US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.15
Data Loss Prevention
(Rev. 15)
Data protection for a Business Partner’s environment is critical in ensuring the privacy and integrity
of their information. Business Partners must have a comprehensive Data Loss Prevention (DLP)
solution in place to provide comfort that data is not being exfiltrated from their environment. The
DLP solution should also provide assurance that if unauthorized data exfiltration is identified, it is
blocked, and the effects are mitigated. The implemented DLP solution must cover data in use
(endpoints), data in transit (network), and data at rest (data storage). Several tools implemented for
other MAC ARS controls, such as Malicious Code Protection (endpoints), Intrusion Detection
System/Intrusion Protection System (network) and encryption (data storage) can be combined to
form a DLP solution. Business partners shall maintain documentation to support the DLP solution
including formally maintained policies and procedures for the tools, controls, and processes.
History
(Rev. 15)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
5db868cc7179c9581adca3e997a319ed8d8d976d45486b631add514fcaed06e2
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.