Pub. L. 92–463), the Centers for Disease ACTION: Notice of a Modified System of will delete the section titled
Control and Prevention (CDC) Records (SOR). ‘‘Additional Circumstances Affecting
announces the following meeting for the Routine Use Disclosures,’’ that
aforementioned committee: SUMMARY: In accordance with the addresses ‘‘Protected Health Information
Time and Date: 10 a.m.–2 p.m., December requirements of the Privacy Act of 1974, (PHI)’’ and ‘‘small cell size.’’ The
13, 2007. we are proposing to modify an existing requirement for compliance with HHS
Place: Holiday Inn Capitol, 550 C Street, SOR titled, ‘‘Individuals Authorized regulation ‘‘Standards for Privacy of
SW., Washington, DC 20024. Access to Centers for Medicare & Individually Identifiable Health
Status: Open to the public, limited only by Medicaid Services (CMS) Computer Information’’ does not apply because
the space available. The meeting room Services (IACS), System No. 09–70– this system does not collect or maintain
accommodates approximately 50 people.
0064,’’ most recently modified at 67 FR PHI. In addition, our policy to prohibit
Teleconference available toll-free; please dial
(888) 677–1819, Participant Pass Code 25404. 48911 (July 26, 2002). We propose to release if there is a possibility that an
Purpose: The Secretary, the Assistant assign a new CMS identification number individual can be identified through
Secretary for Health, and by delegation the to this system to simplify the obsolete ‘‘small cell size’’ is not applicable to the
Director, Centers for Disease Control and and confusing numbering system data maintained in this system.
Prevention, are authorized under sections originally designed to identify the We are modifying the language in the
301 and 308 of the Public Health Service Act Bureau, Office, or Center that remaining routine uses to provide a
to conduct directly or by grants or contracts, maintained information in the Health proper explanation as to the need for the
research, experiments, and demonstrations
rfrederick on PROD1PC67 with NOTICES

Care Financing Administration systems routine use and to provide clarity to


relating to occupational safety and health and
to mine health. The Board of Scientific of records. The new identifying number CMS’s intention to disclose individual-
Counselors shall provide guidance to the for this system should read: System No. specific information contained in this
Director, National Institute for Occupational 09–70–0538. system. The routine uses will then be
Safety and Health on research and prevention We propose to broaden the scope of prioritized and reordered according to
programs. Specifically, the Board shall this system to include a CMS service their usage. We will also take the

VerDate Aug<31>2005 15:30 Nov 09, 2007 Jkt 214001 PO 00000 Frm 00030 Fmt 4703 Sfmt 4703 E:\FR\FM\13NON1.SGM 13NON1
Federal Register / Vol. 72, No. 218 / Tuesday, November 13, 2007 / Notices 63903

