Privacy and Security Standards for Medicaid/CHIP/Health Insurance Exchange
|
|
|
- Collin Anderson
- 10 years ago
- Views:
Transcription
1 Privacy and Security Standards for Medicaid/CHIP/Health Insurance Exchange Melissa Cummings- Niedzwiecki, IRS John Chip Garner, CMS Tom Schankweiler, CMS
2 Changes with the ACA New Paradigm State Agencies will receive informa3on through the Data Services Hub (Hub) A State must comply with federal privacy and security standards, including the appropriate methods for safeguarding federal informa3on Described in the Exchange Final Rule* New State Agency IT System Paradigm No longer just sending files securely to CMS or accessing CMS custom built applica3on front ends (e.g. HITECH, MSIS, MCSIS, PERM) Now we will need to establish State IT System to CMS IT System direct connec3ons (e.g. State E&E to FFE, State E&E to Hub) Requires addi3onal rigor in establishing and documen3ng security controls *Section Available at -
3 New State Agency State Programs: Medicaid, CHIP,... SSA DHS FMS Applicant Web browser HHS Federal, Regional/State Exchange, & Contractors HHS HUB IRS Call Center Web browser Portal Portal Navigator Web browser Caseworker (in- person at Exchange) Web browser
4 Federal Interagency CMS is working to harmonize privacy and security standards for the types of informa3on a Health Insurance Exchange (HIX), Medicaid or CHIP program might use, collect or disclose CMS is partnering with federal agencies, including SSA, DHS, and IRS to ensure that States have adequate support and guidance regarding the privacy and security standards
5 Privacy and Security Standards Must establish and implement privacy and security standards that are consistent with the following seven principles: 1. Individual Access 2. Correc3on 3. Openness and Transparency 4. Collec3on, use, and disclosure limita3ons 5. Data quality and integrity 6. Safeguards 7. Accountability
6 Privacy and Security Guidance Exchange Reference Architecture (ERA) Supplements (Three documents) 1. Harmonized Security and Privacy Framework 2. Minimum Acceptable Risk Standards for Exchanges 3. Catalog of Minimum Acceptable Risk Controls for States
7 Required Documents from State Agencies Documents required to Connect with CMS systems (CALT document number) System Security Plan (doc7280, & doc2158)* Informa3on Security Risk Assessment (doc5299) * IRS Safeguard Procedures Report (doc8982) * Privacy Impact Assessment (doc4708) * Interconnec3on Security s (template(s) under development) * h_ps://calt.hhs.gov/
8 Master and ISA Document CMS will require State system owners to sign ISAs to ensure systems are secure prior to sharing informa7on through the Hub Data Exchange s Fed2Fed Master ISA DEAs MOUs CMAs IEAs ISAs Fed2Fed IRS Fed2Fed SSA Fed2Fed HHS Fed2Fed DHS Fed2Fed VHA Fed2Fed Peace Corps ISAs Fed2NonFed Master ISA State Exchanges State Medicaid Agencies Other
9 Federal to State Exchange s (IEAs) CMS will require new data sharing agreements exis7ng data sharing agreements to receive federal informa7on cannot be reused for this effort CMS DSH CMS FFE CMS IEA (DSH to State) State- Based Exchange State Medicaid and CHIP CMS IEA (FFE to State) Add HIPAA BAA if FFE: (1) Processing PHI (2) On behalf of Medicaid and CHIP CMS Contractors State Data Sharing (State agreement, no CMS involvement) Contractors need to be covered by a DUA
10 IRS Safeguard Requirements IRS is partnering with CMS/CCIIO to ensure the minimum security requirements include security controls for all data, including FTI Office of Safeguards is responsible for ensuring compliance with Publica3on 1075, Tax Informa3on Security Guidelines for Federal State and Local Agencies Safeguards will authorize the release of FTI with an approved Safeguard Procedures Report (SPR)
11 IRS Source Data Elements Provided for Insurance Affordability Program Eligibility I.R.C 6103(l)(21) authorizes the release of the following taxpayer informa3on: (i) taxpayer iden3ty informa3on; (ii) filing status; (iii) number of individuals for which a deduc3on under sec3on 151 was allowed (family size); (iv) modified adjusted gross income; and (v) taxable year to which any such informa3on relates or, alterna3vely, that such informa3on is not available. Trigger for disclosure is the filing of an applica3on for financial assistance No3ce of Proposed Rulemaking dated April 30, 2012 proposes addi3onal items of return informa3on that could be disclosed: See Federal Register, vol. 77, no. 83 (77 FR 25378)
12 Key Tenants of IRS Safeguards Recordkeeping Secure Storage Restric3ng Access Employee Awareness & Internal Inspec3ons Repor3ng Requirements Disposal Need and Use Computer Security
