Amendment 000002 J.2 Unified_Program_Integrity_Contract_USOW_Appendices.doc
DOC document 26 MB Posted
- Attached to
- Unified Program Integrity Contract (UPIC) Federal contract opportunity
- Solicitation number
- HHSM-500-2015-RFP-0122
About this file
J.2 Unified Program Integrity Contract (UPIC) Umbrella Statement of Work (USOW) Appendices Amendment 00002
View the file
Other files for this federal contract opportunity
Show all 50
Unified Program Integrity Contract (UPIC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Amendment 000002 HHSM-500-2015-RFP-0122
Amendment 000002 HHSM-500-2015-RFP-0122
Unified Program Integrity Contractor
Umbrella Statement of Work Appendices
Attachment J.2
List of Appendices
A. DELIVERABLES
B. MAP OF JURISDICTIONS
C. ACRONYMS
D. RECORD RETENTION
E. DATA SOURCES
F. FREEDOM OF INFORMATION GROUP POLICY AND PROCEDURAL GUIDE
G. MEDICAID POLICIES AND PROCEDURES MANUAL
H. DATA RELEASE POLICIES AND PROCEDURES
I. FPS CHANGE REQUEST FORM
J. STATUES AND REGULATIONS
K. UNIFIED CASE MANAGEMENT DRAFT FUNCTIONAL REQUIREMENTS DOCUMENT
L. ONE PROGRAM INTEGRITY USERS MANUAL
M. PROGRAM INTEGRITY MANUAL DRAFT REVISIONS
N. COST REPORTING
The following Appendices are available on the Internet and are hereby incorporated with the same force and effect as if they were provided in full text herein.
O. BUSINESS PARTNERS SYSTEM SECURITY MANUAL
http://www.cms.hhs.gov/manuals/downloads/117_systems_security.pdf
P. PROGRAM INTEGRITY MANUAL
http://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/Internet-Only-Manuals-IOMs-Items/CMS019033.html?DLPage=1&DLSort=0&DLSortDir=ascending
Q. DATA USE AGREEMENT (DUA)
http://www.cms.gov/Medicare/CMS-Forms/CMS-Forms/Downloads/CMS-R-0235.pdf
R. SUPPLEMENT TO DUA
http://www.cms.hhs.gov/cmsforms/downloads/cms-r-0235a.pdf
S. CMS ANNUAL FREEDOM OF INFORMATION ACT (FOIA) REPORT
http://www.cms.hhs.gov/FOIA/05_annualreports.asp#TopOfPage.cms.hhs.gov/FOIA/
T. FREEDOM OF INFORMATION ACT (FOIA) REQUEST FORM (CMS FORM 632)
http://www.cms.hhs.gov/FOIA/04_reqfrm.asp#TopOfPage
A. DELIVERABLES
ITEMS TO BE FURNISHED AND DELIVERABLE SCHEDULE
The Contractor shall submit all required reports and deliverables in accordance with the following schedule. Reports and/or deliverables submitted under this contract shall be in accordance with the Statement of Work entitled Unified Program Integrity Contractor Statement of Work. References to “days” indicate “business days” unless otherwise noted. If a deliverable date happens to fall on a weekend or holiday, the deliverable shall be due on the first subsequent business day after the weekend or holiday. References to “quarterly” frequency mean on the 20th of March, June, September, and December after contract award.
Deliverable Schedule
| RFP/SOW WPS # |
| Related SOW Requirement Name |
| Deliverable Name |
| Deliverable Description |
| Frequency |
| UPIC SOW 4.12 |
| Transition and Implementation Requirements |
| Jurisdiction Implementation Project Plan |
| Project Plan for accomplishing the activities necessary to establish and operate a program integrity operation per the requirements of this SOW |
| Once-within 10 days of contract award |
| UPIC SOW 4.1.3 |
| Transition and Implementation Requirements |
| Risk Management Plan |
| Identifies the jurisdiction wide risks associated with the contractor’s segment workload transition |
| Once-within 10 days of contract award |
| UPIC SOW 4.1.4 |
| Information Technology Systems Plan |
| IT Systems Plan |
| Description of the UPIC’s data access plan as well as list and description of data the UPIC would be required to access from either CMS or the MAC(s) or plan sponsors |
| Once-within 10 days of contract award |
| UPIC SOW 4.2.2 |
| Monthly Status Report |
| Monthly Status Reports |
| Summary of Contractor activities over past month |
| Monthly - The 20th of each month |
| UPIC SOW 4.3.1 |
| Outgoing Transition Activities |
| Workload Closeout Project Plan |
| Identifies plan for outgoing contractor to transition data to the incoming UPIC, and to maintain operational standards during the workload closeout period |
Once, 30 days prior to the end of the final contract period of performance.
