Attachment_J.1-_Incident_Reporting_Guide.pdf
PDF 120 KB Posted
- Attached to
- Research, Measurement, Assessment, Design, and Analysis (RMADA) IDIQ Federal contract opportunity
- Solicitation number
- RFP-CMS-RMADA-2014
About this file
Attachment J.1
View the file
Other files for this federal contract opportunity
Show all 40
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Office of E-Health Standards and Services
CMS Guide for the
Incident Reporting Process
December 2010 i
Centers for Medicare & Medicaid Services
Incident Reporting Process Guide
Executive Summary
The Centers for Medicare & Medicaid Services (CMS) is the federal agency with administrative authority for Medicare, Medicaid, and the Children’s Health Insurance Program (CHIP). In administering these health care programs, CMS is responsible for safeguarding personally identifiable information (PII), including protected health information (PHI), that’s collected, used, and disclosed in the agency’s day-to-day operations. Safeguarding PII/PHI is essential to retaining the trust of its program beneficiaries and the American public.
CMS operates under federal privacy and security requirements that apply to both a federal agency and as a health care component subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Privacy Act of 1974 and the Federal Information Security Act of 2002 (FISMA) are the primary authorities that apply to CMS in safeguarding PII and also by those who work on the agency’s behalf. Additionally, CMS has administrative responsibility for the Original Medicare Plan (fee-for-service program) which is a covered entity subject to HIPAA privacy and security standards enforced by the Office for Civil Rights (OCR) in the Department of Health and Human Services (HHS).
CMS’ Data Governance Board (DGB), chaired by the Senior Agency Official for Privacy (SAOP), establishes and oversees the agency’s data governance and privacy policies. One of the DGB priorities is to oversee the formulation of strategies and decisions to implement a coordinated and consistent agency-wide response to PII/PHI security incident reporting/handling and breach notification. The agency’s incident handling process ensures each incident reported by an entity subject to FISMA is appropriately triaged and assessed in accordance with established policies and procedures based on Federal privacy and security requirements, including applicable breach notification provisions issued by the Office of Management and Budget (OMB) and the HHS OCR. There is close coordination between the CMS SAOP, Chief Information Officer (CIO), and Chief Information Security Officer (CISO).
CMS works with its HHS counterparts on privacy and security policies and procedures, including breach notification. CMS is a member of the HHS PII Privacy Incident Response Team (PIRT), formerly the HHS Breach Response Team.
This Guide provides the agency’s policies, processes, and procedures for handling security incidents involving PII/PHI, breach analysis, and required notification.
ii
Table of Contents
1. Introduction
1.1 Purpose/Scope
1.2 Background/Authority
1.2.1 OMB Breach Notification Guidance
1.2.1 HITECH Breach Notification Provisions
2. CMS Incident Reporting Process
2.1 Overview
2.2 Incident Reporting: CMS IT Service Desk
2.3 CMS CSIRT Triage
2.3.1 Assessment Guidelines
2.4 Pre-Breach Analysis Team (BAT)
2.5 Breach Analysis Team (BAT)
2.6 Breach Notification
3. Medicare Fee-for-Service Program
3.1 Overview
3.3 Incident Reporting
4. Other FISMA Entities
4.1 Overview
4.2 Analytical Contractors
4.3 Program Integrity Contractors
4.4 Quality Improvement Organizations
5. External Research Entities
5.1 Overview
5.2 Research Entities
6. Non-FISMA Entities
6.1 Overview
6.2 Private Medicare Plans
6.3 State Medicaid Programs
iii
7. High/Risk/Profile Breaches
Appendices
Appendix A – Side-by-Side OMB and HITECH Breach Notification for PII/PHI
Appendix B – CSIRT Assessment Guidelines
Appendix C – Breach Analysis Team Evaluation/Recommendation(s)
Appendix D – Roles and Responsibilities of OESS and OIS
Appendix E – Guidelines for Implementing the Revised Information Security Incident Handling and Breach Analysis/Notification Procedures, JSM/TDL-09323, 06-09-09
Appendix F – Chart on Medicare FFS Incident Reporting/Handling and Breach Notification Process
Appendix G – Health Plan Management System (HPMS) Memorandum: Update on Security and Privacy Breach Reporting Procedures, September 28, 2010
Appendix H – State Medicaid Director Letter #06-022, 9/20/06 and Procedures for Reporting Security Incidents
1. Introduction
1.1 Purpose/Scope
This Guide provides information for CMS staff and agency contractors/business associates on agency-wide policies, processes, and procedures for reporting and handling incidents involving personally identifiable information (PII) and/or protected health information (PHI) and breach notification, as required. Additionally, the Guide addresses the incident reporting process for other entities (e.g., private plans, State Medicaid programs) to the appropriate CMS component.
