File No. 36634
This rule was published in the September 1, 2012, issue (Vol. 2012, No. 17) of the Utah State Bulletin.
Governor, Economic Development, Consumer Health Services
Rule R358-1
Electronic Standards for Transmitting Information through the Health Insurance Exchange
Notice of Proposed Rule
(New Rule)
DAR File No.: 36634
Filed: 08/09/2012 03:11:47 PM
RULE ANALYSIS
Purpose of the rule or reason for the change:
The purpose of this rule is to establish electronic standards for the Health Insurance Exchange and its partners.
Summary of the rule or change:
The rule outlines technology standards and requirements for the Health Insurance Exchange and its partners.
State statutory or constitutional authorization for this rule:
- Section 63M-1-2506
Anticipated cost or savings to:
the state budget:
This rule adds no costs nor saves money for the state. It establishes technology standards that prospective partners of the Health Insurance Exchange must meet. Prospective partners will disclose their technology in any request for proposal (RFP) that might be issued, and the Exchange itself will verify whether they meet the requirements.
local governments:
The Health Insurance Exchange is a state entity that does no direct or indirect business with local government. Therefore, no costs or savings will arise with the enactment of this rule.
small businesses:
The Health Insurance Exchange uses industry-standard technology and security requirements. Any business that is qualified to contract with the Exchange will use the same or better standards and requirements. Therefore, it will not cost them anything to conduct business with the Exchange.
persons other than small businesses, businesses, or local governmental entities:
The rule exists solely to set an electronic standard for Health Insurance Exchange partners to use when transmitting health information between their systems and the Exchange. Persons who are not partners of the Health Insurance Exchange will not be affected by the rule and will not experience costs or savings.
Compliance costs for affected persons:
Costs should not be incurred on the Health Insurance Exchange's behalf for any persons. In some cases, prospective contractors or partners may, at their discretion, upgrade their technology and security standards to meet Exchange requirements. However, these upgrades will benefit their business generally and without specific reference to Exchange operations. Any upgrades they deem necessary will increase their overall competitiveness in the market as a whole and will be a benefit to their operations generally.
Comments by the department head on the fiscal impact the rule may have on businesses:
It is my opinion that filing this rule will have no fiscal impact on Utah's businesses. The rule requires adherence to industry standard technologies and practices, a requirement that the Health Insurance Exchange's partners already meet. No persons covered by the rule must bear new costs, nor will they see new savings.
Spencer P. Eccles, Executive Director
The full text of this rule may be inspected, during regular business hours, at the Division of Administrative Rules, or at:
GovernorEconomic Development, Consumer Health Services
60 E SOUTH TEMPLE 3RD FLR
Salt Lake City, UT 84111
Direct questions regarding this rule to:
- Patty Conner at the above address, by phone at 801-538-8715, by FAX at , or by Internet E-mail at [email protected]
Interested persons may present their views on this rule by submitting written comments to the address above no later than 5:00 p.m. on:
10/01/2012
This rule may become effective on:
10/08/2012
Authorized by:
Patty Conner, Director
RULE TEXT
R358. Governor, Economic Development, Consumer Health Services.
R358-1. Electronic Standards for Transmitting Information through the Health Insurance Exchange.
R358-1-1. Purpose and Authority.
(1) The purpose of this rule is to establish electronic standards for data transmission and reception through the Health Insurance Exchange.
(2) This rule is enacted under the authority of Section 63M-1-2506.
R358-1-2. Definitions.
(1) Technology partner. A Health Insurance Exchange technology partner administers the technology on which the Exchange runs and supports the activities that take place on that technology.
(2) Financial partner. A Health Insurance Exchange financial partner administers the financial transactions that occur on the Exchange, including invoicing and collection of payments, and the disbursement of funds for services provided.
(3) Provider partner. A Health Insurance Exchange provider partner is any entity that offers goods or services to consumers through the Exchange system.
R358-1-3. Standards.
(1) The Office of Consumer Health Services requires that all Exchange technology, financial, and provider partners strive to keep consumer data secure at all times. All partners shall:
(a) transmit consumer data between the Exchange and all partners via secure file transfer protocol (SFTP);
(b) keep consumer data encrypted during transmission and while at rest on partner servers; and
(c) establish security profiles to provide leveled access to the minimum allowable data.
R358-1-4. HIPAA Compliance.
(1) The Office of Consumer Health Services requires that all Exchange technology and provider partners comply with the Health Insurance Portability and Accountability Act (HIPAA).
R358-1-5. Quality Control Process.
(1) Because security is integral to Health Insurance Exchange operations, the Office of Consumer Health Services shall:
(a) conduct periodic security audits to ensure the strength of the above standards as performed by all partners; and
(b) perform risk assessments across all partners, technologies, and platforms when implementing new enhancements or services.
KEY: data standards, Health Insurance Exchange, consumer health, health insurance
Date of Enactment or Last Substantive Amendment: 2012
Authorizing, and Implemented or Interpreted Law: 63M-1-2506
Additional Information
The Portable Document Format (PDF) version of the Bulletin is the official version. The PDF version of this issue is available at https://rules.utah.gov/publicat/bull-pdf/2012/b20120901.pdf. The HTML edition of the Bulletin is a convenience copy. Any discrepancy between the PDF version and HTML version is resolved in favor of the PDF version.
Text to be deleted is struck through and surrounded by brackets (e.g., [example]). Text to be added is underlined (e.g., example). Older browsers may not depict some or any of these attributes on the screen or when the document is printed.
For questions regarding the content or application of this rule, please contact Patty Conner at the above address, by phone at 801-538-8715, by FAX at , or by Internet E-mail at [email protected].