US · guidance
CMS Pub. 100-11, ch. 12, § 30
Safeguarding Medical Records
A PACE organization must establish written policies and implement procedures for
safeguarding all data, books, and records against loss, destruction, unauthorized use, or
inappropriate alteration. These policies and procedures must include the following
elements:
• Safeguard the privacy of any information that identifies a particular
participant. Information from, or copies of, records may be released only to
authorized individuals. Original medical records are released only in
accordance with Federal or State laws, court orders, or subpoenas;
• Maintain complete records and relevant information in an accurate and timely
manner;
• Grant each participant timely access, upon request, to review and copy his or
her own medical records and to request amendments to those records; and
• Abide by all Federal and State laws regarding confidentiality and disclosure
for mental health records, medical records, and other participant health
information, including information that qualifies as protected health
information.
Further information is available at
http://www.cms.hhs.gov/HIPAAGenInfo/Downloads/HIPAALaw.pdf.
[42 CFR § 460.200]
History
(Rev. 2, Issued: 06-09-11; Effective: 06-03-11; Implementation: 06-03-11)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
17884bdb3836c261f9fb12f886e44fc3a6d867277234f6129474df0db918dfa3
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.