Applicable federal privacy and security laws and regulations, as well as agency policies and procedures, are cited throughout the Guide with links provided to their URL sites (for 508 compliance issues, please e-mail CMS OESS_508@cms.hhs.gov). Policies and documents that relate to the process and procedures, including guidance materials developed by the agency’s Incident Reporting Process Workgroup and approved by the Data Governance Board (DGB), are also referenced as Appendices and hyperlinked throughout the Guide.
1.2 Background/Authority
CMS operates under federal privacy and security requirements as both a Federal agency and as a health care component of the Department of Health and Human Services (HHS) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Privacy Act of 1974 is the primary authority under which CMS, as a federal agency, may collect, use, and disclose PII necessary to accomplish program purposes and operations. The Office of Management and Budget (OMB) is responsible for developing guidance and providing assistance to and oversight of the agencies’ Privacy Act implementation. Additionally, CMS is subject to the Federal Information Security Act of 2001 (FISMA) which places responsibility and accountability for information security on CMS as well as entities which operate, use, or have access to federal information systems on the agency’s behalf.
CMS is also subject to the HIPAA Privacy Rule in administering the Original Medicare Plan (fee-for-service program). The agency has been designated as a HHS health care component under HIPAA to the extent that its activities relate to the administration of the Medicare fee-for-service (FFS) health plan. This means CMS is responsible for the Original Medicare program’s compliance with HIPAA standards. Other health plans, such as the State Medicaid programs and Medicare Parts C and D plans, are covered entities subject to HIPAA in their own right and responsible for their own compliance. The Office for Civil Rights (OCR) of HHS enforces the HIPAA privacy and security standards for all these health plans and other covered entities.
In May 2006, the Department of Veterans Affairs (VA) experienced a theft of an unencrypted laptop containing personal information on millions of veterans. The VA incident resulted in considerable attention to and concern about information security breaches and potential mass identify theft affecting federal agencies. The President’s Task Force on Identity Theft was created and called for a coordinated and strategic approach among agencies to combat identity theft. OMB issued guidance on agencies’ duty to safeguard PII to prevent its misuse or unauthorized access, with specific direction on the framework within which a breach notification policy and plan should be developed and implemented. In response to OMB’s guidance, CMS mailto:CMS%20OESS_508@cms.hhs.gov� established its Breach Analysis Team (BAT) in 2007 to review PII incidents. The BAT is modeled on the HHS Privacy Incident Response Team (PIRT) on which CMS participates.
The privacy subtitle of the Health Information Technology for Economic and Clinical Health (HITECH) Act, as part of the American Recovery and Reinvestment Act of 2009 (ARRA), contained breach notification provisions applying to HIPAA covered entities and their business associates. HHS issued the interim final rule for breaches of unsecured PHI, effective 9/23/09.
These breach notification requirements rely on OMB’s guidance and also the HITECH statutory provisions (e.g., specific timeframes).
At CMS, the DGB convened the Incident Reporting Workgroup to re-assess the agency’s current process for reporting security incidents involving PII/PHI in the context of HITECH’s breach notification provisions. Policies, processes, and procedures developed by the Workgroup, with DGB approval, ensure agency-wide compliance with federal breach notification requirements applying to entities subject to FISMA. The Workgroup also addressed incident reporting by non-FISMA entities (e.g., private plans, State Medicaid programs).
1.2.1 OMB Breach Notification Guidance
OMB guidance requires each federal agency to develop and implement a breach notification policy and plan. This guidance can be found in OMB Memorandum on Safeguarding Against and Responding to the Breach of Personally Identifiable Information, M-07-16 (May 22, 2007) at http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2007/m07- 16.pdf.
To determine whether notification outside the agency should be given and the nature of notification, the guidance identifies factors to consider in assessing the likely risk of harm caused by the breach. When breach notification is determined to be required, the guidance addresses the timeliness, source, contents, and means of the notification as well as to whom the notification should be provided. The guidance raises concerns about unnecessary notification causing a chilling effect on the public and also about the costs when the risk of harm is low.
