Form Cms-R-0235d1 - Dsh Data Use Agreement For Cost Reporting Periods Prior To Those That Include December 8, 2004 Page 4

ADVERTISEMENT

7. User agrees to establish appropriate administrative, technical, and physical safeguards to protect the
confidentiality of the data and to prevent unauthorized use or access to it. The safeguards shall provide a
level and scope of security that is not less than the level and scope of security established by the Office
of Management and Budget (OMB) in OMB Circular No. A-130, Appendix III—Security of Federal
Automated Information Systems ( ), which sets
forth guidelines for security plans for automated information systems in Federal agencies. User acknowledges
that the use of unsecured telecommunications, including the Internet, to transmit individually identifiable
or deducible information derived from the file(s) specified in paragraph 5 is prohibited. Further, User
agrees that the data must not be physically moved or transmitted in any way from the site(s) indicated in
paragraph 16, except as provided in paragraph 4, without written approval from CMS.
8. User agrees that the authorized representatives of CMS or DHHS Office of the Inspector General will
be granted access to premises where the aforesaid file(s) are kept for the purpose of inspecting security
arrangements confirming whether the User is in compliance with the security requirements specified in
paragraph 7.
9. The User agrees not to disclose direct findings, listings, or information derived from the file(s)
specified in section 5, with or without direct identifiers, if such findings, listings, or information can, by
themselves or in combination with other data, be used to deduce an individual’s identity. Examples of
such data elements include, but are not limited to geographic location, age if > 89, sex, diagnosis and
procedure, admission/discharge date(s), or date of death.
The User agrees that any use of CMS data in the creation of any document (manuscript, table, chart,
study, report, etc.) concerning the purpose specified in section 4 (regardless of whether the report or other
writing expressly refers to such purpose, to CMS, or to the files specified in section 5 or any data derived
from such files) must adhere to CMS’ current cell size suppression policy. This policy stipulates that no
cell (eg. admittances, discharges, patients) less than 11 may be displayed. Also, no use of percentages or
other mathematical formulas may be used if they result in the display of a cell less than 11. By signing this
Agreement you hereby agree to abide by these rules and, therefore, will not be required to submit any written
documents for CMS review. If you are unsure if you meet the above criteria, you may submit your written
products for CMS review. CMS agrees to make a determination about approval and to notify the user within
4 to 6 weeks after receipt of findings. CMS may withhold approval for publication only if it determines that
the format in which data are presented may result in identification of individual beneficiaries.
10. User understands and agrees that it may not reuse original or derivative data file(s) without prior written
approval from the appropriate System Manager or the person designated in paragraph 17 of this Agreement.
11. The parties mutually agree that the following specified Attachments are part of this Agreement:
NO ATTACHMENTS
12. User agrees that in the event CMS determines or has a reasonable belief that User has made or may have
made disclosure of the aforesaid file(s) that is not authorized by this Agreement or other written authorization
from the appropriate System Manager or the person designated in paragraph 17 of this Agreement, CMS
in its sole discretion may require User to: (a) promptly investigate and report to CMS User’s determinations
regarding any alleged or actual unauthorized disclosure, (b) promptly resolve any problems identified by
the investigation; (c) if requested by CMS, submit a formal response to an allegation of unauthorized
disclosure; (d) if requested by CMS, submit a corrective action plan with steps designed to prevent any
future unauthorized disclosures; and (e) if requested by CMS, return data files to CMS. User understands
that as a result of CMS’s determination or reasonable belief that unauthorized disclosures have taken
place, CMS may refuse to release further CMS data to User for a period of time to be determined by CMS.
Form CMS-R-0235D1 (12/09)
4

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Medical
Go
Page of 6