[Federal Register Volume 73, Number 218 (Monday, November 10, 2008)]
[Notices]
[Pages 66648-66651]
From the Federal Register Online via the Government Publishing Office [www.gpo.gov]
[FR Doc No: E8-26725]


-----------------------------------------------------------------------

DEPARTMENT OF HEALTH AND HUMAN SERVICES

Office of Inspector General


Privacy Act of 1974; New OIG Privacy Act System of Records: 
Consolidated Data Repository

AGENCY: Office of Inspector General (OIG), HHS.

ACTION: Notice of proposed new Privacy Act System of Records.

-----------------------------------------------------------------------

SUMMARY: The Privacy Act of 1974 (5 U.S.C. 552(e)(4)) requires that all 
agencies publish in the Federal Register a notice of the existence and 
character of their system of records. Notice is hereby given that OIG 
is adding a new system of records entitled ``Consolidated Data 
Repository--HHS-OIG'' (09-90-1000).

DATES: Effective Date: This system of records will become effective 
without further notice on December 22, 2008, unless comments received 
on or before that date result in a contrary determination.
    Comment Date: Comments on this new system of records will be 
considered if we receive them at the addresses provided below no later 
than 5 p.m. Eastern Standard Time on December 10, 2008.

ADDRESSES: In commenting, please reference file code 09-90-1000. 
Because of staff and resource limitations, we cannot accept comments by 
facsimile (fax) transmission. However, you may submit comments using 
one of the following three ways (no duplicates, please):
    1. Electronically. You may submit electronically through the 
Federal eRulemaking Portal at http://www.regulations.gov. (Attachments 
should be in Microsoft Word, if possible.)
    2. By regular, express, or overnight mail. You may mail your 
printed or written submissions to the following address: Office of 
Inspector General, Department of Health and Human Services, Attention: 
Marco Villagrana, Room 5541, Cohen Building, 330 Independence Avenue, 
SW., Washington, DC 20201. Please allow sufficient time for mailed 
comments to be received before the close of the comment period.
    3. By hand or courier. You may deliver, by hand or courier, before 
the close of the comment period, your printed or written comments to 
the Office of Inspector General, Department of Health and Human 
Services, Cohen Building, 330 Independence Avenue, SW., Washington, DC 
20201. Because

[[Page 66649]]

access to the interior of the Cohen Building is not readily available 
to persons without Federal Government identification, commenters are 
encouraged to schedule their delivery with one of our staff members at 
(202) 619-1343.
    Inspection of Public Comments: All comments received before the end 
of the comment period will be posted on http://www.regulations.gov for 
public viewing. Hard copies will also be available for public 
inspection at the Office of Inspector General, Department of Health and 
Human Services, Cohen Building, 330 Independence Avenue, SW., 
Washington, DC 20201, Monday through Friday, from 8:30 a.m. to 4 p.m. 
To schedule an appointment to view public comments, phone (202) 401-
2206.

FOR FURTHER INFORMATION CONTACT: Marco Villagrana, Department of Health 
& Human Services, Office of Inspector General, Office of External 
Affairs, (202) 401-2206; or Stephen Conway, Department of Health & 
Human Services, Office of Inspector General, Office of Audit Services, 
(617) 565-2946.

SUPPLEMENTARY INFORMATION: Under Section 2 of the Inspector General Act 
of 1978, as amended, OIG is required to conduct audits and 
investigations relating to programs and operations of the Department. 
In performing these required functions, OIG must collect, collate, and 
analyze claims information relating to services rendered to Medicare 
beneficiaries and Medicaid recipients. For this reason, OIG is 
establishing a new system of records which combines information from 
several existing HHS systems of records with information from State 
sources. This combined system of records is necessary for OIG to 
perform timely and independent audits, evaluations and inspections, and 
investigations of the Medicare and Medicaid programs.
    In addition, in compliance with the ``Incident Reporting and 
Handling Requirements'' set forth in the Office of Management and 
Budget Memoranda 07-16, Safeguarding Against and Responding to the 
Breach of Personally Identifiable Information, OIG is incorporating the 
routine use language into this new system of records as part of our 
normal System of Records Notice (SORN) review development process.

Description of the Proposed System of Records

    Records from the Centers for Medicare & Medicaid Services and State 
Medicaid agencies will be incorporated into this new system of records. 
The new system of records will be created by including Medicare and 
Medicaid enrollment, eligibility, and claims data records on all 
beneficiaries and recipients. Data in the system of records will 
include names; Social Security numbers (SSNs); health insurance 
identification numbers; and claims information relating to inpatient, 
outpatient, physician/supplier, skilled nursing facilities, nursing 
home, hospice, home health, durable medical equipment, dental, 
prescription drug, and managed care.

