Vous êtes sur la page 1sur 5

Federal Register / Vol. 72, No.

126 / Monday, July 2, 2007 / Notices 36005

are otherwise authorized by these applies. Federal, HHS, and CMS DEPARTMENT OF HEALTH AND
routine uses may only be made if, and policies and standards include but are HUMAN SERVICES
as, permitted or required by the not limited to: all pertinent National
‘‘Standards for Privacy of Individually Institute of Standards and Technology Centers for Medicare & Medicaid
Identifiable Health Information.’’ (See publications; the HHS Information Services
45 CFR 164.512(a)(1)). Systems Program Handbook and the
In addition, our policy will be to CMS Information Security Handbook. Privacy Act of 1974; Report of a New
prohibit release even of data not directly System of Records
identifiable, except pursuant to one of RETENTION AND DISPOSAL:
AGENCY: Department of Health and
the routine uses or if required by law, Records are maintained in a secure Human Services (HHS), Center for
if we determine there is a possibility storage area with identifiers for 6 years Medicare & Medicaid Services (CMS).
that an individual can be identified 3 months after final action of the case
is completed. All claims-related records ACTION: Notice of a New System of
through implicit deduction based on
are encompassed by the document Records (SOR).
small cell sizes (instances where the
patient population is so small that preservation order and will be retained SUMMARY: In accordance with the
individuals could, because of the small until notification is received from DOJ. requirements of the Privacy Act of 1974,
size, use this information to deduce the we are proposing to establish a new
SYSTEM MANAGER(S) AND ADDRESS:
identity of the beneficiary). system titled, ‘‘State Health Insurance
Director, Division of Premium Billing
POLICIES AND PRACTICES FOR STORING, Assistance Program (SHIP) National
and Collections, Accounting
RETRIEVING, ACCESSING, RETAINING, AND Performance Report (SHIP–NPR),’’
Management Group, Office of Financial
DISPOSING OF RECORDS IN THE SYSTEM: System No. 09–70–0510. The demands,
Management, CMS, Mail Stop N3–21–
expectations and funding for the State
STORAGE: 06, 7500 Security Boulevard, Baltimore,
Health Insurance Assistance Program
All records are stored on direct access Maryland 21244–1850.
(SHIP) increased under the Medicare
storage devices and other electronically Prescription Drug, Improvement, and
NOTIFICATION PROCEDURE:
retrievable media. Modernization Act of 2003 (MMA).
For purpose of access, the subject
RETRIEVABILITY: individual should write to the system Under this increase CMS is now
Information can be retrieved by name, manager who will require the system required to implement an improved
HICN, and assigned agency name, HICN, address, date of birth, and performance measurement system to
identification number. gender, and for verification purposes, manage the program effectively. This
the subject individual’s name (woman’s includes increased access to
SAFEGUARDS: personalized counseling services by
maiden name, if applicable), and SSN.
CMS has safeguards in place for Furnishing the SSN is voluntary, but it beneficiaries and enrollment assistance
authorized users and monitors such may make searching for a record easier provided to beneficiaries in the MMA.
users to ensure against unauthorized and prevent delay. The purpose of this system is to
use. Personnel having access to the collect and maintain information on
system have been trained in the Privacy RECORD ACCESS PROCEDURE: how beneficiaries use SHIP services,
Act and information security For purpose of access, use the same which includes individually identifiable
requirements. Employees who maintain procedures outlined in Notification information on Medicare and Medicaid
records in this system are instructed not Procedures above. Requestors should beneficiaries who have contacted SHIP
to release data until the intended also specify the record contents being representatives. Information retrieved
recipient agrees to implement sought. (These procedures are in from this system may be disclosed to:
appropriate management, operational accordance with department regulation (1) Support regulatory, reimbursement,
and technical safeguards sufficient to 45 CFR 5b.5(a)(2)). and policy functions performed within
protect the confidentiality, integrity and the agency or by a contractor, consultant
availability of the information and CONTESTING RECORDS PROCEDURES: or CMS grantee; (2) assist another
information systems and to prevent The subject individual should contact Federal or state agency with information
unauthorized access. the system manager named above, and to contribute to the accuracy of CMS’s
This system will conform to all reasonably identify the records and payment of Medicare benefits, enable
applicable Federal laws and regulations specify the information to be contested. such agency to administer a Federal
and Federal, HHS, and CMS policies State the corrective action sought and health benefits program, or to enable
and standards as they relate to the reasons for the correction with such agency to fulfill a requirement of
information security and data privacy. supporting justification. (These Federal statute or regulation that
These laws and regulations may apply Procedures are in accordance with implements a health benefits program
but are not limited to: The Privacy Act Department regulation 45 CFR 5b.7). funded in whole or in part with Federal
of 1974; the Federal Information funds; (3) support litigation involving
RECORDS SOURCE CATEGORIES:
Security Management Act of 2002; the the agency; and (4) combat fraud, waste
Computer Fraud and Abuse Act of 1986; Information contained in this system and abuse in certain Federally-funded
the Health Insurance Portability and is obtained from third party agencies, health benefits programs. We have
Accountability Act of 1996; the E- Social Security Administration’s Master provided background information about
Government Act of 2002, the Clinger- Beneficiary Record, and CMS’ the new system in the SUPPLEMENTARY
Cohen Act of 1996; the Medicare Enrollment Database. INFORMATION section below. Although
Modernization Act of 2003, and the the Privacy Act requires only that CMS
jlentini on PROD1PC65 with NOTICES

