Vous êtes sur la page 1sur 4

67130 Federal Register / Vol. 71, No.

223 / Monday, November 20, 2006 / Notices

Due to programmatic matters, this Dated: November 8, 2006. We are modifying the language in the
Federal Register Notice is being Michael O. Leavitt, remaining routine uses to provide a
published on less than 15 calendar days Secretary. proper explanation as to the need for the
notice to the public (41 CFR 102– [FR Doc. 06–9263 Filed 11–17–06; 8:45 am] routine use and to provide clarity to
3.150(b)). BILLING CODE 4160–18–M
CMS’s intention to disclose individual-
Contact Person for More Information: specific information contained in this
Shirley D. Little, Committee system. The routine uses will then be
Management Specialist, Office of DEPARTMENT OF HEALTH AND prioritized and reordered according to
Science, NCEH/ATSDR, 1600 Clifton HUMAN SERVICES their usage. We will also take the
Road, NE., M/S E–28, Atlanta, Georgia opportunity to update any sections of
30333, telephone 404–498–0615. Centers for Medicare & Medicaid the system that were affected by the
The Director, Management Analysis Services recent reorganization or because of the
and Services Office, has been delegated impact of the Medicare Prescription
the authority to sign Federal Register Privacy Act of 1974; Report of a Drug, Improvement, and Modernization
notices pertaining to announcements of Modified or Altered System Act of 2003 (MMA) (Pub. L. 108–173)
meetings and other committee AGENCY: Department of Health and provisions and to update language in
management activities for both CDC and Human Services (HHS), Centers for the administrative sections to
NCEH/ATSDR. Medicare & Medicaid Services (CMS). correspond with language used in other
Dated: November 14, 2006. CMS SORs.
ACTION: Notice of a Modified or Altered
Alvin Hall, The primary purpose of the system of
System of Records (SOR). records is to issue and control United
Director, Management Analysis and Services
Office, Centers for Disease Control and SUMMARY: In accordance with the States Government card keys to all CMS
Prevention. requirements of the Privacy Act of 1974, employees and other authorized
[FR Doc. E6–19544 Filed 11–17–06; 8:45 am] we are proposing to modify or alter an individuals who require access into
existing SOR, ‘‘Record of Individuals certain designated or secured areas.
BILLING CODE 4163–18–P
Authorized Entry to the Health Care Information retrieved from this system
Financing Administration (HCFA) of records will also be disclosed to: (1)
DEPARTMENT OF HEALTH AND Building via a Card Key Access System Support regulatory, reimbursement, and
HUMAN SERVICES (RICKS), System No. 09–70–3001’’ last policy functions performed within the
modified 66 FR 15264 (March 16, 2001). agency or by a contractor, consultant or
Centers for Disease Control and The name of the Agency has been grantee; (2) assist another Federal
Prevention changed from HCFA to the Centers for agency to conduct activities related to
Medicare & Medicaid Services (CMS). this system; and (3) support litigation
Public Health Security and We will modify the system name to involving the agency. We have provided
Bioterrorism Preparedness and read: ‘‘Record of Individuals Authorized background information about the
Response Act Delegation of Authority Entry to the CMS Building via a Card modified system in the SUPPLEMENTARY
Key Access System (RICKS).’’ We INFORMATION section below. Although
Notice is hereby given that I have
delegated to the Director, Centers for propose to assign a new CMS the Privacy Act requires only that CMS
Disease Control and Prevention (CDC), identification number to this system to provide an opportunity for interested
with authority to redelegate, the simplify the obsolete and confusing persons to comment on the routine uses,
following authorities vested in the numbering system originally designed CMS invites comments on all portions
Secretary of Health and Human to identify the Bureau, Office, or Center of this notice. See ‘‘Effective Dates’’
Services, under Title III of the Public that maintained information in the section for comment period.
Health Service (PHS) Act and the Public HCFA systems of records. The new DATES: Effective Dates: CMS filed a
Health Security and Bioterrorism assigned identifying number for this modified or altered system report with
Preparedness and Response (PHSBPR) system should read: System No. 09–70– the Chair of the House Committee on
Act of 2002 (Pub. L. 107–188) as 0518. Government Reform and Oversight, the
amended hereafter, insofar as these We propose to modify existing routine Chair of the Senate Committee on
authorities pertain to the functions use number 1 that permits disclosure to Homeland Security & Governmental
assigned to the CDC: agency contractors and consultants to Affairs, and the Administrator, Office of
• PHS Act, Title III, Section 351A (42 include disclosure to CMS grantees who Information and Regulatory Affairs,
U.S.C. 262a), excluding sections (i), perform a task for the agency. CMS Office of Management and Budget
(g)(3) and (g)(4) as provided in § 201 of grantees, charged with completing (OMB) on November 13, 2006. To
the Act; and projects or activities that require CMS ensure that all parties have adequate
• PHSBPR Act, Title II, Subtitle C, data to carry out that activity, are time in which to comment, the modified
Section 221 (7 U.S.C. 8411). classified separate from CMS system, including routine uses, will
This delegation excludes the authority contractors and/or consultants. The become effective 30 days from the
to submit reports to the Congress, but modified routine use will remain as publication of the notice, or 40 days
should be exercised under the routine use number 1. We will delete from the date it was submitted to OMB
Department’s existing delegation of routine use number 3 authorizing and Congress, whichever is later, unless
authority and policy on regulations. disclosure to support constituent CMS receives comments that require
This delegation is effective upon requests made to a congressional alterations to this notice.
signature. In addition, I hereby affirm representative. If an authorization for ADDRESSES: The public should address
sroberts on PROD1PC70 with NOTICES

