CMS Explains the PPACA Exchange Record System
Client Alert | 1 min read | 02.11.13
On February 6, 2013, the Centers for Medicare & Medicaid Services ("CMS") published a notice about how the new system of records, intended to support the new health insurance exchanges, will operate. A "system of records" is a group of any records under the control of a federal agency from which information about individuals is retrieved by name or other personal identifier.
The Privacy Act, 5 U.S.C. 522a, requires each agency to publish in the Federal Register a system of records notice ("SORN") identifying and describing each system of records the agency maintains, including the purposes for which the agency uses personally identifiable information ("PII") in the system, the routine uses for which the agency discloses such information outside the agency, and how individual record subjects can exercise their rights under the Privacy Act.
Accordingly, CMS provided information about the new system of records, also known as the Health Insurance Exchanges ("HIX") Program. The notice includes the following information about the HIX Program:
- The Patient Protection and Affordable Care Act ("PPACA") requires the U.S. Department of Health and Human Services ("HHS") to collaborate with state agencies in establishing a system of individual and small group exchanges by October 1, 2013.
- The primary purpose of the HIX system is to collect, create, use, and disclose PII on individuals who apply for eligibility determinations for enrollment in a qualified health plan through the exchanges, for insurance affordability programs, and for certifications of exemption from the individual responsibility requirement.
- After consumers provide PII during the application process, the exchanges will share their information with health insurers that sell coverage through the exchanges and others involved in helping consumers use the exchanges.
The text of the notice to establish a new system of records is available here.
Insights
Client Alert | 4 min read | 06.25.26
Twin Executive Orders Seek to Spur Quantum Leap in Technology and Cybersecurity
On June 22, 2026, President Trump signed two executive orders, “Securing the Nation Against Advanced Cryptographic Attacks” (Quantum Security EO) and “Ushering in the Next Frontier of Quantum Innovation” (Quantum Innovation EO), marking the most significant federal action on quantum technology since the Quantum Computing Cybersecurity Preparedness Act of 2022, which directed agencies to harden their information systems against quantum-enabled hacking. The orders seek to speed the development of quantum computers, which are advanced processors that can calculate multiple possibilities simultaneously and thus solve problems exponentially faster than traditional computers. At the same time, the orders look to protect against the danger that quantum technology can “break” traditional encryption by easily decoding it. Of particular note for government contractors, the Quantum Security EO directs agencies to update federal acquisition regulations to require contractors by 2031 to adopt information processing standards that resist quantum-enabled codebreaking.
Client Alert | 7 min read | 06.24.26
Client Alert | 3 min read | 06.24.26
Client Alert | 4 min read | 06.23.26
EPA Hands Over AI Data Center Regulation to States and Communities to Develop Best Practices