SYSTEMS EXEMPTED FROM CERTAIN PROVISIONS


corresponding implementing OF THE ACT: provide an opportunity for interested
regulations. OMB Circular A–130, persons to comment on the proposed
None.
Management of Federal Resources, routine uses, CMS invites comments on
Appendix III, Security of Federal [FR Doc. E7–12679 Filed 6–29–07; 8:45 am] all portions of this notice. See Effective
Automated Information Resources also BILLING CODE 4120–03–P Dates section for comment period.

VerDate Aug<31>2005 22:57 Jun 29, 2007 Jkt 211001 PO 00000 Frm 00039 Fmt 4703 Sfmt 4703 E:\FR\FM\02JYN1.SGM 02JYN1
36006 Federal Register / Vol. 72, No. 126 / Monday, July 2, 2007 / Notices

DATES: Effective Date: CMS filed a new database for the purpose of quality the system. Disclosure of information
SOR report with the Chair of the House improvement of the SHIP Network. from the system will be approved only
Committee on Oversight and The SHIP–NPR is part of an overall to the extent necessary to accomplish
Government Reform, the Chair of the effort by CMS to monitor and assess the purpose of the disclosure and only
Senate Committee on Homeland customer service information efforts, after CMS:
Security & Governmental Affairs, and and develop outcome measures to assess 1. Determines that the use or
the Administrator, Office of Information CMS’ progress in improving overall disclosure is consistent with the reason
and Regulatory Affairs, Office of communications with beneficiaries and that the data is being collected; e.g., to
Management and Budget (OMB) on June other partners over time. As part of the collect and maintain information on
25, 2007. To ensure that all parties have tasks associated with this effort, a how beneficiaries use SHIP services,
adequate time in which to comment, the contractor provided assistance to CMS which includes individually identifiable
new system will become effective 30 staff who were developing program- information on Medicare and Medicaid
days from the publication of the notice, monitoring systems of their customer beneficiaries who have contacted SHIP
or 40 days from the date it was service and information projects with representatives.
submitted to OMB and the Congress, the objective to achieve continuous 2. Determines that:
whichever is later. We may defer quality improvement. a. The purpose for which the
implementation of this system or one or disclosure is to be made can only be
I. Description of the Proposed System of accomplished if the record is provided
more of the routine use statements listed
Records in individually identifiable form;
below if we receive comments that
persuade us to defer implementation. A. Statutory and Regulatory Basis for b. The purpose for which the
SOR disclosure is to be made is of sufficient
ADDRESSES: The public should send importance to warrant the effect and/or
comments to: CMS Privacy Officer, The statutory authority for risk on the privacy of the individual that
Division of Privacy Compliance, maintenance of this system is given additional exposure of the record might
Enterprise Architecture and Strategy under § 4360 of Omnibus Budget bring; and
Group, Office of Information Services, Reconciliation Act of 1990 (Pub. L. 101– c. There is a strong probability that
CMS, Room N2–04–27, 7500 Security 508), the outreach and education the proposed use of the data would in
Boulevard, Baltimore, Maryland 21244– requirements of the Balanced Budget fact accomplish the stated purpose(s).
1850. Comments received will be Act of 1997, and the Medicare 3. Requires the information recipient
available for review at this location, by Prescription Drug, Improvement, and to:
appointment, during regular business Modernization Act of 2003. a. Establish administrative, technical,
hours, Monday through Friday from 9 and physical safeguards to prevent