13 IRS Safeguards Efforts Support CMS in implemen3ng ACA rela3ve to the safeguarding of Federal Tax Informa3on Par3cipate in state reviews and CMS cross- func3onal working teams Provide guidance and assistance; FFE & Hub technical & program staff to discuss Federal Tax Informa3on security related topics Work directly with state agencies and contractors on State- specific issues
14 Info/TA available Contact your CCIIO or CMCS State Officer Melissa Cummings- Niedzwiecki - Melissa.Cummings- [email protected] John Chip Garner [email protected] Tom Schankweiler [email protected] Liz Kane [email protected]
Status: Final. Form Date: 15-JAN-15. Question 1: OPDIV Question 1 Answer: CMS
Status: Final Form Date: 15-JAN-15 Question 1: OPDIV Question 1 Answer: CMS Question 2: PIA Unique Identifier (UID): Question 2 Answer: P-5961755-385901 Question 2A: Name: Question 2A Answer: Multidimensional
APPENDIX B DEFINITIONS
APPENDIX B DEFINITIONS This Appendix defines terms that are used in the Agreement and other Appendices. Any capitalized term used in the Agreement that is not defined here has the meaning provided in 45
Following is a discussion of the Hub s role within the health insurance exchanges, the results of our review, and concluding observations.
Testimony of: Kay Daly Assistant Inspector General for Audit Services Office of Inspector General, U.S. Department of Health and Human Services Hearing Title: The Threat to Americans Personal Information:
Federally Facilitated Exchange (FFE) and Data Services Hub (Hub) Overview. July 25, 2012
Federally Facilitated Exchange (FFE) and Data Services Hub (Hub) Overview July 25, 2012 Agenda Background Technical Overview Project Management Overview 2 Background Patient Protection and Affordable Care
DEPARTMENT OF HEALTH AND HUMAN SERVICES. Centers For Medicare & Medicaid Services. Privacy Act of 1974. CMS Computer Match No.
This document is scheduled to be published in the Federal Register on 02/09/2016 and available online at http://federalregister.gov/a/2016-02527, and on FDsys.gov Billing Code: 4120-03 DEPARTMENT OF HEALTH
Developing Performance Metrics for Marketplace and Medicaid Systems under Healthcare Reform
Developing Performance Metrics for Marketplace and Medicaid Systems under Healthcare Reform Jay Himmelstein, MD, MPH Professor and Chief Health Policy Strategist Co-Authors Scott Keays, MPH, and Natasha
AGREEMENT BETWEEN WEB-BROKERS AND THE CENTERS FOR MEDICARE & MEDICAID SERVICES ( CMS )
DEPARTMENT OF HEALTH & HUMAN SERVICES Centers for Medicare & Medicaid Services Center for Consumer Information and Insurance Oversight 200 Independence Avenue SW Washington, DC 20201 AGREEMENT BETWEEN
Health Informa.on Technology Audits: "Meaningful Use" and HIPAA. January 23, 2015 Eli Poliakoff Gary Capps
Health Informa.on Technology Audits: "Meaningful Use" and HIPAA January 23, 2015 Eli Poliakoff Gary Capps 1 HITECH - Related Audits Health Informa.on Technology for Economic and Clinical Health Act ("HITECH")
Kansas. Architecture Review. Kansas Project Base line Review. Gate > Maryland ACA HCR Wireframes HIX end to end process flow (Individual / family)
Kansas Architecture Kansas Project Base line Maryland Architecture Maryland Project Baseline Massachusetts Architecture Massachusetts Project Baseline Minnesota Architecture Documents > Root Folder > Fed
HEALTHCARE.GOV. Actions Needed to Address Weaknesses in Information Security and Privacy Controls
United States Government Accountability Office Report to Congressional Requesters September 2014 HEALTHCARE.GOV Actions Needed to Address Weaknesses in Information Security and Privacy Controls GAO-14-730
BUSINESS ASSOCIATES AND BUSINESS ASSOCIATE AGREEMENTS
PRIVACY 27.0 BUSINESS ASSOCIATES AND BUSINESS ASSOCIATE AGREEMENTS Scope: Purpose: All subsidiaries of Universal Health Services, Inc., including facilities and UHS of Delaware Inc. (collectively, UHS
Harmonized Security and Privacy Framework Exchange Reference Architecture Supplement
Harmonized Security and Privacy Framework Exchange Reference Architecture Supplement Foreword The Exchange Reference Architecture: Foundation Guidance, provides the business, information, and technical
Minimum Acceptable Risk Standards for Exchanges Exchange Reference Architecture Supplement
Minimum Acceptable Risk Standards for Exchanges Exchange Reference Architecture Supplement Executive Overview The Patient Protection and Affordable Care Act of 2010 1 (hereafter simply the Affordable Care
Federal Exchange Program System Data Services Hub Statement of Work
Procurement Sensitive Department of Health and Human Services Centers for Medicare & Medicaid Services Data Services Hub Statement of Work Version 1.0 July 15, 2011 Table of Contents 1. Introduction...