and ratify any actions taken by you or the disclosure has been obtained from comments to: CMS Privacy Officer,
your subordinates which involved the the data subject, then no routine use is Division of Privacy Compliance,
exercise of the authorities delegated needed. The Privacy Act allows for Enterprise Architecture and Strategy
herein prior to the effective day of the disclosures with the ‘‘prior written Group, Office of Information Services,
delegation. consent’’ of the data subject. CMS, Room N2–04–27, 7500 Security

VerDate Aug<31>2005 17:10 Nov 17, 2006 Jkt 211001 PO 00000 Frm 00038 Fmt 4703 Sfmt 4703 E:\FR\FM\20NON1.SGM 20NON1
Federal Register / Vol. 71, No. 223 / Monday, November 20, 2006 / Notices 67131

Boulevard, Baltimore, MD 21244–1850. purpose of RICKS. CMS has the accomplishing CMS function relating to
Comments received will be available for following policies and procedures purposes for this system.
review at this location, by appointment, concerning disclosures of information CMS occasionally contracts out
during regular business hours, Monday that will be maintained in the system. certain of its functions when doing so
through Friday from 9 a.m.–3 p.m., Disclosure of information from this would contribute to effective and
eastern time zone. system will be approved only to the efficient operations. CMS must be able
FOR FURTHER INFORMATION CONTACT: extent necessary to accomplish the to give a contractor, consultant or
Marcia Levin, Security System purpose of the disclosure and only after grantee whatever information is
Administrator, Emergency Resources CMS: necessary for the contractor or
Management and Response Group, 1. Determines that the use or consultant to fulfill its duties. In these
Office of Operations Management, CMS, disclosure is consistent with the reason situations, safeguards are provided in
Room SLL–11–08, CMS, 7500 Security that the data is being collected, e.g., to the contract prohibiting the contractor,
Boulevard, Baltimore, MD 21244–1850. collect and maintain information to consultant or grantee from using or
Ms. Levin can be reached by telephone issue and control United States disclosing the information for any
at 410–786–7840, or via e-mail at Government card keys to all CMS purpose other than that described in the
Marcia.Levin@cms.hhs.gov. employees and other authorized contract and requires the contractor,
individuals. consultant or grantee to return or
SUPPLEMENTARY INFORMATION:
2. Determines: destroy all information at the
I. Description of the Modified or a. That the purpose for which the completion of the contract.
Altered System of Records disclosure is to be made can only be 2. To assist another Federal agency to
accomplished if the record is provided conduct activities related to this system
A. Statutory and Regulatory Basis for
in individually identifiable form; of records and who need to have access
System b. That the purpose for which the to the records in order to perform the
The authority for this system is given disclosure is to be made is of sufficient activity.
under the provisions of 5 United States importance to warrant the potential We contemplate disclosing
Code (U.S.C.) 301, 40 U.S.C. 121, 41 effect and/or risk on the privacy of the information under this routine use only
Code of Federal Regulations (CFR) Part individual that additional exposure of in situations in which CMS may enter
102–74, Subpart C (Conduct on Federal the record might bring; and into a contractual or similar agreement
Property), 5 U.S.C. 552a(e)(10), and c. That there is a strong probability with another Federal agency to assist in
Office of Management and Budget that the proposed use of the data would accomplishing CMS functions relating