B. Collection and Maintenance of Data
a.m.—3 p.m., Eastern Time zone. unauthorized use of disclosure of the
in the System
FOR FURTHER INFORMATION CONTACT: record;
The system will collect and maintain b. Remove or destroy, at the earliest
Patricia Gongloff, Division of State
individually identifiable information on time, all patient-identifiable
Health Insurance Program Relations,
Medicare and Medicaid beneficiaries information; and
Strategic Research & Campaign
who have contacted SHIP c. Agree to not use or disclose the
Management Group, Office of External
representatives, as well as the SHIP information for any purpose other than
Affairs, Mail Stop S1–13–05, Centers for
counselors. Information collected the stated purpose under which the
Medicare & Medicaid Services, 7500
includes, but is not limited to: Name, information was disclosed.
Security Boulevard, Baltimore, MD
counseling zip code, beneficiary zip 4. Determines that the data are valid
21244–1849. She can be reached by
code, telephone number, data of birth, and reliable.
telephone at 410–786–7610, or via e-
gender, race/ethnicity and date of
mail at Patricia.Gongloff@cms.hhs.gov. III. Proposed Routine Use Disclosures
contact.
SUPPLEMENTARY INFORMATION: The of Data in the System
demands, expectations and funding for II. Agency Policies, Procedures, and
A. The Privacy Act allows us to
the State Health Insurance Assistance Restrictions on the Routine Use
disclose information without an
Program (SHIP) increased under the A. The Privacy Act permits us to individual’s consent if the information
MMA. Under this increase CMS is now disclose information without an is to be used for a purpose that is
required to implement an improved individual’s consent if the information compatible with the purpose(s) for
performance measurement system to is to be used for a purpose that is which the information was collected.
manage the program effectively. This compatible with the purpose(s) for Any such compatible use of data is
includes increased access to which the information was collected. known as a ‘‘routine use.’’ The proposed
personalized counseling services by Any such disclosure of data is known as routine uses in this system meet the
beneficiaries and enrollment assistance a ‘‘routine use.’’ The Government will compatibility requirement of the Privacy
provided to beneficiaries in the MMA. only release SHIP–NPR information that Act. We are proposing to establish the
The SHIP–NPR will provide can be associated with an individual as following routine use disclosures of
maintenance support and evaluate data, provided for under ‘‘Section III. information maintained in the system:
and implement performance targets Proposed Routine Use Disclosures of 1. To agency contractors, consultants
established by CMS. Further efforts will Data in the System.’’ Both identifiable or grantees, who have been engaged by
include strategies to eliminate the and non-identifiable data may be the agency to assist in the performance
duplication in reporting of NPR data by disclosed under a routine use. We will of a service related to this collection and
SHIPs to CMS and other agencies only collect the minimum personal data who need to have access to the records
jlentini on PROD1PC65 with NOTICES

providing services to beneficiaries, necessary to achieve the purpose of in order to perform the activity.
reduce the under-reporting of data on SHIP–NPR. We contemplate disclosing
services provided by SHIPs, and CMS has the following policies and information under this routine use only
development of a system to validate procedures concerning disclosures of in situations in which CMS may enter
data prior to entry into the NPR information that will be maintained in into a contractual or similar agreement