1.2.2 HITECH Breach Notification Provisions
The HITECH breach notification provisions require a HIPAA covered entity or its business associate to provide notification to affected individuals and to the Secretary of HHS following the discovery of a breach of unsecured PHI, effective 9/23/09. The breach notification provisions, which are at http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/index.html, reference OMB’s guidance for assessing the likely risk of harm and contain specific notification requirements:
• Individuals affected by the breach receive timely notice (without unreasonable delay but not later than 60 days of a breach);
• When 500 or more individuals are affected, the covered entity provides timely notice to the HHS Secretary, and this information is posted on OCR’s web site;
http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2007/m07-16.pdf� http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2007/m07-16.pdf� http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/index.html�
• When fewer than 500 individuals are affected, the covered entity submits an annual report to the Secretary;
• When more than 500 residents of a State or jurisdiction are affected, the covered entity provides timely notice to the media;
• A business associate must promptly notify the covered entity of a breach.
The side-by-side comparison of OMB and HITECH breach notification provisions are in Appendix A at H:\OESS\IncidentReportingDocs\Appendices\A-SidebySideOMB&HITECH Reqs.docx.
2. CMS Incident Reporting Process
2.1 Overview
The Office of Information Services (OIS) is responsible for the overall administration of the CMS Information Security Program. The CMS Chief Information Officer (CIO), assisted by the Chief Information Security Officer (CISO), ensures the implementation of the systematic process of agency-wide security incident management. This includes the procedures for employees and contracted personnel to take to report suspected and actual incidents and for determining whether to provide breach notification. For information on CMS Information Security, go to http://www.cms.gov/InformationSecurity/ and the http://www.cms.gov/manuals/downloads/117_systems_security.pdf.
2.2 Incident Reporting: CMS IT Service Desk
CMS’ approach to PII/PHI incident handling begins when agency employees and contractors/business associates of entities subject to FISMA report incidents to the IT Service Desk (cms_it_service_desk@cms.hhs.gov). The IT Service Desk serves as the initial point of contact for reporting PII/PHI incidents within one hour of discovery. The IT Service Desk forwards information on these incidents to the CMS Computer Security Incident Response Team
(CSIRT).
2.3 Triage: CMS Computer Security Incident Response Team (CSIRT)
The CSIRT receives all incidents that are reported to the IT Service Desk. The CSIRT assesses, tracks, and reports PII incidents, including to HHS’ security program, CMS’ Pre-Breach Analysis Team (BAT), and/or the BAT for a full risk assessment. Responsibilities include:
• determining those incidents which must be reported immediately to the HHS Computer Security Incident Response Center (CSIRC); all others are forwarded to the CSIRC in a monthly summary;
• applying the approved Assessment Guidelines to all incidents and maintaining appropriate documentation;
• forwarding any incidents that do not fall within the Assessment Guidelines to the Pre-
BAT for further evaluation and/or triage; and http://www.cms.gov/InformationSecurity/� http://www.cms.gov/manuals/downloads/117_systems_security.pdf� mailto:cms_it_service_desk@cms.hhs.gov�
• identifying the High Risk/Profile Breaches with potential for serious harm and immediately alerting CMS’ CISO.
2.3.1 Assessment Guidelines
The CSIRT applies Assessment Guidelines to all incoming PII incidents. Approved by the DGB, these Guidelines were developed by the Workgroup to categorize incidents with little or no risk of financial, reputational, or other harm to the beneficiary. The Guidelines relate to specific situations involving Medicare documents containing PII/PHI that are received by other covered entities or beneficiaries other than to whom they were intended. The Assessment Guidelines applied by CSIRT are in Appendix B at H:\OESS\IncidentReportingDocs\Appendices\B-Assessment Guidelines.docx.
Incidents which fall within the Assessment Guidelines are documented by CSIRT. No further risk evaluation is required.
2.4 Pre-Breach Analysis Team (BAT) Triage
The Pre-BAT Triage is managed by OIS, with assistance from the Business Owner and OESS as necessary. The Pre-BAT reviews and triages incidents, as appropriate, to a BAT for a formal risk assessment or to OESS for coordinating breach notification. Responsibilities include:
• Convening a BAT for those incidents requiring a formal risk assessment, including providing background information on each incident and resource materials;
• Referring incidents requiring breach notification to OESS;
• Coordinating with the CSIRT on tracking, updating, and reporting incidents; and
• Determining and recommending appropriate policy to apply for Pre-BAT evaluation.
2.5 Breach Analysis Team (BAT)
The BAT is convened to conduct a formal risk assessment of an incident that has been referred by the Pre-BAT. The BAT is co-chaired by OIS, representing the CIO, and OESS, representing the CMS Senior Agency Official for Privacy (SAOP). Other members of the BAT include the CMS Privacy Officer, the CISO, and the Business Owner. Responsibilities include:
• Determining and documenting the likely risk of harm caused by the breach using OMB guidelines and HITECH requirements for breach notification;
• Recommending whether to provide notification and also whether to recommend 1) credit protection services be offered to affected individuals and 2) refer BAT findings to the CMS Center for Program Integrity); and
• Providing BAT findings, including recommendation on whether to notify, to the CIO, SAOP, and senior leadership of the Business Owner component.