Circular A–123, ‘‘Internal Control in fact accomplish the stated purpose(s). to purposes for this system of records.
Systems.’’ 3. Requires the information recipient The Federal Protection Service may
to: require RICKS information if
B. Collection and Maintenance of Data a. Establish administrative, technical,
in the System investigating a crime and/or in the
and physical safeguards to prevent administration of its assigned
The system collects and maintains unauthorized use of disclosure of the responsibilities.
information on Federal employees, record; and 3. To support the Department of
contractors and consultants, b. Remove or destroy at the earliest Justice (DOJ), court or adjudicatory body
Government Services Administration time all patient-identifiable information. when:
(GSA) employees, and contract guards 4. Determines that the data are valid a. The agency or any component
working in the central office complex in and reliable. thereof, or
Baltimore. The information maintained b. Any employee of the agency in his
III. Proposed Routine Use Disclosures
contains the individual’s name, or her official capacity, or
of Data in the System
assigned card key number, demographic c. Any employee of the agency in his
and geographic information, and the A. The Privacy Act allows us to or her individual capacity where the
building/secure area location. The disclose information without an DOJ has agreed to represent the
system also contains the date and time individual’s consent if the information employee, or
of actual or attempted entry to secured is to be used for a purpose that is d. The United States Government is a
areas. compatible with the purpose(s) for party to litigation or has an interest in
which the information was collected. such litigation, and by careful review,
II. Agency Policies, Procedures, and Any such compatible use of data is CMS determines that the records are
Restrictions on the Routine Use known as a ‘‘routine use.’’ The proposed both relevant and necessary to the
A. The Privacy Act permits us to routine uses in this system meet the litigation and that the use of such
disclose information without an compatibility requirement of the Privacy records by the DOJ, court or
individual’s consent if the information Act. We are proposing to establish the adjudicatory body is compatible with
is to be used for a purpose that is following routine use disclosures of the purpose for which the agency
compatible with the purpose(s) for information maintained in the system: collected the records.
which the information was collected. 1. To support agency contractors, Whenever CMS is involved in
Any such disclosure of data is known as consultants, or grantees, who have been litigation, and occasionally when
a ‘‘routine use.’’ The government will engaged by the agency to assist in the another party is involved in litigation
only release RICKS information that can performance of a service related to this and CMS’ policies or operations could
be associated with an individual as collection and who need to have access be affected by the outcome of the
provided for under ‘‘Section III. to the records in order to perform the litigation, CMS would be able to
Proposed Routine Use Disclosures of activity. disclose information to the DOJ, court or
sroberts on PROD1PC70 with NOTICES

Data in the System.’’ Both identifiable We contemplate disclosing adjudicatory body involved.
and non-identifiable data may be information under this routine use only
disclosed under a routine use. in situations in which CMS may enter IV. Safeguards
We will only collect the minimum into a contractual or similar agreement CMS has safeguards in place for
personal data necessary to achieve the with a third party to assist in authorized users and monitors such