VerDate Aug<31>2005 22:57 Jun 29, 2007 Jkt 211001 PO 00000 Frm 00040 Fmt 4703 Sfmt 4703 E:\FR\FM\02JYN1.SGM 02JYN1
Federal Register / Vol. 72, No. 126 / Monday, July 2, 2007 / Notices 36007

with a third party to assist in 4. To a CMS contractor (including, but ‘‘Standards for Privacy of Individually
accomplishing CMS functions relating not necessarily limited to, fiscal Identifiable Health Information.’’ (See
to purposes for this system. intermediaries and carriers) that assists 45 CFR 164.512(a) (1)).
CMS occasionally contracts out in the administration of a CMS- In addition, our policy will be to
certain of its functions when doing so administered health benefits program, prohibit release even of data not directly
would contribute to effective and or to a grantee of a CMS-administered identifiable, except pursuant to one of
efficient operations. CMS must be able grant program, when disclosure is the routine uses or if required by law,
to give a contractor, consultant or deemed reasonably necessary by CMS to if we determine there is a possibility
grantee whatever information is prevent, deter, discover, detect, that an individual can be identified
necessary for the contractor or investigate, examine, prosecute, sue through implicit deduction based on
consultant to fulfill its duties. In these with respect to, defend against, correct, small cell sizes (instances where the
situations, safeguards are provided in remedy, or otherwise combat fraud, patient population is so small that an
the contract prohibiting the contractor, waste or abuse in such programs. individual could, because of the small
consultant or grantee from using or We contemplate disclosing size, use this information to deduce the
disclosing the information for any information under this routine use only identity of the beneficiary).
purpose other than that described in the in situations in which CMS may enter
IV. Safeguards
contract and requires the contractor, into a contractual, grantee, cooperative
consultant or grantee to return or agreement or consultant relationship CMS has safeguards in place for
destroy all information at the with a third party to assist in authorized users and monitors such
completion of the contract. accomplishing CMS functions relating users to ensure against unauthorized
2. To another Federal or state agency to the purpose of combating fraud, use. Personnel having access to the
to: waste and abuse. CMS occasionally system have been trained in the Privacy
a. Contribute to the accuracy of CMS’s contracts out certain of its functions or Act and information security
proper payment of Medicare benefits; makes grants or cooperative agreements requirements. Employees who maintain
b. Enable such agency to administer a when doing so would contribute to records in this system are instructed not
Federal health benefits program, or, as effective and efficient operations. CMS to release data until the intended
necessary, to enable such agency to must be able to give a contractor, recipient agrees to implement
fulfill a requirement of a Federal statute grantee, consultant or other legal agent appropriate management, operational
or regulation that implements a health whatever information is necessary for and technical safeguards sufficient to
benefits program funded in whole or in the agent to fulfill its duties. In these protect the confidentiality, integrity and
part with Federal funds; and/or situations, safeguards are provided in availability of the information and
c. Assist Federal/state Medicaid the contract prohibiting the agent from information systems and to prevent
programs within the state. using or disclosing the information for unauthorized access.
Other Federal or state agencies, in any purpose other than that described in This system will conform to all
their administration of a Federal health the contract and requiring the agent to applicable Federal laws and regulations
program, may require SHIP–NPR return or destroy all information. and Federal, HHS, and CMS policies
information in order to support 5. To another Federal agency or to an and standards as they relate to
evaluations and monitoring of Medicare instrumentality of any governmental information security and data privacy.
claims information of beneficiaries, jurisdiction within or under the control These laws and regulations may apply
including proper reimbursement for of the United States (including any State but are not limited to: The Privacy Act
services provided. or local governmental agency), that of 1974; the Federal Information
3. To the Department of Justice (DOJ), administers, or that has the authority to Security Management Act of 2002; the
court or adjudicatory body when: investigate potential fraud, waste or Computer Fraud and Abuse Act of 1986;
a. The agency or any component abuse in, a health benefits program the Health Insurance Portability and
thereof, or funded in whole or in part by Federal Accountability Act of 1996; the E-
b. Any employee of the agency in his funds, when disclosure is deemed Government Act of 2002, the Clinger-
or her official capacity, or reasonably necessary by CMS to Cohen Act of 1996; the Medicare
c. Any employee of the agency in his prevent, deter, discover, detect, Modernization Act of 2003, and the
or her individual capacity where the investigate, examine, prosecute, sue corresponding implementing
DOJ has agreed to represent the with respect to, defend against, correct, regulations. OMB Circular A–130,
employee, or remedy, or otherwise combat fraud, Management of Federal Resources,
d. The United States Government is a waste or abuse in such programs. Appendix III, Security of Federal
party to litigation or has an interest in Other agencies may require SHIP-NPR Automated Information Resources also
such litigation, and, by careful review, information for the purpose of applies. Federal, HHS, and CMS
CMS determines that the records are combating fraud, waste and abuse in policies and standards include but are
both relevant and necessary to the such Federally-funded programs. not limited to: All pertinent National
litigation and that the use of such Institute of Standards and Technology
records by the DOJ, court or B. Additional Provisions Affecting
publications; the HHS Information
adjudicatory body is compatible with Routine Use Disclosures
Systems Program Handbook and the
the purpose for which the agency To the extent this system contains CMS Information Security Handbook.
collected the records. Protected Health Information (PHI) as
Whenever CMS is involved in defined by HHS regulation ‘‘Standards V. Effects of the Proposed System of
litigation, and occasionally when for Privacy of Individually Identifiable Records on Individual Rights
another party is involved in litigation Health Information’’ (45 CFR Parts 160 CMS proposes to establish this system
jlentini on PROD1PC65 with NOTICES