The BAT’s evaluation procedure, including the analysis factors and recommendation(s), is in Appendix C at H:\OESS\IncidentReportingDocs\Appendices\C-BAT factors & recommendation(s) sheet .docx.
2.6 Breach Notification
OESS is responsible for overall management of the breach notification process in accordance with HITECH requirements. Responsibilities include:
• Coordinating with the Business Owner to notify affected individuals;
• Working with the SAOP to ensure the DGB and Deputy Chief Operating Officer are informed of breach notification and getting their approval, when necessary;
• Notifying HHS OCR of breaches, as required;
• Coordinating with the Office of External Affairs for notification, as required; and
• Serving as liaison to the HHS PIRT on CMS’ breach notification activities.
The roles and responsibilities of OESS and OIS for breach notification is in Appendix D at H:\OESS\IncidentReportingDocs\Appendices\D-OESS-OIS roles.doc.
3. Medicare Fee-for-Service (FFS) Program
3.1 Overview
CMS contracts with Medicare Administrative Contractors (MACs), Fiscal Intermediaries (FI), and carriers for claims payment in operating the Medicare FFS Program. As CMS contractors, these entities are subject to all federal requirements, including OMB and FISMA.
The Medicare FFS contractors are HIPAA business associates doing work on behalf of the Original Medicare health plan. The HIPAA Business Associate provision in all CMS contracts references safeguarding PHI, mitigating any harmful effect(s) of the use or disclosure of PHI, and reporting any use or disclosure not provided for under the contract. The standard HIPAA Business Associate provision that is included in all CMS contracts is found at http://cmsnet.cms.hhs.gov/hpages/oagm/PolicyClauses.htm.
3.2 Incident Reporting
Medicare FFS contractors are subject to the OMB/FISMA requirements to report all PII incidents, both suspected and confirmed breaches, within one hour. CMS provides instructions on incident reporting that starts when MACs reporting both to the IT Service Desk and to the security incident mailbox. The Guidelines for Implementing the Centers for Medicare & Medicaid Services’ (CMS) Revised Information Security Incident Handling and Breach http://cmsnet.cms.hhs.gov/hpages/oagm/PolicyClauses.htm�
Analysis/Notification Procedures, JSM/TDL-09323, 06-09-09 is in Appendix E at H:\OESS\IncidentReportingDocs\Appendices\E-JSMTDL-09323 Update2 (4).doc (The JSM/TDL’s Attachment 1 containing the Incident Reporting Template is at H:\OESS\IncidentReportingDocs\Appendices\E-Attach1-CMM version CSIRC Incident Report Template (2).doc, and the JSM/TDL’s Attachment 2 containing the CMS Information Security Incident Handling and Breach Analysis/Notification Procedures is at H:\OESS\IncidentReportingDocs\Appendices\E-Attachment2- Incident_handling_procedure_Oct08.pdf).
The overall process for Medicare FFS incident reporting, including incident handling and breach analysis/notification, is in Appendix F at H:\OESS\IncidentReportingDocs\Appendices\F- Incident reporting diagram.pdf.
4. Other CMS FISMA Entities
4.1 Overview
CMS contracts with other entities subject to FISMA to assist in the agency’s day-to-day business operations. These include analytical contractors, Program Integrity (PI) contractors, and Quality Improvement Organizations (QIO). As CMS business associates, these entities report PII/PHI incidents in accordance with the provisions in their CMS contracts/agreements. The standard HIPAA Business Associate provision that is included in all CMS contracts is found at http://cmsnet.cms.hhs.gov/hpages/oagm/PolicyClauses.htm.
The CMS data use agreement (DUA) requires reporting incidents to the IT Service Desk. For CMS’ DUA, go to http://www.cms.gov/cmsforms/downloads/cms-r-0235.pdf.
4.2 Analytical Contractors
Analytical contractors work on behalf of the agency in conducting its administrative responsibilities. Their CMS contract requires safeguarding PII/PHI in accordance with FISMA and other Federal requirements, including reporting incidents to the contractors’ Project Officers.
4.3 Program Integrity (PI) Contractors
The program integrity (PI) contractors collect and use PII on behalf of Medicare to perform such activities as medical review and PI activities to prevent fraud and abuse. These PI contractors --program safeguard contractors (PSC) and zone PI contractors (ZPIC) -- are required to report incidents in accordance with instructions in the Medicare Program Integrity Manual, 100-08 (see Chapter 4, Section 4.2.2.6.C.) at http://www.cms.gov/manuals/downloads/pim83c04.pdf.