3.0 ELIGIBILITY AND ENROLLMENT
3.0 ELIGIBILITY AND ENROLLMENT Blueprint Application November, 2012 3.1 Single streamlined application(s) for Exchange and SHOP The Minnesota Exchange intends to implement the HHS-developed application
HIPAA Compliance Calendar
TITLE DESCRIPTION National Provider Identifier National Provider Identifier This final rule establishes the standard for a unique health identifier for health care providers for use in the health care
Establishment Review Process
Establishment Review Process DEPARTMENT OF HEALTH AND HUMAN SERVICES CENTERS for MEDICARE & MEDICAID SERVICES Center for Consumer Information and Insurance Oversight Health Insurance Exchange System-Wide
STATE HEALTH INSURANCE MARKETPLACES. CMS Should Improve Oversight of State Information Technology Projects
United States Government Accountability Office Report to Congressional Requesters September 2015 STATE HEALTH INSURANCE MARKETPLACES CMS Should Improve Oversight of State Information Technology Projects
New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010
New HIPAA Breach Notification Rule: Know Your Responsibilities Loudoun Medical Group Spring 2010 Health Information Technology for Economic and Clinical Health Act (HITECH) As part of the Recovery Act,
APR 11 2014 Marilyn Tavenner Administrator Centers for Medicare & Medicaid Services
DEPARTMENT OF HEALTH AND HUMAN SERVICES OFFICE OF INSPECTOR GENERAL TO: WASHINGTON, DC 20201 APR 11 2014 Marilyn Tavenner Administrator Centers for Medicare & Medicaid Services Leon Rodriguez Director
Compliance Training for Medicare Programs Version 1.0 2/22/2013
Compliance Training for Medicare Programs Version 1.0 2/22/2013 Independence Blue Cross is an independent licensee of the Blue Cross and Blue Shield Association. 1 The Compliance Program Setting standards
Health Reform and Medical Prac3ce in Maine. John Freedman MD MBA June 10, 2013
Health Reform and Medical Prac3ce in Maine John Freedman MD MBA June 10, 2013 Disclosure Statement I have no relevant financial rela3onships to disclose. The opinions expressed are my own. Objec3ves Describe
DEPARTMENT OF HEALTH & HUMAN SERVICES
DEPARTMENT OF HEALTH & HUMAN SERVICES Centers for Medicare & Medicaid Services 200 Independence Avenue SW Washington, DC 20201 Date: May 1, 2013 Updated: November 7, 2014 From: Center for Consumer Information
BUSINESS ASSOCIATE AGREEMENT
THIS IS A TEMPLATE ONLY. CERTAIN STATES MAY NOT PERMIT THE TYPES OF ACTIVITIES ALLOWED HEREUNDER RELATING TO PROTECTED HEALTH INFORMATION. THUS THIS AGREEMENT MAY NEED TO BE MODIFIED IN ORDER TO COMPLY
Agent and Broker Participation in the Federally-facilitated Marketplace (FFM): An Overview for States
Agent and Broker Participation in the Federally-facilitated Marketplace (FFM): An Overview for States Presented on: June 3, 2014 Centers for Medicare & Medicaid Services (CMS) Center for Consumer Information
PATIENT PROTECTION AND AFFORDABLE CARE ACT. Status of CMS Efforts to Establish Federally Facilitated Health Insurance Exchanges
United States Government Accountability Office Report to Congressional Requesters June 2013 PATIENT PROTECTION AND AFFORDABLE CARE ACT Status of CMS Efforts to Establish Federally Facilitated Health Insurance
Information Privacy and Security Program Title:
1 Page: 1 of 5 I. PURPOSE: 1 The purpose of this standard is to identify and define the standards for implementing contracting provisions related to those individuals and organizations identified as Business
HIPAA BUSINESS ASSOCIATE AGREEMENT
HIPAA BUSINESS ASSOCIATE AGREEMENT THIS HIPAA BUSINESS ASSOCIATE AGREEMENT ( BAA ) is entered into effective the day of, 20 ( Effective Date ), by and between the Regents of the University of Michigan,
Name of Other Party: Address of Other Party: Effective Date: Reference Number as applicable:
PLEASE NOTE: THIS DOCUMENT IS SUBMITTED AS A SAMPLE, FOR INFORMATIONAL PURPOSES ONLY TO ABC ORGANIZATION. HIPAA SOLUTIONS LC IS NOT ENGAGED IN THE PRACTICE OF LAW IN ANY STATE, JURISDICTION, OR VENUE OF
Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information
Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information about HIPAA, the HITECH-HIPAA Omnibus Privacy Act, how
HIPAA Breaches, Security Risk Analysis, and Audits
HIPAA Breaches, Security Risk Analysis, and Audits Derrick Hill Senior Health IT Advisor Kentucky REC What cons?tutes PHI? HIPAA provides a list of 18 iden?fiers that cons?tute PHI. Any one of these iden?fiers
Revision to the Executive Director for Health Care Policy and Financing Rule Concerning the All-Payers Claims Database, Section 1.
STATEMENT OF BASIS AND PURPOSE 1. Summary of the basis and purpose for the rule or rule change. (State what the rule says or does and explain why the rule or rule change is necessary). These rules establish
Stream Deployments in the Real World: Enhance Opera?onal Intelligence Across Applica?on Delivery, IT Ops, Security, and More
Copyright 2015 Splunk Inc. Stream Deployments in the Real World: Enhance Opera?onal Intelligence Across Applica?on Delivery, IT Ops, Security, and More Stela Udovicic Sr. Product Marke?ng Manager Clayton
HIPAA Security. 1 Security 101 for Covered Entities. Security Topics
HIPAA SERIES Topics 1. 101 for Covered Entities 2. Standards - Administrative Safeguards 3. Standards - Physical Safeguards 4. Standards - Technical Safeguards 5. Standards - Organizational, Policies &
INFORMATION EXCHANGE AGREEMENT BETWEEN THE SOCIAL SECURITY ADMINISTRATION AND THE STATE OF [NAME OF STATE], [NAME OF STATE AGENCY]
2012 MODEL STC AGREEMENT INFORMATION EXCHANGE AGREEMENT BETWEEN THE SOCIAL SECURITY ADMINISTRATION AND THE STATE OF [NAME OF STATE], [NAME OF STATE AGENCY] AS THE STATE TRANSMISSION/TRANSFER COMPONENT
Interna'onal Standards Ac'vi'es on Cloud Security EVA KUIPER, CISA CISSP [email protected] HP ENTERPRISE SECURITY SERVICES
Interna'onal Standards Ac'vi'es on Cloud Security EVA KUIPER, CISA CISSP [email protected] HP ENTERPRISE SECURITY SERVICES Agenda Importance of Common Cloud Standards Outline current work undertaken Define
HIPAA and Privacy Policy Training
HIPAA and Privacy Policy Training July 2015 1 This training addresses the requirements for maintaining the privacy of confidential information received from HFS and DHS (the Agencies). During this training
Information Technology in Support of Health Insurance Exchange, Integrated Eligibility System, and Health Information Exchange
Information Technology in Support of Health Insurance Exchange, Integrated Eligibility System, and Health Information Exchange Manu Tandon EOHHS Secretariat Chief Information Officer Massachusetts State
Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015
Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015 Katherine M. Layman Cozen O Connor 1900 Market Street Philadelphia, PA 19103 (215) 665-2746
How To Understand The Health Care Exchange
STATE HEALTH INSURANCE EXCHANGE MISSISSIPPI INSURANCE DEPARTMENT P.O. BOX 79 JACKSON, MS 39205-0079 What Is An Exchange? 2 o Essentially a marketplace for major medical insurance. o Travelocity, Expedia,
IT Change Management Process Training
IT Change Management Process Training Before you begin: This course was prepared for all IT professionals with the goal of promo9ng awareness of the process. Those taking this course will have varied knowledge
Entities Covered by the HIPAA Privacy Rule
Entities Covered by the HIPAA Privacy Rule Who Is A Covered Entity? HIPAA standards apply only to: Health care providers who transmit any health information electronically in connection with certain transactions
Am I a Business Associate? Do I want to be a Business Associate? What are my obligations?