opportunity to update any sections of Design & Development Group, Office of approve or deny requests for access to
the system that were affected by the Information Services, CMS, Room N2– business applications.
recent reorganization or because of the 15–04, 7500 Security Boulevard, Initial users of the IACS will be
impact of the Medicare Prescription Baltimore, Maryland 21244–1850. Her primarily CMS business partners such
Drug, Improvement, and Modernization telephone number is 410–786–0167, or as health care plans and customer
Act of 2003 (MMA) (Pub. L. 108–173) e-mail at Nancy.Martin@cms.hhs.gov. inquiry service personnel who answer
provisions and to update language in SUPPLEMENTARY INFORMATION: The IACS queries to 1–800–MEDICARE. Three
the administrative sections to framework consists of two major entities are key in providing this
correspond with language used in other components: An identity management support: The Customer Support for
CMS SORs. service and a set of authentication or Medicare Modernization Support, the
The primary purpose of the system access management services. These two CMS IT CITIC Service Desk and the
has been to collect and maintain components will enable a single identity Centers for Beneficiary Choices. Future
individually identifiable information to to be used throughout CMS and will users will consist of but are not limited
assign, control, track, and report ensure that users authenticate to to, individuals who apply from Plans
authorized access to and use of CMS’s applications using a level of assurance and Providers, Provider Hospitals,
computerized information and equal to the sensitivity of the Group Practitioners, Physicians and
resources, for those individuals who application and/or data. As CMS moves Beneficiaries.
apply for and are granted access across into the web-enabled application arena
multiple CMS systems and business I. Description of the Modified System of
for mission critical applications, the Records
contexts. Information in this system will need to securely manage this
also be used to: (1) Support regulatory environment is a major concern. The A. Statutory and Regulatory Basis for
and policy functions performed within Health Insurance Portability and the System
the Agency or by a contractor, Accountability Act of 1996 (HIPAA) Authority for maintenance of the
consultant, or CMS grantee; and (2) requirements, e-Authentication system is given under Executive Order
support litigation involving the Agency guidance and the Personal Identity 9397, the Debt Collection Improvement
related to this system. We have Verification initiative make the need for Act, 31 United States Code (U.S.C.)
provided background information about a security services framework even more § 7701(c)(1), and 5 U.S.C. 552a(b)(1).
the modified system in the important.
‘‘Supplementary Information’’ section B. Collection and Maintenance of Data
CMS has provided an application that
below. Although the Privacy Act in the System
will streamline our information
requires only that the ‘‘routine use’’ technology environment so that existing Information for this system is
portion of the system be published for and new applications can work more collected and maintained on individuals
comment, CMS invites comments on all effectively by sharing information, and who voluntarily apply for access to the
portions of this notice. See EFFECTIVE so that CMS can be more responsive to Web-based Application Systems and
DATES section for comment period. the demands of changing business needs individuals with an approved need for
EFFECTIVE DATES: CMS filed a modified and emerging technology. CMS plans to access to the computer resources and
system report with the Chair of the make our data more readily accessible to information maintained by CMS.
House Committee on Government our beneficiaries, partners, and Information collected for this system
Reform and Oversight, the Chair of the stakeholders in a secure, efficient, and will include, but is not limited to, name,
Senate Committee on Homeland carefully planned manner. In striving to social security number, date of birth,
Security and Governmental Affairs, and meet these goals, CMS has established a current Resource Access Control
the Administrator, Office of Information target enterprise architecture and Facility Identification (RACF ID), e-mail
and Regulatory Affairs, Office of modernization strategy that is based address, telephone number, company
Management and Budget (OMB) on upon several key design principles: (1) name, and geographic location.
November 7, 2007. To ensure that all An established, secure Internet II. Agency Policies, Procedures, and
parties have adequate time in which to architecture for the CMS enterprise; (2) Restrictions on the Routine Use
comment, the modified SOR, including Defined products for the target
routine uses, will become effective 40 enterprise architecture; (3) Defined A. Agency Policies, Procedures, and
days from the publication of the notice, security classifications and controls for Restrictions on the Routine Use
or from the date it was submitted to CMS applications; (4) Defined security The Privacy Act permits us to disclose
OMB and the Congress, whichever is services that support the architecture information without an individual’s
later, unless CMS receives comments and implement the controls; and (5) consent if the information is to be used
that require alterations to this notice. Prescriptive application development for a purpose that is compatible with the
ADDRESSES: The public should address standards and guidelines for the target purpose(s) for which the information
comments to: CMS Privacy Officer, environment. was collected. Any such disclosure of
Division of Privacy Compliance, When an account/identity is created, data is known as a ‘‘routine use.’’ The
Enterprise Architecture and Strategy a unique identifier will be generated to government will only release IACS
Group, Office of Information Services, universally associate a user with CMS. information that can be associated with
CMS, Room N2–04–27, 7500 Security The provisioning service uses a seven- an individual as provided for under
Boulevard, Baltimore, Maryland 21244– character algorithm to generate user IDs ‘‘Section III. Proposed Routine Use
1850. Comments received will be that are unique across the CMS Disclosures of Data in the System.’’ Both
available for review at this location, by enterprise. The provisioning service will identifiable and non-identifiable data
appointment, during regular business
rfrederick on PROD1PC67 with NOTICES

also provide a mechanism to assign may be disclosed under a routine use.


hours, Monday through Friday from 9 roles that will be maintained in the We will only collect the minimum
a.m.–3 p.m., Eastern Time zone. central data store. An application personal data necessary to achieve the
FOR FURTHER INFORMATION CONTACT: integration point will be established to purpose of IACS. CMS has the following
Nancy Martin, Division of Development allow business application owners to policies and procedures concerning
& Engineering, Information Services use the user provisioning service to disclosures of information that will be