| UPIC SOW 4.3.3 |
| Outgoing Transition Activities |
| Workload Closeout Risk Management Plan |
| Assessment of risk and mitigation and contingency planning where appropriate for the transition of its operations and the transfer of Medicare and Medicaid data |
| Once, 30 days prior to the end of the final contract period of performance. |
| UPIC SOW 5.1 |
| Identification of Vulnerabilities |
| Program Vulnerabilities Report |
| Identifies program vulnerabilities as well as recommended corrective actions to address the vulnerability |
| Quarterly |
| USOW 5.1.1 |
| Regional Steering Committee |
| Regional Steering Committee Agenda |
| Provides items for discussion, collaboration, guidance, and information sharing on program vulnerabilities and analysis results |
| Quarterly - Within 30 days of fully operational period and quarterly thereafter |
| UPIC SOW 5.2.1 |
| Data Analysis and Management Reporting |
| Data Analysis Project Management Plan - Fully Operational Period |
| Identifies data issues/projects that are specific to the states in their region |
| Quarterly - 30 days prior to fully operational period and quarterly thereafter |
| UPIC SOW 5.2.5 |
| Data Analysis and Management Reporting |
| Analytic Findings Report |
| Summarizes the data analysis performed, identifies potential leads that justify further action (also referred to as “actionable”), and provide recommendations for activities that can include further investigation, audit, referral to law enforcement, or administrative action. |
| Upon completion of analysis |
| UPIC SOW 5.2.5 |
| Data Analysis and Management Reporting |
| Data Matching Protocol |
| Delineates the approach that will be taken to establish the matched datasets |
| Within 60 days of contract award |
| UPIC SOW 5.3 |
| Lead Management |
| Lead Management Report |
| Identifies a list of leads submitted to CMS on a daily basis |
Daily
| UPIC SOW 5.3.3 |
| Lead Management Protocol |
| Lead Management Protocol |
| An administrative protocol, or triage process, that governs the disposition of leads based on the likelihood of fraud, waste, and abuse identification. |
| Once - Within 30 days of contract award |
| UPIC SOW 5.4.3.2 |
| Referral to State Medicaid |
| Medicaid Findings Report |
| Report submitted to state outlining the following: Summary of overpayment findings as applicable; |
summary of the federal share of overpayments (FFP)(see Constraints/Assumptions section of Task Order for additional detail);
supporting documentation; and CMS cover letter notifying the state of the overpayment and requesting repayment of the FFP Upon completion of investigations
| UPIC SOW 5.6 |
| Medical Review Requirements |
| Medical Review Strategy |
| Proposed approach to performing Medical Review activities within the jurisdiction |
| Within 30 days of contract award and then Sem-iannually - on the 20th of June and December thereafter |
| UPIC SOW 5.7.3 |
| Evaluating Edit Effectiveness |
| Edit Effectiveness Report |
| The Contractor shall work with the MAC or other entities to receive reports on the results of edits. |
| Semi-annually - On the 20th of June and December |
| UPIC SOW 5.11.2 |
| Educating the Stakeholders |
| Stakeholder Education Plan |
| A plan outlining the Contractor's Plan to educate stakeholders about the Contractor’s role in Medicare and Medicaid fraud waste and abuse prevention and detection |
| Annually - Within 30 days of contract award, and then 30 days after each renewal period. |
| UPIC SOW 5.11.3 |
| Educating the States |
| State Education Report |
| Outlines educational activities conducted and/or planned by state |
| Quarterly - Within 60 days of contract award and quarterly thereafter |
| UPIC SOW 7.1.1 |
| Kickoff meeting with CMS |
| Agenda |
| Outlines contractor briefing activities |
| Draft agenda within 5 days after contract award; Final agenda within 1 day after COR comments |
| UPIC SOW 7.1.1 |
| Kickoff meeting with CMS |
| Meeting Minutes |
| Submission of minutes from Kickoff meeting with CMS |
| Once - Within 3 business days of meeting date |
| UPIC SOW 7.2 |
| Joint Operating Agreements (JOAs) |
| Joint Operating Agreements (JOAs) with Stakeholders |
| Defines roles and responsibilities and creating mutually agreed upon and cost-effective methods to work with and support the Centers for Medicare & Medicaid Services’ (CMS’) mission |
| Upon final agreement with each stakeholder |
| UPIC SOW 7.5.3 |
| Access to CMS Systems |
| Data Use Agreement |
| Delineates confidentiality requirements of the Privacy Act, implement CMS security safeguards, and explain CMS’ data use policies and procedures. The DUA serves as both a means of informing the Contractor of these requirements and a means of obtaining their agreement to abide by them. |
| Within 30 days prior to the fully operational phase of implementation. |
| UPIC SOW 7.7.3 |
| Quality Control Plan |
| Quality Control Plan |
| Specifies procedures and resources applied to ensure services meet contract performance requirements to the COR |
| Once - Within 30 days of contract award |
| UPIC SOW 7.7.5 |
| Continuous Improvement Program |
| Continuous Improvement Reports |
| Outlines continuous improvements and innovations in adapting to unforeseen circumstances and become increasingly effective in achieving its goals. |
| Semi-annually; on the 20th of June and December. |
| UPIC SOW 7.8 |
| Cost Reports |
| Cost Report |
| A summary of costs incurred (by each USOW section) during the previous month |
| Monthly - The 20th of each month |
| UPIC SOW 7.9 |
| Freedom of Information Act Reports |
| Freedom of Information Act (FOIA) Contractor Summary Sheet |
| A summary of all FOIA requests within the contract year |
| Quarterly (only if FOIA requests are received for the quarter being reported) |
| Award Fee Plan |
| Award Fee Performance Evaluation Self-Assessment Report |
| Award Fee Plan |
| An assessment completed by the contractor on its performance in relation to award fee criteria |
| Within 15 business days following completion of each award fee period |
Recipient Addresses:
Michael Connors Contracting Officer (CO)
Centers for Medicare & Medicaid Services
Office of Acquisition and Grants Management
Medicare Contracts Group
Division of Medicare Support Contracts
7500 Security Blvd, Mail Stop: C2-21-15
Baltimore, Maryland 21244
Email:
Michael.Connors@CMS.HHS.Gov Phone:
410-786-5129 Location:
C2-24-16 Primary Contracting Officer’s Representative (COR) As defined in task order Statement of Work
Alternate Contracting Officer’s Representative (Alternate COR) As defined in the task order Statement of Work
Center for Program Integrity 7500 Security Blvd, Mail Stop: AR-18-50 Baltimore, Maryland 21244
CMS Center for Program Integrity Systems Security Officer
Centers for Medicare & Medicaid Services
CPI
7500 Security Blvd., Mail Stop: AR-18-50 Baltimore, Maryland 21244