and CMS policies or operations could be and 164, Subparts A and E) 65 Fed. Reg. in accordance with the principles and
affected by the outcome of the litigation, 82462 (12–28–00). Disclosures of such requirements of the Privacy Act and will
CMS would be able to disclose PHI that are otherwise authorized by collect, use, and disseminate
information to the DOJ, court or these routine uses may only be made if, information only as prescribed therein.
adjudicatory body involved. and as, permitted or required by the Data in this system will be subject to the

VerDate Aug<31>2005 22:57 Jun 29, 2007 Jkt 211001 PO 00000 Frm 00041 Fmt 4703 Sfmt 4703 E:\FR\FM\02JYN1.SGM 02JYN1
36008 Federal Register / Vol. 72, No. 126 / Monday, July 2, 2007 / Notices

authorized releases in accordance with PURPOSE(S) OF THE SYSTEM: DOJ has agreed to represent the
the routine uses identified in this The purpose of this system is to employee, or
system of records. collect and maintain information on d. The United States Government, is
CMS will take precautionary how beneficiaries use SHIP services, a party to litigation or has an interest in
measures to minimize the risks of which includes individually identifiable such litigation, and, by careful review,
unauthorized access to the records and information on Medicare and Medicaid CMS determines that the records are
the potential harm to individual privacy beneficiaries who have contacted SHIP both relevant and necessary to the
or other personal or property rights of representatives. Information retrieved litigation and that the use of such
patients whose data are maintained in from this system may be disclosed to: records by the DOJ, court or
this system. CMS will collect only that (1) Support regulatory, reimbursement, adjudicatory body is compatible with
information necessary to perform the and policy functions performed within the purpose for which the agency
system’s functions. In addition, CMS the agency or by a contractor, consultant collected the records.
will make disclosure from the proposed or CMS grantee; (2) assist another 4. To a CMS contractor (including, but
system only with consent of the subject Federal or state agency with information not necessarily limited to, fiscal
individual, or his/her legal to contribute to the accuracy of CMS’s intermediaries and carriers) that assists
representative, or in accordance with an payment of Medicare benefits, enable in the administration of a CMS-
applicable exception provision of the such agency to administer a Federal administered health benefits program,
Privacy Act. CMS, therefore, does not health benefits program, or to enable or to a grantee of a CMS-administered
anticipate an unfavorable effect on such agency to fulfill a requirement of grant program, when disclosure is
individual privacy as a result of Federal statute or regulation that deemed reasonably necessary by CMS to
information relating to individuals. implements a health benefits program prevent, deter, discover, detect,
Dated: June 21, 2007. funded in whole or in part with Federal investigate, examine, prosecute, sue
Charlene Frizzera, funds; (3) support litigation involving with respect to, defend against, correct,
Chief Operating Officer, Centers for Medicare the agency; and (4) combat fraud, waste remedy, or otherwise combat fraud,
& Medicaid Services. and abuse in certain Federally-funded waste or abuse in such program.
health benefits programs. 5. To another Federal agency or to an
SYSTEM NO. 09–70–0510
ROUTINE USES OF RECORDS MAINTAINED IN THE instrumentality of any governmental
SYSTEM NAME: SYSTEM, INCLUDING CATEGORIES OR USERS AND jurisdiction within or under the control
