Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 4.2

Encryption Requirements for Data Leaving Data Centers

activein force · 2026-08-25 – presentas-observed

(Rev. 15)

CMS, as a trusted custodian of individual health care data, must protect its most valuable assets—

its information and its information systems. Consequently, CMS believes that putting the

government’s credibility at risk is not acceptable.

No data that includes personally identifiable information (PII) shall be transported from a CMS data

center (including business partner data centers and subcontractor data centers) unless it has been

encrypted in accordance with CMS standards. The only exception to this requirement is for

hardcopy records that are transported to and from an off-site location and between off-site

locations. To qualify for this exception, the controls listed below (additional information is

available from CMS) shall be used.

To prepare the records for shipment:

• The records shall be stored in boxes.

• Each box shall be uniquely identified.

• Boxes shall be secured for shipment.

• Secured boxes shall be loaded into the shipping container or vehicle.

• Total items in each shipment shall be noted and the Bill of Lading signed.

• At time of pickup, the shipping company representative shall verify and sign the Bill of

Lading.

• A copy of the identification records shall accompany each shipment.

• The shipping container or vehicle shall be locked and sealed with the seal number noted on

the Bill of Lading.

• A copy of the completed Bill of Lading shall be kept by the contractor.

Upon receipt of the shipment at the storage facility:

• A storage facility representative shall verify the seal number and that it is unbroken.

• Compare the contents of the shipment against the Bill of Lading and the boxes against the

copy of the identification record.

• If any discrepancies are found, the discrepancy shall be immediately resolved.

• After verification that all boxes shipped were received, information from the Bill of Lading

shall be sent to the shipper where it shall be verified.

• Within 24 hours, all boxes on each shipment shall be scanned into the storage facility’s

tracking system and inserted into the storage racks.

History

(Rev. 15)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
a230e916be013336e6a8b1a790d784e8120b7576477e22a8cf0a1be55e3575d4
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.