Agency Policies, Procedures and Restrictions on the Routine Use

    The Privacy Act permits OIG to disclose information outside HHS 
without an individual's consent if the information is to be used for a 
purpose that is compatible with the purposes for which the information 
was collected. Any such disclosure of data is known as a routine use. 
Accordingly, we are proposing to establish the following routine use 
disclosures of records maintained in the system:
    1. Disclosure may be made to Federal, State, and local agencies for 
the purpose of better identifying the total current health care usage 
of the Medicare and Medicaid patient population.
    2. Disclosure may be made to Federal, State, and local government 
agencies and national health organizations to assist in the development 
of programs that will be beneficial to claimants and to protect their 
rights under law and assure that they are receiving all benefits to 
which they are entitled.
    3. Disclosure may be made to a Federal department or agency or to a 
contractor of a Federal department or agency in order to conduct 
Federal audits, evaluations and inspections, or investigations 
necessary to accomplish a statutory purpose of an agency. OIG must be 
able to disclose information for purposes needed to accomplish a 
statutory purpose of a Federal agency.
    4. Disclosure may be made to a congressional office from the record 
of an individual in response to an inquiry from the congressional 
office made at the request of that individual.
    5. In the event of litigation, information from the system of 
records may be disclosed to the Department of Justice, to a judicial or 
administrative tribunal, opposing counsel, and witnesses in the course 
of proceedings involving HHS, any HHS employee (where the matter 
pertains to the employee's official duties), or the United States, or 
any agency thereof where the litigation is likely to affect HHS, or HHS 
is a party or has an interest in the litigation and the use of the 
information is relevant and necessary to the litigation.
    6. In the event that a system of records maintained by OIG to carry 
out its functions indicates a violation or potential violation of law, 
whether civil, criminal, or regulatory in nature, and whether arising 
by general statute or particular program statute, or by regulation, 
rule, or order issued pursuant thereto, the relevant records in the 
system of records may be referred, as a routine use, to the appropriate 
agency, whether Federal, State, local, or foreign, charged with the 
responsibility of investigating or prosecuting such violation or 
charged with enforcing or implementing the statute, rule, regulation, 
or order issued pursuant thereto.
    7. In the event the that Department deems it desirable or necessary 
in determining whether particular records are required to be disclosed 
under the Freedom of Information Act, disclosure may be made to the 
Department of Justice for the purpose of obtaining its advice.
    8. A record from this system of records may be disclosed to a 
Federal agency in response to its request in connection with the hiring 
or retention of an employee, the issuance of a security clearance, the 
reporting of an investigation of an employee, the letting of a 
contract, or the issuance of a license, grant, or other benefit by the 
requesting agency, to the extent that the record is relevant and 
necessary to the requesting agency's decision on the matter.
    9. The system of records may be disclosed to student volunteers and 
other individuals performing functions for the Department but 
technically not having the status of agency employees, if they need 
access to the records to perform their assigned agency functions.
    10. A record may be disclosed to appropriate Federal agencies and 
Department contractors that have a need to know the information for the 
purpose of assisting the Department's efforts to respond to a suspected 
or confirmed breach of the security or confidentiality of information 
maintained in this system of records, and the information disclosed is 
relevant and necessary for that assistance.

Safeguards

    OIG has safeguards in place for authorized users and monitors users 
to ensure against unauthorized use. The system will conform to all 
applicable Federal laws and regulations and Federal, HHS, and OIG 
policies and standards as they relate to information security and data 
privacy.

[[Page 66650]]

Effects of the Proposed System of Records on Individual Rights

    This system is established in accordance with the principles and 
requirements of the Privacy Act and will collect, use, and disseminate 
information only as prescribed therein. Data in this system will be 
subject to the authorized releases in accordance with the routine uses 
identified in this system of records notice.
    OIG will take precautionary measures to minimize the risks of 
unauthorized access to the records and the potential harm to individual 
privacy or other personal or property rights of beneficiaries and 
recipients whose data are maintained in the system. OIG will make 
disclosures from the proposed system in accordance with the Privacy 
Act. OIG does not anticipate an unfavorable effect on individual 
privacy as a result of the disclosure of information relating to 
individuals. This proposed change will not otherwise increase access to 
these records.

    Dated: October 28, 2008.
Daniel R. Levinson,
Inspector General.
09-90-1000

SYSTEM NAME:
    Consolidated Data Repository-HHS-OIG.