‘‘State Health Insurance Assistance THE PURPOSES OF SUCH USES: of the United States (including any State
Program (SHIP) National Performance A. The Privacy Act allows us to or local governmental agency), that
Report (SHIP-NPR),’’ HHS/CMS/OEA. disclose information without an administers, or that has the authority to
individual’s consent if the information investigate potential fraud, waste or
SECURITY CLASSIFICATION: abuse in, a health benefits program
is to be used for a purpose that is
Level Three Privacy Act Sensitive compatible with the purpose(s) for funded in whole or in part by Federal
Data. which the information was collected. funds, when disclosure is deemed
SYSTEM LOCATION: Any such compatible use of data is reasonably necessary by CMS to
Centers for Medicare & Medicaid known as a ‘‘routine use.’’ The proposed prevent, deter, discover, detect,
Services (CMS) Data Center, 7500 routine uses in this system meet the investigate, examine, prosecute, sue
Security Boulevard, North Building, compatibility requirement of the Privacy with respect to, defend against, correct,
First Floor, Baltimore, Maryland 21244– Act. We are proposing to establish the remedy, or otherwise combat fraud,
1850 and at various co-locations of CMS following routine use disclosures of waste or abuse in such programs.
agents. information maintained in the system: B. Additional Provisions Affecting
1. To agency contractors, consultants Routine Use Disclosures.
CATEGORIES OF INDIVIDUALS COVERED BY THE or grantees, who have been engaged by To the extent this system contains
SYSTEM: the agency to assist in the performance Protected Health Information (PHI) as
The system will collect and maintain of a service related to this collection and defined by HHS regulation ‘‘Standards
individually identifiable information on who need to have access to the records for Privacy of Individually Identifiable
Medicare and Medicaid beneficiaries in order to perform the activity. Health Information’’ (45 CFR Parts 160
who have contacted SHIP 2. To another Federal or state agency and 164, Subparts A and E) 65 Fed. Reg.
representatives, as well as the SHIP to: 82462 (12–28–00). Disclosures of such
counselors. a. Contribute to the accuracy of CMS’s PHI that are otherwise authorized by
proper payment of Medicare benefits; these routine uses may only be made if,
CATEGORIES OF RECORDS IN THE SYSTEM: b. Enable such agency to administer a
Information collected includes, but is and as, permitted or required by the
Federal health benefits program, or, as
not limited to: Name, counseling zip ‘‘Standards for Privacy of Individually
necessary, to enable such agency to
code, beneficiary zip code, telephone Identifiable Health Information.’’ (See
fulfill a requirement of a Federal statute
number, data of birth, gender, race/ 45 CFR 164.512(a) (1)).
or regulation that implements a health
ethnicity and date of contact. benefits program funded in whole or in In addition, our policy will be to
part with Federal funds; and/or prohibit release even of data not directly
AUTHORITY FOR MAINTENANCE OF THE SYSTEM: identifiable, except pursuant to one of
c. Assist Federal/state Medicaid
The statutory authority for programs within the state. the routine uses or if required by law,
maintenance of this system is given 3. To the Department of Justice (DOJ), if we determine there is a possibility
under § 4360 of Omnibus Budget court or adjudicatory body when: that an individual can be identified
Reconciliation Act of 1990 (Pub. L. 101– a. The agency or any component through implicit deduction based on
jlentini on PROD1PC65 with NOTICES