Regional Office FOIA Coordinator
TBD
Until the RO FOIA Coordinator is identified, please submit to:
Sam Seidman, Freedom of Information Specialist
Centers for Medicare & Medicaid Services
Freedom of Information Group
7500 Security Blvd, Mail Stop: N2-20-16
Baltimore, Maryland 21244
Fax: 410.786.0474
Phone: 410.786.3327
Small Business Administration (SBA)
CMS Small Business Specialist
Attn: Anita Allen Centers for Medicare & Medicaid Services
Office of Acquisition and Grants Management
Acquisition Support & Policy
7500 Security Blvd, Mail Stop: C2-21-15
Baltimore, Maryland 21244
B. MAP OF JURISDICTIONS
C. ACRONYMS
| TERM |
| Acronym or Abbreviation |
| Definition |
| Additional Documentation Requests |
| ADR |
| Affordable Care Act |
| ACA |
| The Patient Protection and Affordable Care Act |
| Alert Status Report |
| ASR |
| Also known as Alert Summary Records. As Medicare claims are analyzed in FPS using analytic models, the system identifies high-risk claims for individual providers and generates the alerts that are referred to as ASRs. |
| Assistant U.S. Attorney |
| AUSA |
| Authority to Operate |
| ATO |
| Business Partners System Security Manual |
| BPSSM |
| CMS Access Administrator |
| CAA |
| CMS Analysis, Reporting, and Tracking System |
| CMS ARTS |
| This database is used by CMS and contractors to track contract actions, cost reports, and some workload reporting. |
| CMS Data Center |
| CMSDC |
| CMS Entitlement, Eligibility, and Enrollment |
| CME |
| Medicare eligibility data that is supplied from multiple systems, including MARx, EDB, and MDB |
| CMS Integrated Security Suite - Federal Information Security Management Act |
| CISS FISMA |
| Command Center Rotation |
| CCR |
| Common Working File |
| CWF |
| The Medicare pre-payment validation and authorization system that forms the cornerstone for Medicare transactions processing. It is the single data source that verifies beneficiary eligibility and provides prepayment review and approval of claims. |
| Competitive Bidding Implementation Contractor |
| CBIC |
| Contracting Officer |
| CO |
| Contracting Officer's Representative |
| COR |
| Contractor Medical Director |
| CMD |
| Corrective Action Plan |
| CAP |
| Cost Report |
| CR |
| Cost Report Audit |
| CRA |
| Cost Report Review |
| CRR |
| Data Extract System |
| DESY |
| Access method or tool used to view and obtain NCH claims information |
| Data Use Agreement |
| DUA |
| Department of Justice |
| DOJ |
| Doctor of Osteopathy |
| DO |
| Do Not Pursue |
| DNP |
| Drug Data Processing System |
| DDPS |
| This is the system from which the Part D prescription drug events are generated. |
| Durable Medical Equipment |
| DME |
| Electronic Submission of Medical Documentation |
| esMD |
| An electronic "gateway" that enables providers to send medical documentation to CMS |
| Enrollment Data Base |
| EDB |
| Medicare beneficiary enrollment data including identifiers and eligibility status. A subset of EDB data is found in CME. |
| Enterprise Data Center |
| EDC |
| Federal Bureau of Investigation |
| FBI |
| Federal Medical Assistance Percentage |
| FMAP |
| A calculation that determines the ratio of matching funds for each state's Medicaid program. |
| Fee-for-Service |
| FFS |
| Field Office |
| FO |
| Fiscal Intermediary Shared System |
| FISS |
| Fraud Investigation Database |
| FID |
| The FID is a nationwide database of Medicare fraud and abuse investigations, cases, payment suspensions and requests for information. |
| Fraud Prevention System |
| FPS |
| A predictive analytic technology that is used to identify and prevent improper claims, starting with Medicare fee-for-service claims. |
| Fraud, Waste, and Abuse |
| FWA |
| Full Time Equivalent |
| FTE |
| Generally Accepted Government Auditing Standards |
| GAGAS |
| Healthcare Fraud Prevention Partnership |
| HFPP |
| A joint initiative established by the Dept. of Health and Human Services and the Dept. of Justice to detect and prevent healthcare fraud by sharing data and information among public and private partners. |
| Health Care Information System |
| HCIS |
| This file contains historical CMS data for development of normative data sets. Data in HCIS is summarized from Standard Analytical Files and contains Medicare Part A and B data based on the type and State of the institutional provider. It can be downloaded or otherwise obtained from www.cms.gov. It is under transition and will be called "CSI" (Claim Summary Information project) to be used for broader purposes. |
| Health Insurance Claim Number |
| HICN |
| Health Insurance Master Record |
| HIMR |
| This is an access method, or tool to view CWF claims information. It is available using the claims processing systems. |
| Health Insurance Portability and Accountability Act |
| HIPAA |
| Provisions of HIPAA require HHS to adopt national standards for electronic health care transactions and national identifiers for providers, health plans, and employers. |
| Healthcare Integrated General Ledger Accounting System |
| HIGLAS |
| The CMS integrated general ledger accounting system to account for Medicare payments. HIGLAS replaces the accounting systems that were used by Medicare contractors. |
| Identity and Access Management |
| I&A |
| General term for identity and access management which includes specific systems; IACS and Enterprise Identity Management (EIDM) |
| Information Security |
| IS |
| Information Technology |
| IT |
| Integrated Data Repository |
| IDR |
| An integral part of the CMS data warehouse strategy to take disparate databases and integrate them for efficiency. |
| International Classification of Diseases |
| ICD |
| Can also be referred to as ICD-9-CM (Clinical Modification) or ICD-10-CM. |
| Internet-Only Manuals |
| IOM |
| Joint Operating Agreement |
| JOA |
| Law Enforcement |
| LE |
| Local Coverage Determination |
| LCD |
| Local Medical Review Policy |
| LMRP |
| Medicaid Fiscal Agent |
| MFA |
| Medicaid Fraud Control Unit |
| MFCU |
| Medicaid Integrity Contractor |
| MIC |
| Medicaid Management Information System |
| MMIS |
| Medicaid Statistical Information System |
| MSIS |
| Medical Doctor |
| MD |
| Medical Review |
| MR |
| Medicare Administrative Contractor |
| MAC |
| Medicare Advantage |
| MA |
| Medicare Advantage Prescription Drug Development & Enhancements |
| MARx |
| Medicare Appeals Support Contractor |
| MAS |
| Medicare Beneficiary Database |
| MBD |
| Medicare Drug Integrity Contractor |
| MEDIC |
| Medicare Integrity Program |
| MIP |
| Medicare-Medicaid Data Match Program |
| Medi-Medi |
| Medicare-Medicaid Data Match Program Policies and Procedures Manual |
| PPM |
| The "PPM" is the policies and procedures manual specifically for the Medicare-Medicaid Data Match Program (Medi-Medi). |
| Medicare-Medicaid Enrollee |
| MME |
| Memorandum of Understanding |
| MOU |
| Multi-Carrier System |
| MCS |
