CMS Incident Reporting Requirements

CMS One‑Hour Confirmed Privacy Incident Reporting Requirement

The Centers for Medicare & Medicaid Services (CMS) imposes one of the strictest federal incident‑reporting timelines in the United States. Under CMS’s privacy and security program requirements, Medicare Advantage (MA), Part D sponsors, and certain contractors must report confirmed privacy incidents to CMS within one hour of determining that an incident has occurred.

This requirement applies to any organization that handles CMS data under contract, including health plans, delegated entities, and downstream vendors.

What Triggers the One‑Hour Reporting Requirement?

The one‑hour clock begins when the organization has a “confirmed privacy incident.”

A confirmed incident generally means:

  • The organization has validated that CMS data was accessed, used, disclosed, or exposed in a manner not permitted under CMS rules, HIPAA, or contract terms
  • The organization has enough information to reasonably conclude that an incident did occur, even if the full scope is still being investigated

This is different from a suspected incident.
The one‑hour rule applies only once the incident is confirmed, but confirmation is expected to happen quickly.

📄 What Must Be Reported to CMS?

Within one hour of confirmation, the organization must submit an incident report to CMS (typically via the CMS data incident reporting portal or designated email). The report must include:

  • Description of the incident
  • Date and time the incident occurred and was discovered
  • Type of data involved (e.g., beneficiary identifiers, PHI, PII)
  • Number of individuals affected (or best estimate)
  • Systems, vendors, or contractors involved
  • Immediate mitigation steps taken
  • Contact information for follow‑up

CMS may request additional details as the investigation progresses.

🧩 What Counts as a Privacy Incident?

Examples include:

  • Misdirected mail containing CMS beneficiary information
  • Unauthorized access by employees or contractors
  • Loss or theft of devices containing CMS data
  • Emailing CMS data to the wrong recipient
  • System misconfigurations exposing CMS data
  • Vendor breaches involving CMS information

If CMS data is involved, the incident is almost always reportable.

🔐 Why the Requirement Is So Strict

CMS handles highly sensitive beneficiary information and expects contractors to:

  • Detect incidents quickly
  • Escalate internally without delay
  • Notify CMS so it can assess systemic risk and coordinate response

The one‑hour rule is designed to ensure real‑time visibility into potential threats to Medicare beneficiaries.

⚠️ Consequences of Non‑Compliance

Failure to meet the one‑hour reporting requirement can lead to:

  • Corrective action plans
  • Contract sanctions
  • Civil monetary penalties
  • Increased CMS oversight
  • Potential contract termination in severe cases

See Also