508), the outreach and education thereof, or small cell sizes (instances where the
requirements of the Balanced Budget b. Any employee of the agency in his patient population is so small that an
Act of 1997, and the Medicare or her official capacity, or individual could, because of the small
Prescription Drug, Improvement, and c. Any employee of the agency in his size, use this information to deduce the
Modernization Act of 2003. or her individual capacity where the identity of the beneficiary).

VerDate Aug<31>2005 22:57 Jun 29, 2007 Jkt 211001 PO 00000 Frm 00042 Fmt 4703 Sfmt 4703 E:\FR\FM\02JYN1.SGM 02JYN1
Federal Register / Vol. 72, No. 126 / Monday, July 2, 2007 / Notices 36009

POLICIES AND PRACTICES FOR STORING, SYSTEM MANAGER AND ADDRESS: Paperwork Reduction Act (44 U.S.C.
RETRIEVING, ACCESSING, RETAINING, AND Division of State Health Insurance Chapter 35). OMB approval has been
DISPOSING OF RECORDS IN THE SYSTEM: requested within 20 days of publication
Program Relations, Strategic Research &
STORAGE: Campaign Management Group, Office of of this notice. To request more
External Affairs, Mail Stop S1–13–05, information on the proposed project or
All records are stored on electronic
Centers for Medicare & Medicaid to obtain a copy of the data collection
media.
Services, 7500 Security Boulevard, plans and draft instruments, call the
RETRIEVABILITY: Baltimore, MD 21244–1849. HRSA Reports Clearance Officer on
The collected data are retrieved by the (301) 443–1129.
NOTIFICATION PROCEDURE: Written comments and
name or other identifying information of
For purpose of access, the subject recommendations should be sent within
the participating provider or
individual should write to the system 14 days of publication of this notice to
beneficiary, and may also be retrieved
manager who will require the system the desk officer for HRSA, either by e-
by a distinct identifier such as the
name, employee identification number, mail to OIRA_submission@omb.eop.gov
Health Insurance Claim Number (HICN),
tax identification number, national or by fax to 202–395–6974. Please direct
at the individual beneficiary level. all correspondence ‘‘to the attention of
provider number, and for verification
SAFEGUARDS: purposes, the subject individual’s name the desk officer for HRSA.’’
CMS has safeguards in place for (woman’s maiden name, if applicable), Proposed Project: Ryan White HIV/
authorized users and monitors such HICN, and/or Social Security Number AIDS Program Core Medical Services
users to ensure against unauthorized (SSN) (furnishing the SSN is voluntary, Waiver Application Requirements
use. Personnel having access to the but it may make searching for a record (NEW)
system have been trained in the Privacy easier and prevent delay).
Title XXVI of the Public Health
Act and information security RECORD ACCESS PROCEDURE: Service (PHS) Act, as amended by the
requirements. Employees who maintain For purpose of access, use the same Ryan White HIV/AIDS Treatment
records in this system are instructed not procedures outlined in Notification Modernization Act of 2006 (Ryan White
to release data until the intended Procedures above. Requestors should HIV/AIDS Program) requires that
recipient agrees to implement also reasonably specify the record grantees expend 75 percent of Parts A,
appropriate management, operational contents being sought. (These B, and C funds on core medical services,
and technical safeguards sufficient to procedures are in accordance with including antiretroviral drugs, for
protect the confidentiality, integrity and Department regulation 45 CFR individuals with HIV/AIDS identified
availability of the information and 5b.5(a)(2)). and eligible under the legislation,