| Part B claims processing system used by the MACs. |
| National Benefit Integrity Medicare Drug Integrity Contractor |
| NBIMEDIC |
| National Claims History |
| NCH |
| Master file for claims submission, adjudication activities, payment accounts |
| National Council for Prescription Drug Programs |
| NCPDP |
| National Coverage Determination |
| NCD |
| National Institute of Standards and Technology |
| NIST |
| National Provider Identifier |
| NPI |
| National Supplier Clearinghouse |
| NSC |
| Master file for DMEPOS supplier information. |
| Office of the Inspector General |
| OIG |
| One Program Integrity system |
| OnePI |
| Online Survey, Certification, and Reporting |
| OSCAR |
| This is an access method, or tool to view and obtain institutional provider information. OSCAR is being converted to QIES. |
| Part B National Summary Data File |
| Previously known as "BESS" |
| Summarized Part B data plus procedure and modifier codes. This file can be used for benchmarking purposes. It is updated only once per year. These files can be downloaded from www.cms.gov. |
| Part B Provider Extract File |
| PROV BX |
| Personal Health Information |
| PHI |
| Personally Identifiable Information |
| PII |
| Prescription Drug Events |
| PDE |
| Refers to Medicare Part D Prescription drug events |
| Pricing, Data Analysis and Coding Contractor |
| PDAC |
| Program Integrity |
| PI |
| Program Integrity Data Users Group |
| PIDUG |
| Program Integrity Manual |
| PIM |
| The “PIM” specifically means the Medicare Program Integrity Manual. |
| Policies & Procedures Manual |
| PPM |
| “PPM” refers to the UPIC Medicaid Program Integrity Coordination Policies and Procedures Manual |
| Program Safeguard Contractor |
| PSC |
| Provider Enrollment, Chain, and Ownership System |
| PECOS |
| Provider of Services |
| POS |
| This file contains an individual record for each Medicare approved provider and is updated quarterly. |
| Provider Outreach and Education |
| POE |
| For purposes of this SOW, POE is a functional area of the MAC that provides education to the provider when questionable practices that do not appear to have fraudulent intent are found. |
| Provider Transaction Access Number |
| PTAN |
| Qualified Independent Contractor |
| QIC |
| Quality Control Plan |
| QCP |
| Quality Improvement Evaluation System |
| QIES |
| OSCAR is being converted to QIES; OSCAR standard and user-defined reports are available in QIES. This system is also referred to as the Health Care Quality improvement System. |
| Quality Improvement Organization |
| QIO |
| Regional Office |
| RO |
| Registered Nurse |
| RN |
| Senior Medicare Patrol |
| SMP |
| State Medicaid Agency |
| SMA |
| Statement of Work |
| SOW |
| Subject Matter Expert |
| SME |
| Systems Advisory Board |
| SAB |
| Task Order Statement of Work |
| TO SOW |
| Tax Identification Number |
| TIN |
| Technical Reference Architecture |
| TRA |
| Transformed Medicaid Statistical Information System |
| TMSIS |
| Trusted Third Party |
| TTP |
| A Trusted Third Party is included in the HFPP to provide the technical and operational platform to support the partnerships' data sharing, collaboration, and study outreach activities. |
| Umbrella Statement of Work |
| USOW |
| Unified Case Management system |
| UCM |
| A central repository to track and establish transparency in Medicare and Medicaid program integrity activities and contractor workload; monitor priorities; and measure outcomes. The UCM system will be within the OnePI portal. |
| Unified Program Integrity Contractor |
| UPIC |
| Viable Information Processing Systems |
| VMS |
| Virtual Data Center |
| VDC |
| Virtual Private Network |
| VPN |
| Work Breakdown Structure |
| WBS |
| Workflow Management System |
| WFMS |
| Zone Program Integrity Contractor |
| ZPIC |
D. RECORD RETENTION
1 - General Requirements
The Unified Program Integrity Contractor (UPIC) shall establish and maintain a continuing program for the economical and efficient management of records. The UPIC’s records management program must provide for:
· Effective controls over the creation, organization, maintenance, use, and disposition of all the Centers for Medicare & Medicaid Services (CMS) health insurance claims and non-claims records.
· Development and application of standards, procedures, and techniques designed to ensure the maintenance and security of records of continuing value, and to facilitate the segregation and disposal of all records of temporary value. The UPIC should (1) provide for the continued analysis and improvement of record classification and indexing systems, the use of filing equipment and supplies, and the reproduction and transportation of records, and (2) ensure that records are maintained economically and efficiently for maximum usefulness.
· Physically safeguarding identifiable personal information (Privacy Act (PA)) and protected health information (Health Insurance Portability and Accountability Act of 1996 (HIPAA)).
· Storage and servicing of records in a safe and secure environment that meets the requirements outlined in 36 FR 1228.222.
The files established by the UPIC should be available for periodic review by CMS. In addition, all records and procedures documenting the UPIC’s programs for controlling the creation, maintenance, and use of current records, for the selective retention of records of continuing value, and for the disposal of non-current records, should be available for periodic review by CMS.
1.1 - Description of Records Maintained
1.1.1 - Claims Records
These are government records, including government-issued standard forms and other forms, documents, and statements needed to support claims. Such records are maintained by the affiliated contractor and Medicare Administrative Contractor (MAC) in accordance with instructions regarding retention, transfer, destruction, and other disposition of claims materials.
1.1.2 - Non-Claims Records
These are materials not needed as supporting documentation of a claim, such as used worksheets, extra copies, electronic data processing (EDP) listings, and general correspondence not related to specific pending or processed claims.
1.1.3 - Fiscal and Administrative Records
These are materials not included as claims or non-claims records.
1.1.4 - Microform Records
This includes any form containing micro-images (e.g., microfilm and microfiche).
1.1.5 - Electronic Records
This includes any information that is recorded in a form that only a computer can process (e.g., optical image and scanned images).
1.2 - Definition of Files
Files are basically papers, folders of papers, photographs, photographic copies, magnetic tapes, or other recorded information regardless of physical form or characteristics, accumulated or maintained in filing equipment, boxes, or shelves, and occupying office or storage space. Stocks of publications and blank forms are not included in this definition.