VerDate Aug<31>2005 15:30 Nov 09, 2007 Jkt 214001 PO 00000 Frm 00031 Fmt 4703 Sfmt 4703 E:\FR\FM\13NON1.SGM 13NON1
63904 Federal Register / Vol. 72, No. 218 / Tuesday, November 13, 2007 / Notices

maintained in the system. Disclosure of into a contractual or similar agreement and Federal, HHS, and CMS policies
information from the system will be with a third party to assist in and standards as they relate to
approved only to the extent necessary to accomplishing CMS functions relating information security and data privacy.
accomplish the purpose of the to purposes for this system. These laws and regulations include but
disclosure and only after CMS: CMS occasionally contracts out are not limited to: the Privacy Act of
1. Determines that the use or certain of its functions when this would 1974; the Federal Information Security
disclosure is consistent with the reason contribute to effective and efficient Management Act of 2002; the Computer
that the data is being collected, e.g., to operations. CMS must be able to give a Fraud and Abuse Act of 1986; the
collect and maintain individually contractor, consultants, or grantee Health Insurance Portability and
identifiable information to assign, whatever information is necessary for Accountability Act of 1996; the E-
control, track, and report authorized the contractor to fulfill its duties. In Government Act of 2002, the Clinger-
access to and use of CMS’s these situations, safeguards are provided Cohen Act of 1996; the Medicare
computerized information and in the contract prohibiting the Modernization Act of 2003, and the
resources. contractor, consultants, or grantee from corresponding implementing
2. Determines that: using or disclosing the information for regulations. OMB Circular A–130,
a. The purpose for which the any purpose other than that described in Management of Federal Resources,
disclosure is to be made can only be the contract and to return or destroy all Appendix III, Security of Federal
accomplished if the record is provided information at the completion of the Automated Information Resources also
in individually identifiable form; contract. applies. Federal, HHS, and CMS
b. The purpose for which the 2. To assist the Department of Justice policies and standards include but are
disclosure is to be made is of sufficient (DOJ), court or adjudicatory body when not limited to: all pertinent National
importance to warrant the effect and/or a. The Agency or any component Institute of Standards and Technology
risk on the privacy of the individual that thereof; or publications; HHS Information Systems
additional exposure of the record might b. Any employee of the Agency in his Program Handbook and the CMS
bring; and or her official capacity; or Information Security Handbook.
c. There is a strong probability that c. Any employee of the Agency in his
the proposed use of the data would in or her individual capacity where the V. Effects of the Modified System of
fact accomplish the stated purpose(s). DOJ has agreed to represent the Records on Individual Rights
3. Requires the information recipient employee; or CMS proposes to establish this system
to: d. The United States Government; is
in accordance with the principles and
a. Establish administrative, technical, a party to litigation or has an interest in
requirements of the Privacy Act and will
and physical safeguards to prevent such litigation, and by careful review,
collect, use, and disseminate
unauthorized use of disclosure of the CMS determines that the records are
information only as prescribed therein.
record; both relevant and necessary to the
Data in this system will be subject to the
b. Remove or destroy at the earliest litigation.
Whenever CMS is involved in authorized releases in accordance with
time all patient-identifiable information;
litigation, or occasionally when another the routine uses identified in this
and
party is involved in litigation and CMS’s system of records.
c. Agree to not use or disclose the
information for any purpose other than policies or operations could be affected CMS will take precautionary
the stated purpose under which the by the outcome of the litigation, CMS measures to minimize the risks of
information was disclosed. would be able to disclose information to unauthorized access to the records and
4. Determines that the data are valid the DOJ, court or adjudicatory body the potential harm to individual privacy
and reliable. involved. A determination would be or other personal or property rights of
made in each instance that, under the patients whose data are maintained in
III. Proposed Routine Use Disclosures the system. CMS will collect only that
circumstances involved, the purposes
of Data in the System information necessary to perform the
served by the use of the information in
A. The Privacy Act allows us to the particular litigation is compatible system’s functions. In addition, CMS
disclose information without an with a purpose for which CMS collects will make disclosure from the modified
individual’s consent if the information the information. system only with consent of the subject
is to be used for a purpose that is individual, or his/her legal
compatible with the purpose(s) for IV. Safeguards representative, or in accordance with an
which the information was collected. CMS has safeguards in place for applicable exception provision of the
Any such compatible use of data is authorized users and monitors such Privacy Act. CMS, therefore, does not
known as a ‘‘routine use.’’ The proposed users to ensure against unauthorized anticipate an unfavorable effect on
routine uses in this system meet the use. Personnel having access to the individual privacy as a result of the
compatibility requirement of the Privacy system have been trained in the Privacy disclosure of information relating to
Act. We are proposing to establish the Act and information security individuals.
following routine use disclosures of requirements. Employees who maintain Dated: November 7, 2007.
information maintained in the system: records in this system are instructed not Charlene Frizzera,
1. To support Agency contractors, to release data until the intended Chief Operating Officer, Centers for Medicare
consultants, or CMS grantee who have recipient agrees to implement & Medicaid Services.
been contracted by the Agency to assist appropriate management, operational
in accomplishment of a CMS function and technical safeguards sufficient to System No.: 09–70–0538
rfrederick on PROD1PC67 with NOTICES