Am I a Business Associate? Do I want to be a Business Associate? What are my obligations? Brought to you by Winston & Strawn s Health Care Practice Group 2013 Winston & Strawn LLP Today s elunch Presenters
REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI
REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI Healthcare Organizations Can Adopt Enterprise-Wide Disclosure Management Systems To Standardize Disclosure Processes,
Copyright Telerad Tech 2009. RADSpa. HIPAA Compliance
RADSpa HIPAA Compliance 1. Introduction 3 1.1. Scope and Field of Application 3 1.2. HIPAA 3 2. Security Architecture 4 2.1 Authentication 4 2.2 Authorization 4 2.3 Confidentiality 4 2.3.1 Secure Communication
OCRA Spring Convention ~ 2014 Phyllis Craver Lykken, RPR, CLR, CCR 2463. Court Reporters and HIPAA
Court Reporters and HIPAA OCRA Spring Convention ~ 2014 Phyllis Craver Lykken, RPR, CLR, CCR 2463 1 What Exactly is HIPAA? HIPAA is an acronym for the Health Insurance Portability and Accountability Act
DRAFT BUSINESS ASSOCIATES AGREEMENT
DRAFT BUSINESS ASSOCIATES AGREEMENT THIS AGREEMENT is made this day of, 20, by and among, a Corporation organized under the laws of the State of (hereinafter known as "Covered Entity") and organized under
Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know
Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know Note: Information provided to NCRA by Melodi Gates, Associate with Patton Boggs, LLC Privacy and data protection
DEPARTMENT OF HEALTH AND HUMAN SERVICES. AGENCY: Centers for Medicare & Medicaid Services (CMS), HHS.
DEPARTMENT OF HEALTH AND HUMAN SERVICES Centers for Medicare & Medicaid Services [CMS-5505-N] Medicare Program; Advanced Payment Model AGENCY: Centers for Medicare & Medicaid Services (CMS), HHS. ACTION:
An Introduc+on to CloudPrime
TM An Introduc+on to CloudPrime Secure messaging pla/orm to protect pa2ent privacy and uphold HIPAA/HITECH regula2on Mari Tangredi, CloudPrime 1 CloudPrime Company Overview! Headquartered in San Francisco,
HIPAA. Health Insurance Portability & Accountability Act Administrative Simplification FIVE THINGS YOU SHOULD KNOW ABOUT PAYMENTS AND HIPAA
HIPAA Health Insurance Portability & Accountability Act Administrative Simplification FIVE THINGS YOU SHOULD KNOW ABOUT PAYMENTS AND HIPAA Steve Stone PNC Bank, N.A. October 14, 2009 Five Things You Should
Business Associate Agreement
Business Associate Agreement This Business Associate Agreement (the Agreement ) is made by and between Business Associate, [Name of Business Associate], and Covered Entity, The Connecticut Center for Health,
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( Agreement ) is entered into on [Month], [Day] 2014 (the effective Date ), by and between Accreditation Association for Ambulatory Health
Iterative Approach to Build an Enterprise Architecture for Health Insurance Exchange
Oracle Enterprise Architecture Oracle Enterprise Architecture Iterative Approach to Build an Enterprise Architecture for Health Insurance Exchange Maharshi Desai, Director, IT Strategy