2 - Implementing Files Management Program
Adequate records management controls over the creation of UPIC files must ensure that important policies and decisions are adequately recorded, routine operational paperwork is kept to a minimum, and the accumulation of unnecessary files is prevented. Effective techniques in this area include the application of systems for the control of correspondence and forms, the minimizing of duplicate files, and the disposal without filing of transitory material that has no value for record purposes.
The following actions are generally basic to such a files management program, which each UPIC is expected to establish.
1. Standardize classification and filing schemes to:
· Achieve maximum uniformity and ease in maintaining and using program records
· Facilitate disposal of records in accordance with applicable records disposal schedules
· Facilitate possible later consolidation of identical type files presently maintained at different locations
2.
Formally authorize official file locations. Prohibit the maintenance of files at unauthorized locations.
3.
Standardize reference service procedures to facilitate the finding charge out, and refiling of records.
4.
Establish and implement standards and procedures issued by CMS for:
· Classifying, indexing, and filing records
· Providing reference services to filed records
· Locating active files to facilitate use of the records
· Reviewing the program periodically to determine the adequacy of the system and its effectiveness in meeting requests
5.
Ensure that the standards, guides, and instructions developed for the files management program are readily available to all employees concerned with the files operations. In addition, pertinent information for users of files and reference services should be given the widest possible dissemination.
6.
File accumulations of papers received at file locations on a daily basis.
7.
Audit periodically a representative sample of the files for duplications, misclassification, or misfiles.
The methods used in maintaining, using, and disposing of these files vary with the UPIC. These methods depend on the filing and control methods established (e.g., health insurance claim number, date, name, or other sequence) to record requests from beneficiaries and others; to furnish replies; to check on overdue cases; to control cases for completion of processing; to control cases requiring some type of investigation or additional documentation; to retain completed cases for history or other reference; to maintain records for audits; and to schedule records for transfer to other storage areas. Other variances may be due to computer or clerical practices, workload volume, and other considerations.
3 - Microfilming and Imaging of Files Material
UPICs are authorized to microfilm/image files material such as computer printouts, canceled checks, and financial records. UPICs are not authorized to destroy original source documents, but are permitted to transfer an accumulation of these documents to an onsite/offsite storage facility after microfilming/imaging and verification of the quality and completeness of the film. The accumulation period may be daily, weekly, or monthly, depending on volume. When microfilming material, UPICs shall follow the procedures below. For imaging, UPICs shall follow parallel procedures to microfilming. UPICs shall ensure the integrity of imaged documents with appropriate procedures to scan, index, retrieve, and read or access documents for the life of the record.
3.1 - Microfilming Procedures
3.1.1 - General Authenticate each roll of film containing reproductions of Medicare claims records by including certifications of authenticity at the start and at the end of the filmed documents. The UPIC produces these certificates and target cards as needed. Camera operator completes a report for each roll that is microfilmed. Film claims records without attachments (e.g., coding sheets) overlaying data on the record. If data on the attachment are needed for reference purposes, film them separately.
To ensure that the camera is working efficiently, film a microcopy resolution test chart on the first roll in the morning and the first roll in the afternoon. Give these rolls priority processing so that any camera malfunction is discovered as soon as possible.
3.1.2 - Normal Filming
Film the start certificate after any target (or flash) cards that identify or index the documents on the film and before the records are filmed. Film the end certification after the last document and before any end target card. Retain documents in the order they were filmed for ease in reviewing the processed microfilm roll.
3.1.3 - Corrections
If the camera operator notices that a document has been incorrectly filmed due to being twisted, folded, or torn, photograph a correction card right after the incorrect document.
3.1.4 - Filming Retakes and Additions
When the processed microfilm roll is reviewed, some documents may be illegible or incorrectly photographed. Other documents may have been out of file or omitted at the time of original microfilming. Re-photograph these documents and splice onto the front end of the completed microfilm roll. If splicing is not practical, maintain the retakes and additions as a separate microform roll. Photograph a start or retake or addition card immediately before the documents to be re-photographed are added. Photograph an end of retake or addition certificate immediately after the last document to be re-photographed is added.
3.2 - Index Label
Affix an index label to each roll microfilm container (e.g., box, cartridge). This label lists the contents of the roll microfilm and provides reference markers. It lists the normal filming and the retakes and additions.
3.3 - Retention and Destruction of Microfilm
3.3.1 - Master Microfilm
After producing the number of copies of the microfilm required for reference purposes, the UPIC retains the master microfilm as a security file. Store it at an off-site location so that copies may be made in the event the reference copies are destroyed. Dispose of the master microfilm at the time the storage facility disposes of the hard copy contained on the film.
The UPIC need not maintain a master microfilm security file of records such as computer printouts when complete computerized backup data are retained.
3.3.2 - Copies of Microfilm
Retain one copy of the microfilm as a record copy. Store it onsite so that it may be used for reference purposes. Dispose of the record copy with the master microfilm.
The UPIC may dispose of any other reference copies of the microfilm 2 years after the end of the calendar year in which the documents were filmed. These copies may be retained for a longer period if they are needed for reference purposes, but no longer than the master microfilm.
3.3.3 - Destruction of Microfilm
Destroy microfilm by shredding, as this method provides the most complete destruction of the data on the film. Other methods of destroying film, such as exposure to extreme heat or boiling, do not eradicate the data as completely or efficiently. Shredders exist that can destroy both film and reels. Retain cartridges or magazines that contained the microfilm for reuse because of the high cost of replacement. If an UPIC does not have a shredder and purchase of a shredder is not cost-justified, check local sources such as microfilm equipment vendors, microfilm service bureaus, banks, and insurance companies for a shredder that it can use to destroy its film. If a shredder cannot be located, contact the Primary COR and Alternate COR for assistance.
4 - Procedures for Transfer of Material to a Storage Facility
When the retention period has elapsed for a block of files, materials, or canceled checks, the UPIC should prepare the records for shipment. The standard cartons that are used to ship such materials may be purchased directly from the General Services Administration (GSA) warehouses and self-service stores or the PCS can purchase from their own supply source.
When contacting the appropriate GSA supply source for the cartons, the UPIC presents the letter of authorization, signed by the regional representative, which authorizes the UPIC to purchase directly from GSA.
