US · guidance
CMS Pub. 100-04, ch. 24, § 40.2.2.1
A/B MACs, DME MACs, and CEDI Data Security and
Confidentiality Requirements
(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)
All Medicare beneficiary-specific information is confidential and subject to the
requirements of §1106(a) of the Act and implementing regulations at
http://www.gpo.gov/fdsys/browse/collectionCfr.action?collectionCode=CFR. Those
regulations specify that, as a general rule, every proposed disclosure of Medicare
information shall be subject to the Freedom of Information Act rules at 45 CFR Part 5.
Also all such information, to the extent that it is maintained in a “system of records,” is
protected under the provisions of the Privacy Act of 1974 (5 USC. 552a) and
implementing regulations at
http://www.gpo.gov/fdsys/browse/collectionCfr.action?collectionCode=CFR. Such
information is included in claims, remittance advice, eligibility information, online
claims corrections, and any other transactions where personal information applicable to a
beneficiary is processed or transported. Such information may not be disclosed to anyone
other than the provider or supplier that submitted a claim or to the beneficiary for whom a
claim was filed. A/B, MACs, DME MACs and CEDI must ensure the security of all EDI
transactions and data. See the CMS Business Partners System Security Manual and its
Core Security Requirements attachment for more detailed information on system security
requirements.
A/B, MACs, DME MACs and CEDI systems must include the following system security
capabilities:
• All data must be password protected and passwords modified at periodic but irregular
intervals, as well as when an individual having knowledge of the password changes
positions, and when a security breach is suspected or identified;
• Provide mechanisms to detect unauthorized users and prohibit access to anyone who
does not have an appropriate user ID and password;
• Maintain a record of operator-attempted system access violations;
• Maintain a multi-level system/user authorization to limit access to system functions,
files, databases, tables, and parameters from external and internal sources;
• Maintain updates of user controlled files, databases, tables, parameters, and retain a
history of update activity; and
• Protect data ownership and integrity from the detailed transaction level to the
summary file level.
History
(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
d8232e659a3086195f5c178fc48f3293accc15ce236a03d23a1cbabc77539a8e
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.