relating to the purposes for this system protect the confidentiality, integrity and
SYSTEM NAME:
and who need to have access to the availability of the information and
records in order to assist CMS. information systems and to prevent ‘‘Individuals Authorized Access to
We contemplate disclosing unauthorized access. Centers for Medicare & Medicaid
information under this routine use only This system will conform to all Services (CMS) Computer Services
in situations in which CMS may enter applicable Federal laws and regulations (IACS), HHS/CMS/OIS’’.

VerDate Aug<31>2005 15:30 Nov 09, 2007 Jkt 214001 PO 00000 Frm 00032 Fmt 4703 Sfmt 4703 E:\FR\FM\13NON1.SGM 13NON1
Federal Register / Vol. 72, No. 218 / Tuesday, November 13, 2007 / Notices 63905

SECURITY CLASSIFICATION: been contracted by the Agency to assist Appendix III, Security of Federal
Level 3 Privacy Act Sensitive. in accomplishment of a CMS function Automated Information Resources also
relating to the purposes for this system applies. Federal, HHS, and CMS
SYSTEM LOCATION:
and who need to have access to the policies and standards include but are
Centers for Medicare & Medicaid records in order to assist CMS. not limited to: all pertinent National
Services Data Center, 7500 Security 2. To assist the Department of Justice Institute of Standards and Technology
Boulevard, North Building, First Floor, (DOJ), court or adjudicatory body when publications; HHS Information Systems
Baltimore, Maryland 21244–1850. a. The Agency or any component Program Handbook and the CMS
CATEGORIES OF INDIVIDUALS COVERED BY THE thereof; or Information Security Handbook.
SYSTEM: b. Any employee of the Agency in his
or her official capacity; or RETENTION AND DISPOSAL:
Information for this system is
collected and maintained on individuals c. Any employee of the Agency in his CMS will retain information for the
who voluntarily apply for access to the or her individual capacity where the duration the user needs access to CMS’
Web-based Application Systems and DOJ has agreed to represent the computer systems or until no longer
individuals with an approved need for employee; or needed for administrative, legal, audit
access to the computer resources and d. The United States Government; or other operations services, whichever
information maintained by CMS. is a party to litigation or has an is longer. All claims-related records are
interest in such litigation, and by careful encompassed by the document
CATEGORIES OF RECORDS IN THE SYSTEM: review, CMS determines that the preservation order and will be retained
Information collected for this system records are both relevant and necessary until notification is received from DOJ.
will include, but is not limited to, name, to the litigation.
social security number (SSN), date of SYSTEM MANAGER AND ADDRESS:
birth, current Resource Access Control POLICIES AND PRACTICES FOR STORING,
RETRIEVING, ACCESSING, RETAINING, AND Director, Division of Development &
Facility Identification (RACF ID), e-mail
DISPOSING OF RECORDS IN THE SYSTEM: Engineering, Information Services
address, telephone number, company
name, and geographic location. STORAGE: Design & Development Group, Office of
All records are stored on magnetic Information Services, CMS, Mail Stop
AUTHORITY FOR MAINTENANCE OF THE SYSTEM: N2–15–18, 7500 Security Boulevard,
media.
Authority for maintenance of the Baltimore, Maryland, 21244–1850.
system is given under Executive Order RETRIEVABILITY:
9397, the Debt Collection Improvement Information can be retrieved by NOTIFICATION PROCEDURE:
Act, 31 United States Code (U.S.C.) assigned User ID, user name, and user For purpose of access, the subject
§ 7701(c)(1), and 5 U.S.C. 552a(b)(1). e-mail address. individual should write to the system
PURPOSE(S) OF THE SYSTEM: SAFEGUARDS:
manager who will require the system
The primary purpose of the system name, and for verification purposes, the
CMS has safeguards in place for subject individual’s name (woman’s
has been to collect and maintain authorized users and monitors such
individually identifiable information to maiden name, if applicable), and SSN
users to ensure against unauthorized (furnishing the SSN is voluntary, but it
assign, control, track, and report use. Personnel having access to the
authorized access to and use of CMS’s may make searching for a record easier
system have been trained in the Privacy and prevent delay).
computerized information and Act and information security
resources, for those individuals who requirements. Employees who maintain RECORD ACCESS PROCEDURE:
apply for and are granted access across records in this system are instructed not
multiple CMS systems and business to release data until the intended For purpose of access, use the same
contexts. Information in this system will recipient agrees to implement procedures outlined in Notification
also be used to: (1) Support regulatory appropriate management, operational Procedures above. Requestors should
and policy functions performed within and technical safeguards sufficient to also reasonably specify the record
the Agency or by a contractor, protect the confidentiality, integrity and contents being sought. (These
consultant, or CMS grantee; and (2) availability of the information and procedures are in accordance with
support litigation involving the Agency information systems and to prevent Department regulation 45 CFR
related to this system. unauthorized access. 5b.5(a)(2).)
ROUTINE USES OF RECORDS MAINTAINED IN THE This system will conform to all CONTESTING RECORD PROCEDURES:
SYSTEM, INCLUDING CATEGORIES OR USERS AND applicable Federal laws and regulations
THE PURPOSES OF SUCH USES: and Federal, HHS, and CMS policies The subject individual should contact
A. The Privacy Act allows us to and standards as they relate to the system manager named above, and
disclose information without an information security and data privacy. reasonably identify the record and
individual’s consent if the information These laws and regulations include but specify the information to be contested.
is to be used for a purpose that is are not limited to: the Privacy Act of State the corrective action sought and
compatible with the purpose(s) for 1974; the Federal Information Security the reasons for the correction with
which the information was collected. Management Act of 2002; the Computer supporting justification. (These
Any such compatible use of data is Fraud and Abuse Act of 1986; the procedures are in accordance with
known as a ‘‘routine use.’’ The proposed Health Insurance Portability and Department regulation 45 CFR 5b.7.)
routine uses in this system meet the Accountability Act of 1996; the E-
RECORD SOURCE CATEGORIES:
rfrederick on PROD1PC67 with NOTICES