4.1 - Packing and Labeling of Records for Transfer
Pack records in the boxes in the same manner as they are arranged in the file cabinets. Each box equals 1 cubic foot. Do not jam records into the cartons. Boxes usually do not have preprinted labels.
When the UPIC arranges the records being transferred to the storage facility in other than a consecutive claim number or date sequence, such arrangements should include necessary identification and sequencing to facilitate reference to an individual record with a minimum of effort. Specifically, when the sequencing of material in the carton is by terminal-digit grouping, alphabetic grouping, or date-paid grouping, arrange each major grouping so as to facilitate the location of an individual case. Such arrangement may require some additional sorting by the UPIC.
Depending on local filing practices and volume, this may be based on sorting of an additional digit, letter, or other factor, where the volume of records being transferred renders the current major grouping too large and cumbersome for ready reference. Recall of records from the storage facility could then be accomplished with a minimum of time and manpower requirements.
Staple or attach all individual documents related to a specific record in an acceptable manner. In cases where staples have been removed (i.e., microfilming), make special arrangements to facilitate ready referral and recall of the complete claim number material.
4.2 - Preparation of Transmittal Document
Although Federal Record Centers (FRCs) are no longer used to store contractor records, UPICs shall continue to use Standard Form (SF) 135 Records Transmittal and Receipt for record keeping purposes. To reduce postal costs, use first class mail rather than a more expensive postal service such as airmail or special delivery when shipping to an offsite storage facility.
4.3 - Shipment of Records
UPICs that are located near the offsite storage facility may use trucks owned by the storage facility to pick up the records, depending upon the local arrangements with each storage facility.When shipments are made by commercial motor freight, to get lower tariff rates UPICs shall include the following statement on each bill of lading: “Transportation, hereunder, for the Department of Health and Human Services, and the actual total transportation charges paid to the UPIC by the consignor or the consignee are assignable to, and are to be reimbursed by the Government.”
5 - Temporary Agency Policy
Effective 1992, the Department of Justice (DOJ) required CMS to preserve all current and future Medicare claims payment records indefinitely (MSP cases). Contractors were notified to cease the destruction of all hard-copy Medicare claims/payment records. Federal Records Centers would no longer accept additional records for storage from Medicare contractors. Contractors are to assume responsibility for the storage of these records, either onsite or by procuring offsite storage.
Contractors must submit a written request to their Primary Contracting Officer’s Representative (COR) for temporary relief from using an offsite storage facility that does not meet federal facility standards. This request will be forwarded to the CMS Records Officer for processing. CMS expands the freeze from MSP files only to include all Medicare records.
Regulations
· 36 CFR Part 1222 (Creation and Maintenance of Federal Records)
· Section 1222.48 (Data Created or Received and Maintained for the Government by Contractors)
· Part 1228 (Disposition of Federal Records)
· Section 1228.152 and 1228.224(1)&(2) (Federal Facility Standards)
· Part 1230, Subpart D (Standards for the Storage, Use, and Disposition of Microform Records)
· Section 1234.32 (Retention and Disposition of Electronic Records)
· Section 1234.34 (Destruction of Electronic Records)
Statutes
· 44 U.S.C., chapters 2904, 3101, 3102, 3103, and 3133
· 5 U.S.C. 522 (Freedom of Information Act)
· 5 U.S.C. 552a (Privacy Act)
· Public Law 104-191 (Health Insurance Portability and Accountability Act of 1996)
The UPIC shall continue to box and identify the records in accordance with the Federal Records Center and CMS’ requirements. Since no records will be stored at the FRC, provisions must be made to store these records onsite. If this is not feasible, commercial facilities most closely approaching federal standards must be utilized. Measures must be taken to ensure the protection of these records from fire, theft, and deterioration; to avoid scandal and harm to the government; and to safeguard personal indicators.
If it is difficult to locate a storage facility that meets the federal requirements, submit a written request for temporary relief from the requirements for 1 year to the CMS Project Officer/Regional Office who in turn will submit to the CMS Records Officer for processing. If after 1 year a facility is not found, contractors must submit a letter outlining what actions have been taken and request an extension for relief from these standards.
Offsite storage may be procured and should be handled within the current budget.
6 - Retention of Records
6.2 - Records the UPIC Shall Retain For 10 Years
The UPIC shall retain the following records for 10 years:
· Cost Reports and Administrative Budget Estimates - Form 1524 and attachments, contractor’s initial budget requests, supplemental budget requests, notice of budget approvals, interim expenditure reports, final administrative cost proposals, supporting schedules correspondence, and audit reports.
· Program Integrity (PI) Documentation & Files – Files/documents shall be retained for 10 years. However, files/documents shall be retained indefinitely and shall not be destroyed if they relate to a current investigation or litigation/negotiation; ongoing Workers’ Compensation set aside arrangements, or documents which prompt suspicions of fraud and abuse of overutilization of services. This will satisfy evidentiary needs and discovery obligations critical to the agency’s litigation interests.
· PI Manager - Provider education letters, 100% prepay warning letters, various reports (e.g., Carrier MR Report (MRS1), focused MR status (MFSR), ratio reports, and provider list reports for Comprehensive Medical Review (CMR)), provider audit lists, post payment claims determinations, medical records, and correspondence.
· All documentation the UPIC solicits from providers - The UPIC shall retain a copy of all documentation submitted after claims submission for 10 years.
The UPIC shall return completed appeals files to the affiliated contractor. The UPIC does not need to maintain copies of the entire file. The UPIC may retain copies of the appeals file for as long as it deems necessary.