VerDate Aug<31>2005 17:10 Nov 17, 2006 Jkt 211001 PO 00000 Frm 00039 Fmt 4703 Sfmt 4703 E:\FR\FM\20NON1.SGM 20NON1
67132 Federal Register / Vol. 71, No. 223 / Monday, November 20, 2006 / Notices

users to ensure against unauthorized anticipate an unfavorable effect on agency or by a contractor, consultant or
use. Personnel having access to the individual privacy as a result of grantee; (2) assist another Federal
system have been trained in the Privacy information relating to individuals. agency to conduct activities related to
Act and information security Dated: November 8, 2006. this system; and (3) support litigation
requirements. Employees who maintain John R. Dyer,
involving the agency.
records in this system are instructed not
Chief Operating Officer, Centers for Medicare ROUTINE USES OF RECORDS MAINTAINED IN THE
to release data until the intended
& Medicaid Services. SYSTEM, INCLUDING CATEGORIES OF USERS AND
recipient agrees to implement THE PURPOSES OF SUCH USES:
appropriate management, operational SYSTEM NO. 09–70–0518
A. The Privacy Act allows us to
and technical safeguards sufficient to
SYSTEM NAME: disclose information without an
protect the confidentiality, integrity and
‘‘Record of Individuals Authorized individual’s consent if the information
availability of the information and
information systems and to prevent Entry to CMS Building via a Card Key is to be used for a purpose that is
unauthorized access. Access System (RICKS), HHS/CMS/ compatible with the purpose(s) for
This system will conform to all OOM’’. which the information was collected.
applicable Federal laws and regulations Any such compatible use of data is
SECURITY CLASSIFICATION: known as a ‘‘routine use.’’
and Federal, HHS, and CMS policies
and standards as they relate to Level Three Privacy Act Sensitive The proposed routine uses in this
information security and data privacy. Data. system meet the compatibility
These laws and regulations may apply requirement of the Privacy Act. We are
SYSTEM LOCATION: proposing to establish the following
but are not limited to: the Privacy Act
The Centers for Medicare & Medicaid routine use disclosures of information
of 1974; the Federal Information
Services (CMS) Data Center, 7500 maintained in the system:
Security Management Act of 2002; the
Computer Fraud and Abuse Act of 1986; Security Boulevard, North Building, 1. To support agency contractors,
the Health Insurance Portability and First Floor, Baltimore, Maryland 21244– consultants, or grantees, who have been
Accountability Act of 1996; 1850 and South Building, Baltimore, engaged by the agency to assist in the
the E-Government Act of 2002, the Maryland 21244–1850. performance of a service related to this
Clinger-Cohen Act of 1996; the collection and who need to have access
CATEGORIES OF INDIVIDUALS COVERED BY THE
Medicare Modernization Act of 2003, to the records in order to perform the
SYSTEM:
and the corresponding implementing activity.
The system collects and maintains 2. To assist another Federal agency to
regulations. OMB Circular A–130, information on Federal employees,
Management of Federal Resources, conduct activities related to this system
contractors and consultants, of records and who need to have access
Appendix III, Security of Federal Government Services Administration
Automated Information Resources also to the records in order to perform the
(GSA) employees, and contract guards activity.
applies. Federal, HHS, and CMS working in the central office complex in 3. To support the Department of
policies and standards include but are Baltimore. Justice (DOJ), court or adjudicatory body
not limited to: All pertinent National
Institute of Standards and Technology CATEGORIES OF RECORDS IN THE SYSTEM:
when:
a. The agency or any component
publications; the HHS Information The information maintained contains thereof, or
Systems Program Handbook and the the individual’s name, assigned card b. Any employee of the agency in his
CMS Information Security Handbook. key number, demographic and or her official capacity, or
V. Effects of the Modified or Altered geographic information, and the c. Any employee of the agency in his
System of Records on Individual Rights building/secure area location. The or her individual capacity where the
system also contains the date and time DOJ has agreed to represent the
CMS proposes to modify this system of actual or attempted entry to secured
in accordance with the principles and employee, or
areas. d. The United States Government is a
requirements of the Privacy Act and will
party to litigation or has an interest in
collect, use, and disseminate AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
such litigation, and by careful review,
information only as prescribed therein. The authority for this system is given CMS determines that the records are
Data in this system will be subject to the under the provisions of 5 United States both relevant and necessary to the
authorized releases in accordance with Code (U.S.C.) 301, 40 U.S.C. 121, 41 litigation and that the use of such
the routine uses identified in this Code of Federal Regulations (CFR) Part records by the DOJ, court or
system of records. 102–74, Subpart C (Conduct on Federal
CMS will take precautionary adjudicatory body is compatible with
Property), 5 U.S.C. 552a(e)(10), and the purpose for which the agency
measures (see item IV above) to Office of Management and Budget
minimize the risks of unauthorized collected the records.
Circular A–123, ‘‘Internal Control
access to the records and the potential Systems.’’ POLICIES AND PRACTICES FOR STORING,
harm to individual privacy or other RETRIEVING, ACCESSING, RETAINING, AND
personal or property rights of patients PURPOSE(S) OF THE SYSTEM: DISPOSING OF RECORDS IN THE SYSTEM:
whose data are maintained in the The primary purpose of the system of STORAGE:
system. CMS will collect only that records is to issue and control United All records are stored on paper and
information necessary to perform the States Government card keys to all CMS magnetic disk.
system’s functions. In addition, CMS employees and other authorized
will make disclosure from the proposed individuals who require access into RETRIEVABILITY:
sroberts on PROD1PC70 with NOTICES

