CMS proposal requires HIXs to report breaches within one hour
The Centers for Medicare & Medicaid Services is proposing an emergency review that requires state health insurance exchanges to report suspected or confirmed incidents affecting loss or suspected loss of protected health information within one hour of discovery. The exchanges would be required to notify their Center for Consumer Information and Insurance Oversight state officer, which in turn would notify affected federal agendy data sources.
“The approval of this data collection process is essential to ensuring that Information Security (IS) incidents, which also include Personally Identifiable Information (PII) and Protected Health Information (PHI), are captured within the specified timeframe,” Martique Jones, deputy director, regulations development group, office of strategies operations and regulatory affairs, wrote in a notice published on Aug. 21 in the Federal Register. “In absence of this change, a significant number of incidents will not be detected; therefore causing harm and potential risk to the public's identity with identity fraud.”
CMS requested that the Office of Management and Budget review and approve this collection by Sept. 25 with a 180-day approval period and is seeking comments on the proposal.
To review the notice and instructions on submitting comments, go here.