Transcription of CMS Information Systems Security and Privacy Policy
{{id}} {{{paragraph}}}
Centers for Medicare & Medicaid Services Information Security and Privacy Group CMS Information Systems Security and Privacy Policy Final Version Document Number: CMS-CIO-POL-SEC-2019-0001 May 21, 2019 Final Centers for Medicare & Medicaid Serv ices CMS Information Sy stems Security and Priv acy Policy Document Number: CMS-CIO-POL-SEC-2019-0001 i May 17, 2019 Record of Changes This Policy supersedes the CMS Information Systems Security and Privacy Policy v , April 26, 2016. This Policy consolidates existing laws, regulations, and other drivers of Information Security and Privacy into a single volume and directly integrates the enforcement of Information Security and Privacy through the CMS Chief Information Officer, Chief Information Security Officer, and Senior Official for Privacy . Version Date Author/Owner Description of Change CR # 3/15/2016 FGS MITRE Initial Publication 05/17/2019 ISPG Edits addressing the HIPAA Privacy Rule, some Roles and Responsibilities, Role-Based Training/NICE, High Value Assets, and references, CR: Change Request Final Centers for Medicare & Medicaid Serv ices CMS Information Sy stems Security and Priv acy Policy Document Number: CMS-CIO-POL-SEC-201
agreement in place. Any contract, agreement, or other arrangement that collects, creates, uses, discloses, or maintains sensitive information, including but not limited to Personally Identifiable Information (PII) and Protected Health Information (PHI), must comply with this Policy. In
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}