MARS-E
Privacy PII PHI Protection - MARS-E v2.0

MARS-E MARS-E-Privacy-PII-PHI-Minimum-Necessary-HIPAA-Privacy-Rule-NIST-800-122-45-CFR-164-Subpart-E: MARS-E Privacy + PII + PHI + Minimum Necessary + HIPAA Privacy Rule + NIST 800-122 + 45 CFR 164 Subpart E

Protect Personally Identifiable Information (PII) and Protected Health Information (PHI) handled by Exchanges. Apply NIST 800-122 PII Confidentiality Impact Level determination + minimum necessary standard for use disclosure and request + HIPAA Privacy Rule 45 CFR 164 Subpart E (Privacy of Individually Identifiable Health Information) where applicable + ACA Section 1411 information requirements + 45 CFR 155.260(a)(3) privacy and security requirements. Implement notice of privacy practices for Exchange consumers. Honor opt-out and choice mechanisms. De-identification under HIPAA Safe Harbor or Expert Determination. Limited Data Set procedures with Data Use Agreements. Tax Filing Status disclosure restrictions. Beneficiary consent for information sharing across Exchange + Medicaid + CHIP + plan issuers. Strict controls for sharing with Federal Data Services Hub. Annual privacy training. Privacy Officer designation. Privacy Impact Assessment per OMB M-03-22 + DHS Privacy Office Handbook + CMS PIA Template.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.