information systems and to prevent effective Fiscal Year (FY) 2007. In order
unauthorized access. CONTESTING RECORD PROCEDURES: for grantees under Parts A, B, and C to
This system will conform to all The subject individual should contact be exempted from the 75 percent core
applicable Federal laws and regulations the system manager named above, and medical services requirement, they must
and Federal, HHS, and CMS policies reasonably identify the record and request and receive a waiver from
and standards as they relate to specify the information to be contested. HRSA, as required in the Act. HRSA has
information security and data privacy. State the corrective action sought and developed a process for waiver request
These laws and regulations may apply the reasons for the correction with submission, review, and notification.
but are not limited to: The Privacy Act supporting justification. (These The core medical services waiver
of 1974; the Federal Information procedures are in accordance with uniform standard and waiver request
Security Management Act of 2002; the Department regulation 45 CFR 5b.7). process will apply to Ryan White HIV/
Computer Fraud and Abuse Act of 1986; AIDS Program grant awards under Parts
RECORDS SOURCE CATEGORIES:
the Health Insurance Portability and A, B, and C of Title XXVI of the PHS
Accountability Act of 1996; the E- Data will be collected from Medicare Act beginning FY 2008. Core medical
Government Act of 2002, the Clinger- and SHIP administrative records. services waivers will be effective for a
Cohen Act of 1996; the Medicare SYSTEMS EXEMPTED FROM CERTAIN PROVISIONS one-year period consistent with the
Modernization Act of 2003, and the OF THE ACT: grant award period.
corresponding implementing None. Grantees must submit a waiver
regulations. OMB Circular A–130, request with the annual grant
Management of Federal Resources, [FR Doc. E7–12680 Filed 6–29–07; 8:45 am] application containing the following
Appendix III, Security of Federal BILLING CODE 4120–03–P certifications and documentations
Automated Information Resources also which will be utilized by HRSA in
applies. Federal, HHS, and CMS making determinations regarding waiver
policies and standards include but are DEPARTMENT OF HEALTH AND requests. The waiver must include:
not limited to: All pertinent National HUMAN SERVICES 1. Certification from the Part B state
Institute of Standards and Technology grantee that there are no current or
Health Resources and Services
publications; the HHS Information anticipated ADAP services waiting lists
Administration
Systems Program Handbook and the in the state for the year in which such
CMS Information Security Handbook. Agency Information Collection waiver request is made. This
Activities Under Emergency Review for certification must also specify that there
RETENTION AND DISPOSAL: are no waiting lists for a particular core
the Office of Management and Budget
Records will be retained for a period (OMB) class of antiretroviral therapeutics
jlentini on PROD1PC65 with NOTICES

of 6 years and 3 months. All claims- established by the Secretary, e.g., fusion
related records are encompassed by the The Health Resources and Services inhibitors;
document preservation order and will Administration (HRSA) has submitted 2. Certification that all core medical
be retained until notification is received the following request (see below) for services listed in the statute (Part A
from DOJ. emergency OMB review under the section 2604(c)(3), Part B section

VerDate Aug<31>2005 22:57 Jun 29, 2007 Jkt 211001 PO 00000 Frm 00043 Fmt 4703 Sfmt 4703 E:\FR\FM\02JYN1.SGM 02JYN1

Vous aimerez peut-être aussi