Bindinglaw

US · guidance

CMS Pub. 100-04, ch. 24, § 40.2.2.1

A/B MACs, DME MACs, and CEDI Data Security and

activein force · 2026-08-25 – presentas-observed

Confidentiality Requirements

(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)

All Medicare beneficiary-specific information is confidential and subject to the

requirements of §1106(a) of the Act and implementing regulations at

http://www.gpo.gov/fdsys/browse/collectionCfr.action?collectionCode=CFR. Those

regulations specify that, as a general rule, every proposed disclosure of Medicare

information shall be subject to the Freedom of Information Act rules at 45 CFR Part 5.

Also all such information, to the extent that it is maintained in a “system of records,” is

protected under the provisions of the Privacy Act of 1974 (5 USC. 552a) and

implementing regulations at

http://www.gpo.gov/fdsys/browse/collectionCfr.action?collectionCode=CFR. Such

information is included in claims, remittance advice, eligibility information, online

claims corrections, and any other transactions where personal information applicable to a

beneficiary is processed or transported. Such information may not be disclosed to anyone

other than the provider or supplier that submitted a claim or to the beneficiary for whom a

claim was filed. A/B, MACs, DME MACs and CEDI must ensure the security of all EDI

transactions and data. See the CMS Business Partners System Security Manual and its

Core Security Requirements attachment for more detailed information on system security

requirements.

A/B, MACs, DME MACs and CEDI systems must include the following system security

capabilities:

• All data must be password protected and passwords modified at periodic but irregular

intervals, as well as when an individual having knowledge of the password changes

positions, and when a security breach is suspected or identified;

• Provide mechanisms to detect unauthorized users and prohibit access to anyone who

does not have an appropriate user ID and password;

• Maintain a record of operator-attempted system access violations;

• Maintain a multi-level system/user authorization to limit access to system functions,

files, databases, tables, and parameters from external and internal sources;

• Maintain updates of user controlled files, databases, tables, parameters, and retain a

history of update activity; and

• Protect data ownership and integrity from the detailed transaction level to the

summary file level.

History

(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
d8232e659a3086195f5c178fc48f3293accc15ce236a03d23a1cbabc77539a8e
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.