decisionhealth Newsletters, Answer Books - 2006 Issue 3 (March)
Program_Memos / 2003 / AB-03-034
Subscribe or sign in to view the full article.
Article Overview
This article explains how CMS and Medicare fee-for-service contractors were expected to align operations with HIPAA privacy requirements in 2003. It is most relevant to Medicare contractors, compliance staff, privacy officers, and health information management professionals who need a high-level view of CMS privacy implementation guidance, related contractor responsibilities, and the categories of beneficiary-request handling addressed in the accompanying questions and answers.
Why This Topic Matters
The memo provides operational context for how Medicare privacy obligations were being interpreted and implemented during the HIPAA Privacy Rule transition period. It helps readers understand the scope of CMS oversight, contractor responsibilities, and the general types of privacy-related issues addressed in the guidance.
Article Sections
-
Program Memorandum
Identifies the transmittal, issuing agencies, date, subject, and general purpose of the memorandum.
-
Privacy Rule Requirements
Summarizes the HIPAA Privacy Rule framework and describes its relevance to Medicare and CMS operations.
-
Business Associates
Addresses contractor status and the broader relationship between Medicare contractors and CMS under privacy requirements.
-
Notice of Privacy Practices
Describes CMS’s beneficiary notice responsibilities and related distribution channels.
-
Authorization
Reviews the general topic of beneficiary authorizations and CMS’s plan to provide standardized materials.
-
Opportunity to Agree/Object
Covers permissible disclosures involving individuals, family members, and routine beneficiary communications.
-
Individual Rights and Complaints
Discusses the types of individual privacy rights and the process for handling complaints and requests.
-
Administrative Requirements
Summarizes broader administrative obligations, including oversight, training, and internal compliance expectations.
-
Compliance Date
States the timing for compliance and the effective/implementation dates associated with the memorandum.
-
Attachment
Introduces the attached question-and-answer material that expands on the memorandum’s privacy implementation topics.
-
Covered Entity
Explains the general categories of CMS programs treated as covered entities for privacy purposes.
-
CMS Privacy Rule Implementation
Describes CMS’s internal planning approach for privacy rule implementation and compliance oversight.
-
Budget
Addresses funding and system-impact questions associated with privacy implementation activities.
-
Access & Amendment
Summarizes beneficiary access and amendment topics and the distinction between different request types.
-
Accounting for Disclosures
Covers disclosure accounting topics and CMS’s handling approach for beneficiary-related inquiries.
-
Right to Restrict/Confidential Communications
Discusses restriction requests and confidential communication considerations within Medicare operations.
-
Complaints
Outlines complaint handling channels and the role of central office in privacy-related complaints.
-
Authorizations
Addresses authorization topics and related beneficiary communication procedures.
-
Administrative Requirements
Further discusses oversight, privacy officers, and training expectations in the Medicare context.
-
Miscellaneous
Covers additional privacy-related topics including the interaction of federal privacy authorities, state law considerations, call center practices, remote monitoring, trading partner agreements, and electronic claims enrollment.
What You Will Learn
- How CMS framed HIPAA Privacy Rule implementation for Medicare fee-for-service contractors.
- Which privacy-related responsibilities were assigned to CMS versus contractors.
- What categories of beneficiary privacy requests and complaints were addressed in the guidance.
- How the memorandum relates to Medicare notices, authorizations, access, amendments, and disclosure handling.
- Which operational privacy topics were included in the attached question-and-answer material.
Who Should Read This
- Medicare fee-for-service contractors
- CMS compliance and operations staff
- Privacy officers
- Health information management professionals
- Medical billing and administrative staff
- Healthcare policy and regulatory readers
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com