4.4 Quality Improvement Organizations (QIO)
The QIOs conduct activities to improve the quality of care delivered to Medicare beneficiaries.
The QualityNet Security Program provides guidance on incidence response by QualityNet users, contractors, and others who process, store, transmit, or have access to PII/PHI. For the QualityNet Incident Response Procedures, go to http://www.qualitynet.org/.
http://cmsnet.cms.hhs.gov/hpages/oagm/PolicyClauses.htm� http://www.cms.gov/cmsforms/downloads/cms-r-0235.pdf� http://www.cms.gov/manuals/downloads/pim83c04.pdf� http://www.qualitynet.org/�
5. External Research Entities
5.1 Overview
The agency discloses PII/PHI to external entities to conduct research studies that will improve CMS programs or services provided to its beneficiaries. These entities are often federally funded grantees of another HHS Operating Division or other federal agency.
These external entities are not subject to FISMA. However, their research protocols include a description of the database management safeguards to ensure the privacy and confidentiality of CMS data. The entities are also required to sign the CMS DUA which requires reporting incidents involving PII to the IT Service Desk. For the DUA, go to http://www.cms.gov/cmsforms/downloads/cms-r-0235.pdf.
5.2 Research Entities
External entities are instructed to immediately notify their CMS Project Officer of a breach involving data provided by the agency for research purposes. Additionally, the entities follow the DUA’s provision to immediately report a PII breach to the IT Service Desk.
6. Non-FISMA Entities
6.1 Overview
Private Medicare plans and State Medicaid Programs are HIPAA covered entities in their own right. As such, these health plans are subject to HITECH breach notification requirements and are responsible to report breaches directly to HHS OCR, as required. CMS does not report incidents from these entities to HHS CSIRC (the agency reports incidents involving FISMA entities only).
The CMS components with program administration and oversight responsibilities for these health plans have established the process and procedures to report PII breaches.
6.2 Private Medicare Plans
CMS contracts with private health plans for health coverage choice and prescription drug coverage to beneficiaries. These Medicare Parts C and D plans are HIPAA covered entities in their own right and are responsible for reporting breaches directly to the HHS OCR in accordance with HITECH requirements. CMS requires these organizations to submit concurrent notification to their Regional Office account managers of breach notifications submitted to OCR.
Additionally, these organizations are required to comply with all federal requirements under their CMS contract, including HIPAA. CMS has authority to take compliance or enforcement actions where the agency believes organizations have not taken appropriate measures to safeguard the privacy of its Medicare members.
http://www.cms.gov/cmsforms/downloads/cms-r-0235.pdf�
The Health Plan Management System (HPMS) memorandum on Update on Security and Privacy Breach Reporting, 9/28/10, is in Appendix G at H:\OESS\IncidentReportingDocs\Appendices\G- CMS HPMS Alert_BreachNotification.pdf.
6.3 State Medicaid Programs
State Medicaid programs are health plans subject to HIPAA. As with the private Medicare C and D plans, these programs are covered entities in their own right. As such, State Medicaid programs are responsible for reporting breaches directly to the HHS OCR in accordance with HITECH requirements.
Additionally, the CMS Center for Medicaid, CHIP, and Survey and Certification has established procedures for the States to report security incidents. The State Medicaid Director Letter, SMDL #06-022, is in Appendix H at H:\OESS\IncidentReportingDocs\Appendices\H-SMDL .pdf, along with Procedures for Reporting Security Incidents at H:\OESS\IncidentReportingDocs\Appendices\H-Security Incident Reporting.doc.
7. High Risk/Profile Breaches
7.1 Overview
There may be high risk/profile breaches with the potential for serious harm to the agency and/or individual(s). This may involve a CMS program, contractor, or non-FISMA entity. The agency’s immediate attention is necessary to address these breaches.
7.2 Handling High Risk/Profile Breaches
When the CSIRT receives an incident report from a FISMA entity or the component with oversight responsibility for the non-FISMA entity (e.g., CM for private plans) with the potential to be a High Risk/Profile breach, the CSIRT or component immediately contacts the CISO. The CISO informs the CIO, SAOP, and Business Owner who together determine appropriate action, including whether to notify senior agency leadership. Additional consideration may be given to activating appropriate risk mitigation practices. Decision-making for this type of breach is on a case-by-case basis.
File details come from the government source that posted it. Updated .