SYSTEM LOCATION(S):
    Records will be maintained at the following computer site 
locations:
     HHS-OIG, 330 Independence Avenue, SW., Washington, DC 
20201.
     HHS-OIG, N2-01-02, 7500 Security Boulevard, Baltimore, MD 
21244.
    And the following HHS-OIG Regional/Field Office locations:
     JFK Federal Building, Boston, MA 02203.
     J.K. Javits Federal Building, 26 Federal Plaza, New York, 
NY 10278.
     150 South Independence Mall West, Public Ledger Building, 
Philadelphia, PA 19106.
     Atlanta Federal Center, Forsyth Street South, Atlanta, GA 
30303.
     8659 Baypine Road, Suite 203 Jacksonville, FL 32256.
     233 North Michigan Avenue, Room 1360, Chicago, IL 60601.
     3815 West Street, Joseph Hwy, Lansing, MI 48917.
     Galtier Plaza, 380 Jackson Street, Suite 727, St. Paul, MN 
55101.
     1124 Rickard Road, Suite C, Springfield, IL 62704.
     1100 Commerce Street, Dallas, TX 75242.
     1201 Walnut Street, Kansas City, MO 64106.
     90 7th Street, San Francisco, CA 94103.

CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:
    The records include information concerning Medicare beneficiaries 
and Medicaid recipients.

CATEGORIES OF RECORDS IN THE SYSTEM:
    The categories of records in the system will include Medicare 
beneficiaries' names, addresses, dates of birth, Medicare HIC numbers, 
SSNs, enrollment information and eligibility information, and claims 
information relating to the following types of services: Inpatient, 
skilled nursing facility, outpatient, physician/supplier, home health, 
hospice, durable medical equipment, prescription drug, and Medicare 
Advantage. The records will also include names, addresses, dates of 
birth, and SSNs on Medicaid recipients from State enrollment and 
eligibility files and claims information relating to the following 
types of services: Inpatient, long-term care, professional, dental, 
pharmacy, and Medicare cross-over. The National Provider Identification 
database and the Unique Provider Identification Number (UPIN) directory 
will be stored in this system of records.

AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
    Inspector General Act of 1978 (5 U.S.C. App.).

PURPOSE(S):
    The purpose of this system of records is to conduct audits, 
evaluations and inspections, and investigations of the Medicare and 
Medicaid programs.

ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM, INCLUDING CATEGORIES 
OF USERS AND THE PURPOSE OF SUCH USES:
    The Privacy Act permits OIG to disclose information outside HHS 
without an individual's consent if the information is to be used for a 
purpose that is compatible with the purposes for which the information 
was collected. Any such disclosure of data is known as a routine use. 
Accordingly, we are proposing to establish the following routine use 
disclosures of records maintained in the system:
    a. Disclosure may be made to Federal, State, and local agencies for 
the purpose of better identifying the total current health care usage 
of the Medicare and Medicaid patient population.
    b. Disclosure may be made to Federal, State, and local government 
agencies and national health care organizations to assist in the 
development of programs that will be beneficial to claimants and to 
protect their rights under law and assure that they are receiving all 
benefits to which they are entitled.
    c. Disclosure may be made to a Federal department or agency or to a 
contractor of a Federal department or agency to permit it to conduct 
Federal audits, evaluations and inspections, or investigations 
necessary to accomplish a statutory purpose of an agency. OIG must be 
able to disclose information for purposes needed to accomplish a 
statutory purpose of a Federal agency.
    d. Disclosure may be made to a congressional office from the record 
of an individual in response to an inquiry from the congressional 
office made at the request of that individual.
    e. In the event of litigation, information from the system of 
records may be disclosed to the Department of Justice, to a judicial or 
administrative tribunal, opposing counsel, and witnesses, in the course 
of proceedings involving HHS, any HHS employee (where the matter 
pertains to the employee's official duties), or the United States, or 
any agency thereof where the litigation is likely to affect HHS, or HHS 
is a party or has an interest in the litigation and the use of the 
information is relevant and necessary to the litigation.
    f. In the event that a system of records maintained by OIG to carry 
out its functions indicates a violation or potential violation of law, 
whether civil, criminal, or regulatory in nature, and whether arising 
by general statute or particular program statute, or by regulation, 
rule or order issued pursuant thereto, the relevant records in the 
system of records may be referred, as a routine use, to the appropriate 
agency, whether Federal, State, local, or foreign, charged with the 
responsibility of investigating or prosecuting such violation or 
charged with enforcing or implementing the statute, or rule, regulation 
or order issued pursuant thereto.
    g. In the event that the Department deems it desirable or 
necessary, in determining whether particular records are required to be 
disclosed under the Freedom of Information Act, disclosure may be made 
to the Department of Justice for the purpose of obtaining its advice.
    h. A record from this system of records may be disclosed to a 
Federal agency, in response to its request, in connection with the 
hiring or retention of an employee, the issuance of a security 
clearance, the reporting of an investigation of an employee, the 
letting of a contract, or the issuance of a license, grant, or other 
benefit by the requesting agency, to the extent that the record is 
relevant and necessary to the requesting agency's decision on the 
matter.