E. EXAMPLES OF MEDICARE AND MEDICAID DATA SOURCES
| CMS Data File |
| File Contents |
| Type of Access |
| Schedule |
| National Claims History (NCH) File |
| Master file for claims submission, adjudication activities, payment accounts |
| Feed into One PI |
| Daily/Weekly updates |
| Enrollment Data Base (EDB) |
| Beneficiary enrollment data including identifiers & eligibility status. |
| Feed into One PI |
| Daily updates |
| EDB Workbench |
| Access method to view and obtain beneficiary information. |
| Feed into One PI |
| Daily updates |
| Provider Enrollment Chain of and Ownership System (PECOS) |
| Provider and supplier data |
| Authorized access and feed into One PI |
| Daily updates |
| Unified Case Management System (UCM) |
| Cross-reference to determine providers being reviewed for fraudulent activities. |
| Authorized access |
| Online access as needed |
| Common Working File (CWF) |
| Access method to view CWF claims information. |
| Feed into One PI |
| Daily updates |
| MCS Claims |
| Claims data that is used to adjudicate a claim by the MAC. |
| Authorized access |
| Daily updates |
| FISS Claims |
| Claims data that is used to adjudicate a Part A claim by the MAC. |
| Authorized access |
| Daily updates |
| MAC Beneficiary File |
| Beneficiary information that is used to adjudicate a claim by the MAC. |
| Feed into One PI |
| Daily updates |
| NPI Crosswalks |
| Provider data including identifiers (not only Medicare); official source of the National Provider Identifier mandated by HIPAA. |
| Feed into One PI or query online |
| Daily updates |
| MARx |
| Data on enrollment/disenrollment |
transactions associated with Part D
| Feed into One PI |
| Daily updates |
| CWF |
| Medicare beneficiary and claims data, including MSP data and other data needed to substantiate claims. |
| Feed into One PI |
| Daily updates |
| Prescription Drug Event (PDE) |
| Medicare prescription drug data |
| Feed into One PI |
| Daily updates |
| Pharmacy Reference |
| National Drug Code (NDC); First Data Bank (FDB); and Medispan MDDB |
| Feed into One PI |
| Daily updates |
| Common Medicare Environment (CME) |
| Medicare Eligibility data |
| Feed into One PI |
| Daily updates |
| EDB Workbench |
| Access method to view and obtain beneficiary information. |
| Authorized access |
| Online access as needed |
| Medicare Physician Identification Eligibility Record (MPIER) |
| Provider data including identifiers. |
| Obtain file |
| Quarterly |
| Provider of Services (POS) |
| All Medicare institutional providers. |
| Obtain file |
| Quarterly |
| OSCAR |
| Access method to view and obtain institutional provider information. |
| Authorized access |
| Online access as needed |
| Part B Extract and Summary System (BESS) |
| Summarized Part B data plus procedure and modifier codes. |
| Obtain file |
| Online access as needed |
| National Supplier Clearinghouse File |
| Master file for DMEPOS supplier information. |
| Obtain file |
| Monthly |
| CMS Customer Information System (HCIS) |
| Five years of historical CMS data for development of normative data sets. |
| Obtain file |
| Online access as needed |
| CWF (HIMR) |
| Access method to view CWF claims information. |
| Authorized access |
| Online access as needed |
| MCS Claims |
| Claims data that is used to adjudicate a claim by the MAC. |
| Obtain file |
| Monthly |
| MAC Provider File |
| Physician information that is used to adjudicate a claim by the MAC. |
| Obtain file |
| Monthly |
| Provider 1099 data |
| Tax information on providers. |
| Obtain file |
| Annually |
| VMS Reports |
| Specified Management Reports produced by VMS. |
| Obtain report |
| As produced by VMS |
| MCS Reports |
| Specified Management Reports produced by MCS. |
| Obtain report |
| As produced by MCS |
| FISS Claims |
| Claims data that is used to adjudicate a Part A claim by the MAC. |
| Obtain file |
| Monthly |
| HCRIS |
| Hospital Cost Reporting Information System. |
| Obtain file |
| Quarterly |
| SNCRIS |
| Skilled Nursing Facility Cost Reporting Information System. |
| Obtain file |
| Quarterly |
| HIGLAS |
| Medicare data on accounts payable and receivable, and on claims processed (contractor transitions will be complete by 2011). |
| Authorized access |
| Access as needed |
Examples of Medicaid Data Sources
| Medicaid Data File |
| File Contents |
| Compromised claims files |
| Adjustment history of paid claims. |
| MMIS Medicaid Claims Files |
| Master file for claims submission, adjudication activities, payment accounts. |
| MMIS Medicaid Provider File |
| All Medicaid Providers. |
| MMIS Medicaid Eligibility/Enrollment File |
| All Medicaid Eligibility Beneficiary History file for residence. |
| Return mail files |
| Use to check claims returned to Medicaid due to “address unknown,” “moved,” or other. |
| Excluded provider files (including OIG sanctioned provider database access) |
| Nationwide database of providers suspended, excluded, or terminated from the Medicare or Medicaid programs. |
| Fee Schedules |
| Fee schedule data that includes lab, physician, DME, ASC, institutional providers. |
Examples of Non-CMS Data Sources
| Non-CMS Data File |
| File Contents |
| Provider credential files |
| Credential verification that can be matched to Medicare providers. |
| Beneficiary/provider death files |
| Dates that can be matched to claims or can help ensure providers or beneficiaries exist. |
| Computerized background search files |
| Files provide ownership, license status of physicians, size of operation, equipment, real estate, and litigation pending. |
| Computerized residential and business address files |
| Used to assess that the provider is bona fide. |
| Healthcare Integrity and Protection Data Bank |
| A data collection system offering valuable info on adverse actions taken against health care providers, suppliers and practitioners. |
| National Insurance Crime Bureau files |
| Database of individuals who are or have been involved in health care fraudulent activities. |
| National Practitioner Data Bank |
| File containing information about practitioners' licensure, professional society memberships, medical malpractice payment history, and record of clinical privileges. |
| State Licensing Board Links |
| Public access files for verifying licensed practitioners in each state. Public access files for verifying excluded individuals and entities in each state. |
F. FREEDOM OF INFORMATION GROUP POLICY AND PROCEDURAL GUIDE
Office of Strategic Operations and Regulatory Affairs
Freedom of Information Group
Policy and Procedural Guide
ADMINISTRATION OF THE FREEDOM OF INFORMATION ACT
Section
Title
Page 0501-1-00
PURPOSE
0501-1-05
POLICY
0510-1-10
GENERAL INFORMATION
0501-1-15
RESPONSIBILITY
0501-1-20
ADMINISTRATIVE PROCEDURES
0501-1-25
FEES FOR SERVICES
Exhibit H INTERMEDIARY/CARRIER/CENTRAL OFFICE COMPONENT
SUMMARY SHEET FOR THE CMS MONTHLY FOIA REPORT
Exhibit I CMS MONTHLY FOIA REPORT
Exhibit J
FREEDOM OF INFORMATION REQUEST LOG
[FOIA GROUP PAGE 1]
0501-1-00
PURPOSE
This Guide describes the CMS procedures for administering the Freedom of Information Act (FOIA) (5 U.S.C. 552). It conforms to and delineates for CMS the DHHS FOIA regulations published in the Federal Register by the Office of the Assistant Secretary for Public Affairs on
November 25, 1988.