system only with consent of the subject certain designated or secured areas. Magnetic media records are retrieved
individual, or his/her legal Information retrieved from this system by the name of the employees or other
representative, or in accordance with an of records will also be disclosed to: (1) authorized individual and/or card key
applicable exception provision of the Support regulatory, reimbursement, and number. Paper records are retrieved
Privacy Act. CMS, therefore, does not policy functions performed within the alphabetically by name.

VerDate Aug<31>2005 17:10 Nov 17, 2006 Jkt 211001 PO 00000 Frm 00040 Fmt 4703 Sfmt 4703 E:\FR\FM\20NON1.SGM 20NON1
Federal Register / Vol. 71, No. 223 / Monday, November 20, 2006 / Notices 67133

SAFEGUARDS: Furnishing the SSN is voluntary, but it We propose to modify existing routine
CMS has safeguards in place for may make searching for a record easier use number 2 that permits disclosure to
authorized users and monitors such and prevent delay. agency contractors and consultants to
users to ensure against unauthorized include disclosure to CMS grantees who
RECORD ACCESS PROCEDURE:
use. Personnel having access to the perform a task for the agency. CMS
system have been trained in the Privacy For purpose of access, use the same grantees, charged with completing
Act and information security procedures outlined in Notification projects or activities that require CMS
requirements. Employees who maintain Procedures above. Requestors should data to carry out that activity, are
records in this system are instructed not also specify the record contents being classified separately from CMS
to release data until the intended sought. (These procedures are in contractors and/or consultants. The
recipient agrees to implement accordance with department regulation modified routine use will be
appropriate management, operational 45 CFR 5b.5(a)(2).) renumbered as routine use number 1.
and technical safeguards sufficient to CONTESTING RECORDS PROCEDURES:
We will delete routine use number 3
protect the confidentiality, integrity and authorizing disclosure to support
The subject individual should contact constituent requests made to a
availability of the information and the system manager named above, and
information systems and to prevent congressional representative. If an
reasonably identify the records and authorization for the disclosure has
unauthorized access. specify the information to be contested.
This system will conform to all been obtained from the data subject,
State the corrective action sought and then no routine use is needed. The
applicable Federal laws and regulations
the reasons for the correction with Privacy Act allows for disclosures with
and Federal, HHS, and CMS policies
supporting justification. (These the ‘‘prior written consent’’ of the data
and standards as they relate to
Procedures are in accordance with subject.
information security and data privacy.
Department regulation 45 CFR 5b.7.) We propose to broaden the scope of
These laws and regulations may apply
but are not limited to: The Privacy Act RECORDS SOURCE CATEGORIES:
the disclosure provisions of this system
of 1974; the Federal Information by adding a routine use to permit the
The data contained in this system of release of information to another
Security Management Act of 2002; the records are obtained from the
Computer Fraud and Abuse Act of 1986; Federal or state agency to contribute to
individuals who submit a request for the accuracy of CMS’ proper payment of
the Health Insurance Portability and access to a secure building or area.
Accountability Act of 1996; the E- Medicare benefits, to enable such
Government Act of 2002, the Clinger- SYSTEMS EXEMPTED FROM CERTAIN PROVISIONS agency to administer a Federal health