compatibility requirement of the Privacy Government Act of 2002, the Clinger-


Act. We are proposing to establish the Cohen Act of 1996; the Medicare Sources of information contained in
following routine use disclosures of Modernization Act of 2003, and the this records system include data
information maintained in the system: corresponding implementing collected from applications submitted
1. To support Agency contractors, regulations. OMB Circular A–130, by the individuals requiring access to
consultants, or CMS grantee who have Management of Federal Resources, computer services.

VerDate Aug<31>2005 15:30 Nov 09, 2007 Jkt 214001 PO 00000 Frm 00033 Fmt 4703 Sfmt 4703 E:\FR\FM\13NON1.SGM 13NON1
63906 Federal Register / Vol. 72, No. 218 / Tuesday, November 13, 2007 / Notices

SYSTEMS EXEMPTED FROM CERTAIN PROVISIONS Information will be released to these administration of Federal and state HHA
OF THE ACT: organizations for only those facilities programs within the state; and (7)
None. that they accredit and that participate in monitor the continuity of care for
[FR Doc. E7–22079 Filed 11–9–07; 8:45 am] the Medicare program and if they meet patients who reside temporarily outside
the following requirements: (1) Provide of the state. Information maintained in
BILLING CODE 4120–03–P
identifying information for HHAs that this system will also be disclosed to: (1)
have an accreditation status with the Support regulatory, reimbursement, and
DEPARTMENT OF HEALTH AND requesting deemed organization, (2) policy functions performed within the
HUMAN SERVICES submission of a finder file identifying Agency or by a contractor, consultant, or
beneficiaries/patients receiving HHA grantee; (2) assist another Federal and/
Centers for Medicare & Medicaid services, (3) safeguard the or state agency, agency of a state
Services confidentiality of the data and prevent government, an agency established by
unauthorized access, and (4) upon state law, or its fiscal agent, for
Privacy Act of 1974; Report of a completion of a signed data exchange evaluating and monitoring the quality of
Modified or Altered System agreement or a CMS data use agreement. home health care and contribute to the
We will delete routine use number 7 accuracy of health insurance operations;
AGENCY: Department of Health and authorizing disclosure to support
Human Services (HHS), Centers for (3) support research, evaluation, or
constituent requests made to a epidemiological projects related to the
Medicare & Medicaid Services (CMS). congressional representative. If an
ACTION: Notice of a Modified or Altered
prevention of disease or disability, or
authorization for the disclosure has the restoration or maintenance of health,
System of Records (SOR). been obtained from the data subject, and for payment related projects; (4)
then no routine use is needed. The support the functions of Quality
SUMMARY: In accordance with the
Privacy Act allows for disclosures with Improvement Organizations (QIO); (5)
requirements of the Privacy Act of 1974, the ‘‘prior written consent’’ of the data
we are proposing to modify or alter an support the functions of national
subject. We will broaden the scope of
SOR titled ‘‘Home Health Agency (HHA) accrediting organizations; (6) support
published routine uses number 8 and 9,
Outcome and Assessment Information litigation involving the Agency; (7)
authorizing disclosures to combat fraud
Set (OASIS),’’ System No. 09–70–9002, combat fraud, waste, and abuse in
and abuse in the Medicare and
last modified at 66 Federal Register certain health care programs. We have
Medicaid programs to include
66903 (December 27, 2001). We propose provided background information about
combating ‘‘waste’’ which refers
to assign a new CMS identification the modified system in the
increasingly more to specific beneficiary
number to this system to simplify the SUPPLEMENTARY INFORMATION section
or recipient practices that result in
obsolete and confusing numbering unnecessary cost to Federally-funded below. Although the Privacy Act
