Bindinglaw

US · guidance

CMS SOM App. H, Tag V727

§ 494.170(a) Standard: Protection of the patient’s record

activein force · 2026-07-22 – presentas-observed

The dialysis facility must—

(1) Safeguard patient records against loss, destruction, or unauthorized use; and

(2) Keep confidential all information contained in the patient’s record, except when release

is authorized pursuant to one of the following:

(i) The transfer of the patient to another facility.

(ii) Certain exceptions provided for in the law.

(iii) Provisions allowed under third party payment contracts.

(iv) Approval by the patient.

(v) Inspection by authorized agents of the Secretary, as required for the administration of

the dialysis program.

Interpretive Guidance § 494.170 (a)(1) and (2)(i)-(v)

The medical record system must protect the privacy and security of all patients’ medical record

information. The medical records system must ensure that records are not lost, stolen, destroyed,

altered, or reproduced in an unauthorized manner. All locations where medical records are

stored or maintained must ensure the integrity, security, controlled accessibility and protection

of the records.

Electronic medical records systems must be designed to prevent accidental loss or destruction of

medical record information (e.g., have an automated backup system), and should have

safeguards to prevent alteration of entries without notation of the alteration (e.g., a late entry

should be indicated as such). Facility personnel should have sufficient knowledge of electronic

system functions to ensure their ability to safeguard records on that system in the event of a

Page 277 of 420

problem, including backup of electronic medical records and restoring data. Staff members

should be aware of the facility’s plan to ensure uninterrupted maintenance of the patient’s

medical record in the event of a computer failure. Staff members should be able to provide a

printed copy of requested portions or the complete current medical record without significant

delay (e.g., less than one hour for a portion of the record, less than four hours for the complete

current record).

The accumulation of records for a patient treated several times a week for years can become

voluminous. The current working chart may contain recent treatment records, and a year of

patient assessments, plans of care, progress notes, orders, lab reports, etc. Older records of

current patients may be stored in a convenient and secure location where they can be readily

accessed as needed. Electronic storage of records is permissible if a secure means to protect the

integrity of the record and the privacy of the patient is provided.

The facility policy for stored medical records should ensure prompt retrieval. Facility policy

should address how staff members access records that are stored offsite, and the expected time to

retrieve them.

In the event of loss of medical records due to unavoidable circumstances, (i.e., natural or man-made disaster) there should be evidence in the QAPI documentation of the event of what records

were lost/destroyed, and what steps were taken to prevent similar losses in the future. The

facility must have a plan for protecting medical records in an emergency (e.g. transport, secure

in place, redundant backup, continuous automatic off-site backup), and for minimizing loss.

Facility policy and practices must reflect the requirements of the Health Insurance Portability

and Accountability Act of 1996 (HIPAA) requirements for paper and electronic medical records.

HIPAA allows release of protected health information (PHI) in certain emergency

circumstances, and for the continuity of health care. Also refer to the Condition for patients’

rights at V455.

Facility policy should address release of a patient’s protected health information to third parties.

History

Rev.

Provenance

Source
cms.gov
Retrieved
2026-07-22
Edition
som-2026-07-22
Content hash
9f05c2469191441530f23a1b82bfb81c8b668f451455169a8e7f75eb621ac18c
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS SOM App. H, Tag V727 — § 494.170(a) Standard: Pro… · binding.law