Skip to Main Content

Print | Bookmark | Email | Font Size: + |

January 15, 2014

Submission of Requested Documentation

When submitting documentation based on a request from any CMS-contracted entity (CGS, Comprehensive Error Rate Testing (CERT) contractor, Recovery Audit Contractor (RAC), or Zone Program Integrity Contractor (ZPIC)), please review prior to sending to ensure you are only sending the requested information.

The CERT contractor continues to receive documentation that contains more than one set of patient records included with their requests.

Reminder of HIPAA Requirements

MINIMUM NECESSARY
[45 CFR 164.502(b), 164.514(d)]

The minimum necessary standard, a key protection of the HIPAA Privacy Rule, is derived from confidentiality codes and practices in common use today. It is based on sound current practice that protected health information should not be used or disclosed when it is not necessary to satisfy a particular purpose or carry out a function. The minimum necessary standard requires covered entities to evaluate their practices and enhance safeguards as needed to limit unnecessary or inappropriate access to and disclosure of protected health information. The Privacy Rule's requirements for minimum necessary are designed to be sufficiently flexible to accommodate the various circumstances of any covered entity. HIPAA requires covered entities to take reasonable steps to limit the use or disclosure of, and requests for, protected health information to the minimum necessary to accomplish the intended purpose.

Frequently Asked Questions (FAQs) from Health & Human Services (HHS):

spacer

26 Century Blvd Ste ST610, Nashville, TN 37214-3685 © CGS Administrators, LLC. All Rights Reserved