system originally designed to identify health benefit programs. requires only that CMS provide an
the Bureau, Office, or Center that We are modifying the language in the opportunity for interested persons to
maintained information in the Health remaining routine uses to provide a comment on the routine uses, CMS
Care Financing Administration systems proper explanation as to the need for the invites comments on all portions of this
of records. The new assigned identifying routine use and to provide clarity to notice. See EFFECTIVE DATES section for
number for this system should read: CMS’s intention to disclose individual- comment period.
System No. 09–70–0522. specific information contained in this EFFECTIVE DATES: CMS filed a modified
We propose to modify existing routine system. The routine uses will then be or altered system report with the Chair
use number 1 that permits disclosure to prioritized and reordered according to of the House Committee on Government
agency contractors and consultants to their usage. We will also take the Reform and Oversight, the Chair of the
include disclosure to CMS grantees who opportunity to update any sections of Senate Committee on Homeland
perform a task for the agency. CMS the system that were affected by the Security & Governmental Affairs, and
grantees, charged with completing recent reorganization or because of the the Administrator, Office of Information
projects or activities that require CMS impact of the Medicare Prescription and Regulatory Affairs, Office of
data to carry out that activity, are Drug, Improvement, and Modernization Management and Budget (OMB) on
classified separate from CMS Act of 2003 (MMA) (Pub. L. 108–173) November 6, 2007. To ensure that all
contractors and/or consultants. The provisions and to update language in parties have adequate time in which to
modified routine use will remain as the administrative sections to comment, the modified system,
routine use number 1. We will modify correspond with language used in other including routine uses, will become
existing routine use number 4 that CMS SORs. effective 30 days from the publication of
permits disclosure to Peer Review The primary purposes of the SOR are the notice, or 40 days from the date it
Organizations (PRO). Organizations to collect and maintain information to: was submitted to OMB and Congress,
previously referred to as PROs will be (1) Study and help ensure the quality of whichever is later, unless CMS receives
renamed to read: Quality Improvement care provided by home health agencies
comments that require alterations to this
Organizations (QIO). Information will be (HHA); (2) aid in administration of the
notice.
disclosed to QIOs relating to assessing survey and certification of Medicare/
and improving HHA quality of care. The Medicaid HHAs; (3) enable regulators to ADDRESSES: The public should address
modified routine use will remain as provide HHAs with data for their comments to: CMS Privacy Officer,
routine use number 4. internal quality improvement activities; Division of Privacy Compliance,
CMS proposes to broaden the scope of (4) support agencies of the state Enterprise Architecture and Strategy
rfrederick on PROD1PC67 with NOTICES

the disclosure requirement for routine government to determine, evaluate and Group, Office of Information Services,
use number 5, authorizing disclosure to assess overall effectiveness and quality CMS, Room N2–04–27, 7500 Security
national accrediting organizations that of HHA services provided in the state; Boulevard, Baltimore, Maryland 21244–
have been approved by CMS for (5) provide for the validation, and 1850. Comments received will be
deeming authority for Medicare refinements of the Medicare Prospective available for review at this location, by
requirements for home health services. Payment System; (6) aid in the appointment, during regular business

VerDate Aug<31>2005 15:30 Nov 09, 2007 Jkt 214001 PO 00000 Frm 00034 Fmt 4703 Sfmt 4703 E:\FR\FM\13NON1.SGM 13NON1

Das könnte Ihnen auch gefallen