Revision Date: February 2003
(Replaces CMS Administrative Issuances System Guide CMS.g:0501-1. March 30, 1984..Public Affairs. Administration of the Freedom of Information Act)
[FOIA GROUP PAGE 2]
0501-1-05
POLICY
A.
This Guide represents CMS policy for administering and implementing the Freedom of Information Act (FOIA). It supplements and is in full compliance with the Department's Freedom of Information Act Regulation (45 C.F.R. Part 5) and the CMS FOIA Regulations at 42 CFR 401.101 et seq.
B.
Any instructions to CMS components not in compliance with this issuance are null and void. All supplements to this issuance must be cleared with the Director, Freedom of Information Group in order to ensure uniformity of procedures, as well as consistency with the law and regulations.
0501-1-10
GENERAL INFORMATION
A.
Scope The Freedom of Information Act (FOIA) requires that most records in the custody of the Centers for Medicare & Medicaid Services be made available to the general public when requested. The Act does not apply to materials specifically prepared for public distribution or sale, e.g., press releases, speeches, fact sheets, listings (names and business addresses) of Medicaid and/or Medicare providers, MMACs, RADARs, information brochures, any publication which has been assigned a CMS, Health and Human Services, Government Printing Office or National Technical Information Service (NTIS) publication number.
The FOIA covers records (paper or electronic/tape) only. It does not cover information which may be requested and imparted orally or in writing. For example, requests for dates, addresses, figures such as the Medicare enrollment for a state, which need not be responded to with the production of a document are not FOIA requests. Such requests should be directed to the proper public inquiries office.
Similarly, coverage inquiries by providers may not always be best resolved through the FOIA. They may often be handled most appropriately through the provider relations office or its equivalent.
B.
Authority to Release/Deny With the exception of the documents listed in sections C, D and E below, all requests for records which are received anywhere in CMS will be forwarded immediately to the Freedom of Information Group (FIG), in the manner described in Section C under Administrative Procedures. Only the Director, FIG can decide on release of non-excepted records, or the full or partial denial of any request. FOIA exemptions are shown in Exhibit G. Requesters may appeal a decision to withhold all or part of the records requested. Only the Administrator or Deputy Administrator of CMS can rule on appeals of denials made under FOIA. The CMS procedure for handling FOIA requests is depicted graphically in Exhibit A. The CMS and Department FOIA policy permits certain categories of records to be released by the contractors and components/regions. When directly releasing records the cover letter to the requester should include pertinent information (e.g., no documents found in response to a specific item in the request, certain pages are of poor quality, or no better copy could be located).
C.
Direct Release of Routine Records
The first category of exceptions (identified herein by the prefix “I”) includes those types of records whose routine release continues to be a policy of the Department. Thus, requests for the following will be directly released by any CMS component or its contractors:
I.1 -- Provider Cost Reports and Back-up Data
(Forms 339, Cost Report Reimbursement Questionnaires and working trial balances are not part of the cost report. Do not directly releasable these documents; send them to FIG for disposition.)
I.2 -- Budget Methodology (from OBRA 87)
I.3 -- DME Reimbursement Calculations (as per OBRA 87)
I.4 -- All Policy Issuances, Provider Bulletins Prepared for Distribution to the Provider Community, “Numbered” Program Memorandums (Including Intermediary and Carrier Letters and CMS Transmittals)
I.5 -- Provider Cost Data Tapes (from Cost Reports)
Directly release data arrays used to formulate routine cost limits for providers (include provider name, number, address, bed size, HI days, per diem and cost limit).
I.6 -- Profiles of Customary Charges, Compilations of Prevailing Charges or Fee Schedules
Remove the frequency field when releasing profiles of customary charges that identify individual practitioners. Remove personal identifiers from backup data for prevailing charges - unless the profiled practitioner is also the FOIA requester. Provide profiles of customary charges free of charge once per year to each practitioner who requests his or her own profile.
I.7 -- Lists of Medicare Contractors, Providers and Suppliers, including
Provider Numbers.
I.8 -- CMS Manuals
The receiving component or contractor will meet requests for portions of manuals. If the request is for a complete manual, refer the requester to the Superintendent of Documents, Government Printing Office, P.O. Box 37194, Pittsburgh, PA. 15250-7954. (Phone Number: (202) 512-1800; fax number: (202) 512-2250), or to the nearest Regional Depository.
I.9 -- Hospital Diagnostic Related Group (DRG) Reports.
I.10 -- Statistical Prospective Payment Data
Release as provided in Regional Office guidance.
I.11 -- All Material Listed in the FOIA Index
The Index is a listing required by the Act, of all final opinions, orders made in the adjudication of cases and statements of policy and interpretations which have been adopted by the Agency but are not published in the Federal Register. The Index is published in the Federal Register and can be purchased from GPO.
I.12 -- Documents Addressing Medicare Coverage Issues.
Release documents listing and/or describing acceptable diagnostic/procedure codes, rate schedules, covered services. Do not release documents that contain any internal claims processing guidelines, service frequency and/or dollar limits.
I.13 -- Summary Provider Statistical and Reimbursement (PS&R) Reports
I.14 -- FOIA Request(s) Made by Other Requesters
Release the name of the FOIA requester. Do not release home addresses and phone numbers.
D.
Regional Office Authorized Direct Releases
The second category of exceptions (identified herein by the prefix “II”) includes those records that Medicare contractors may release when instructed to do so by their Regional Office.
II.1 --
Data that contrast a contractor's performance with the performance of any other contractor, or which compare a contractor's…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .