Bindinglaw

US · guidance

CMS Pub. 100-10, ch. 8, § 8020

Security Handbook

activein force · 2026-08-25 – presentas-observed

The System Security Policy establishes a security management process for QIO users

that complies with the Computer Security Act of 1987 (P.L. 100-235), the Health

Insurance Portability and Accountability Act of 1996 (P.L. 104-191), Appendix III to the

Office of Management and Budget (OMB), Circular No. A-130 (50 FR 52730; December

24, 1985), Federal Information Security Management Act (FISMA), Title III of the E-

Government Act of 2002 (Public Law 107-347, 44 U.S.C. Chapter 36), the Department of

Health and Human Services and CMS information security policy, programmatic

direction, standards, guidelines, and handbooks. Use of the CMS-furnished IT

infrastructure environment as well as access to and use of QIO Program data is subject

to CMS information security and privacy policy and program oversight provided by the

CMS Office of the Chief Information Office and the Chief Information Security Officer.

All personnel working within the CMS-furnished IT infrastructure and data environment

must abide by the policies and procedures set forth in the Security Policy, read the

Statement of Acceptance, and sign the Policy Acceptance Log attesting to the acceptance

of these policies once a year.

The Security Policy provides guidelines pertaining to the appropriate use of the Internet

and email resources for transmission of QIO Program data. The System Security Policy is

available for download on the main page of the QIO Program Internet site (secure log in

is not required).

History

(Rev. 22, Issued: 12-02-15, Effective: 12-02-15, Implementation: 12-02-15)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
1b5c22000193ae423dd24b4c65f7439fc5a6e406ed89b1e4b6cd246f31e1803d
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.