Cohen Act of 1996; the Medicare OF THE ACT: benefits program, and/or as necessary to
Modernization Act of 2003, and the None. enable such agency to fulfill a
corresponding implementing requirement of a Federal statute or
[FR Doc. E6–19503 Filed 11–17–06; 8:45 am] regulation that implements a health
regulations. OMB Circular A–130, BILLING CODE 4120–03–P
Management of Federal Resources, benefits program funded in whole or in
Appendix III, Security of Federal part with Federal funds, to evaluate and
Automated Information Resources also to monitor the amount and kinds of
DEPARTMENT OF HEALTH AND services received by Medicare
applies. Federal, HHS, and CMS HUMAN SERVICES beneficiaries contracting cancer. The
policies and standards include but are
Centers for Medicare & Medicaid added routine use will be numbered as
not limited to: All pertinent National
Services routine use number 2.
Institute of Standards and Technology We will further broaden the scope of
publications; the HHS Information this system by including the section
Systems Program Handbook and the Privacy Act of 1974; Report of a
Modified or Altered System titled ‘‘Additional Circumstances
CMS Information Security Handbook. Affecting Routine Use Disclosures,’’ that
RETENTION AND DISPOSAL: AGENCY: Department of Health and addresses ‘‘Protected Health Information
Records are retained for up to 3 years Human Services (HHS), Centers for (PHI)’’ and ‘‘small cell size.’’ The
following expiration of an individual’s Medicare & Medicaid Services (CMS). requirement for compliance with HHS
authority to enter secured areas. When ACTION: Notice of a Modified or Altered regulation ‘‘Standards for Privacy of
an individual is no longer authorized, System of Records (SOR). Individually Identifiable Health
information is deleted from magnetic Information’’ applies whenever the
SUMMARY: In accordance with the system collects or maintains PHI. This
media immediately.
requirements of the Privacy Act, we are system may contain PHI. In addition,
SYSTEM MANAGER AND ADDRESS: proposing to modify or alter an existing our policy to prohibit release if there is
Director, Emergency Management and SOR titled, ‘‘Medicare-Cancer Registry a possibility that an individual can be
Response Group, Office of Operations Record System (MCR), System No. 09– identified through ‘‘small cell size’’ will
Management, CMS, Room SLL–11–28, 70–0042,’’ established at 53 FR 38082 apply to the data disclosed from this
7500 Security Boulevard, Baltimore, (September 29, 1988), and most recently system.
Maryland 21244–1850. modified at 65 FR 37792 (June 16, We are modifying the language in the
2000). We propose to assign a new CMS remaining routine uses to provide a
NOTIFICATION PROCEDURE: identification number to this system to proper explanation as to the need for the
For purpose of access, the subject simplify the obsolete and confusing routine use and to provide clarity to
individual should write to the system numbering system originally designed CMS’s intention to disclose individual-
manager who will require the system to identify the Bureau, Office, or Center specific information contained in this
sroberts on PROD1PC70 with NOTICES

name, assigned card key number, and that maintained information in the system. The routine uses will then be
building/secure area, and for Health Care Financing Administration prioritized and reordered according to
verification purposes, the subject systems of records. The new assigned their usage. We will also take the
individual’s name (woman’s maiden identifying number for this system opportunity to update any sections of
name, if applicable), and SSN. should read: System No. 09–70–0509. the system that were affected by the

VerDate Aug<31>2005 17:10 Nov 17, 2006 Jkt 211001 PO 00000 Frm 00041 Fmt 4703 Sfmt 4703 E:\FR\FM\20NON1.SGM 20NON1

Vous aimerez peut-être aussi