US · guidance
CMS Pub. 100-10, ch. 8, § 8020
Security Handbook
The System Security Policy establishes a security management process for QIO users
that complies with the Computer Security Act of 1987 (P.L. 100-235), the Health
Insurance Portability and Accountability Act of 1996 (P.L. 104-191), Appendix III to the
Office of Management and Budget (OMB), Circular No. A-130 (50 FR 52730; December
24, 1985), Federal Information Security Management Act (FISMA), Title III of the E-
Government Act of 2002 (Public Law 107-347, 44 U.S.C. Chapter 36), the Department of
Health and Human Services and CMS information security policy, programmatic
direction, standards, guidelines, and handbooks. Use of the CMS-furnished IT
infrastructure environment as well as access to and use of QIO Program data is subject
to CMS information security and privacy policy and program oversight provided by the
CMS Office of the Chief Information Office and the Chief Information Security Officer.
All personnel working within the CMS-furnished IT infrastructure and data environment
must abide by the policies and procedures set forth in the Security Policy, read the
Statement of Acceptance, and sign the Policy Acceptance Log attesting to the acceptance
of these policies once a year.
The Security Policy provides guidelines pertaining to the appropriate use of the Internet
and email resources for transmission of QIO Program data. The System Security Policy is
available for download on the main page of the QIO Program Internet site (secure log in
is not required).
History
(Rev. 22, Issued: 12-02-15, Effective: 12-02-15, Implementation: 12-02-15)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
1b5c22000193ae423dd24b4c65f7439fc5a6e406ed89b1e4b6cd246f31e1803d
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.