[[Page 66651]]

    i. The system of records may be disclosed to student volunteers and 
other individuals performing functions for the Department but 
technically not having the status of agency employees, if they need 
access to the records to perform their assigned agency functions.
    j. A record may be disclosed to appropriate Federal agencies and 
Department contractors that have a need to know the information for the 
purpose of assisting the Department's efforts to respond to a suspected 
or confirmed breach of the security or confidentiality of information 
maintained in this system of records, and the information disclosed is 
relevant and necessary for that assistance.

POLICIES AND PRACTICES FOR STORING, RETRIEVING, ACCESSING, RETAINING, 
AND DISPOSING OF RECORDS IN THE SYSTEM:
STORAGE:
    Data are maintained on magnetic tape, disk, or laser optical media.

RETRIEVABILITY:
    Records may be retrieved by name, name and one or more criteria 
(e.g., dates of birth, death, and service), SSN, Medicare HIC number, 
Medicaid Identification Number.

SAFEGUARDS:
    The computers that process these data are protected by technical, 
managerial, and operational controls that follow Federal policies and 
guidelines. The computers are protected by a combination of physical 
security by being located in Federal offices; access controls such as 
passwords and identification numbers; and technical protections such as 
encryption, firewalls, and anti-virus software. These controls allow 
only authorized users to access the data.
    Employees who maintain records in this system are instructed not to 
release data until the intended recipient agrees to implement 
appropriate management, operational, and technical safeguards 
sufficient to protect the confidentiality, integrity, and availability 
of the information and information systems and to prevent unauthorized 
access. This system will conform to all applicable Federal laws and 
regulations and Federal, HHS, and OIG policies and standards as they 
relate to information security and data privacy. These laws and 
regulations may apply but are not limited to: The Privacy Act of 1974; 
the Federal Information Security Management Act of 2002; the Computer 
Fraud and Abuse Act of 1986; the Health Insurance Portability and 
Accountability Act of 1996; the eGovernment Act of 2002, the Clinger-
Cohen Act of 1996; the Medicare Prescription Drug, Improvement, and 
Modernization Act of 2003, and the corresponding implementing 
regulations; and OMB Circular A-130, Management of Federal Resources, 
Appendix III, Security of Federal Automated Information Resources also 
applies. Federal, HHS, and OIG policies and standards include but are 
not limited to: All pertinent National Institute of Standards and 
Technology publications; the HHS Information Systems Program Handbook; 
and OIG Information Security Handbooks.

RETENTION AND DISPOSAL:
    These records may be maintained for an indefinite duration.

SYSTEM MANAGER AND ADDRESS:
    The agency official responsible for the system policies and 
practices outlined above is: The Chief Information Officer, Office of 
Management and Policy, Office of Inspector General, Department of 
Health and Human Services, Wilbur J. Cohen Building, Room 5230, 330 
Independence Avenue, SW., Washington, DC 20201.

NOTIFICATION PROCEDURE:
    Any inquiries regarding these systems of records should be 
addressed to the System Manager. An individual who requests 
notification of or access to a medical record shall, at the time the 
request is made, designate in writing a responsible representative who 
will be willing to review the record and inform the subject individual 
of its contents at the representative's discretion. (These notification 
and access procedures are in accordance with Department regulations (45 
CFR 5b.6).)

RECORDS ACCESS PROCEDURES:
    Same as notification procedures. Requesters should also reasonably 
specify the record contents being sought. (These access procedures are 
in accordance with Department regulations (45 CFR 5b.5(a)(2).)

CONTESTING RECORD PROCEDURES:
    Contact the official at the address in the System Manager and 
Address section above, and reasonably identify the record and specify 
the information to be contested and the corrective action sought with 
supporting justification. (These procedures are in accordance with 
Department Regulations (45 CFR 5b.7).)

RECORD SOURCE CATEGORIES:
    Information may be obtained from the Centers for Medicare & 
Medicaid Services National Claims History (inpatient, outpatient, 
physician supplier, nursing home, hospice, home care, and durable 
medical equipment), Drug Data Processing System, Medicare Advantage and 
Prescription Drug system and State Medicaid claims and enrollment 
databases.

SYSTEMS EXEMPTED FROM CERTAIN PROVISIONS OF THE ACT:

    None.
[FR Doc. E8-26725 Filed 11-7-08; 8:45 am]
BILLING CODE 4152-01-P