---
kind: "section"
citation: "42 C.F.R. § 401.718"
title: "42"
number: "401.718"
heading: "Dissemination of data."
url: "https://uscodex.org/cfr/42/401.718"
---

# §401.718. Dissemination of data.

- (a) **General.** Subject to the other requirements in this subpart, the requirements in paragraphs [(b)](#b) and [(c)](#c) of this section and any other applicable laws or contractual agreements, a qualified entity may provide or sell combined data or provide Medicare data at no cost to authorized users defined at § [401.703(b)](/cfr/42/401.703.md?p=b), [(c)](/cfr/42/401.703.md?p=c), [(m)](/cfr/42/401.703.md?p=m), and [(n)](/cfr/42/401.703.md?p=n).
- (b) **Data—**
  - (1) **De-identification.** Except as specified in [paragraph (b)(2)](#b-2) of this section, any data provided or sold by a qualified entity to an authorized user must be limited to beneficiary de-identified data. De-identification must be determined based on the de-identification standards for HIPAA covered entities found at [45 CFR 164.514(b)](/cfr/45/164.514.md?p=b).
  - (2) **Exception.** If such disclosure will be consistent with all applicable laws, data that individually identifies a beneficiary may only be disclosed to a provider or supplier (as defined at § [401.703(b)](/cfr/42/401.703.md?p=b) and [(c)](/cfr/42/401.703.md?p=c)) with whom the identifiable individuals in such data have a current patient relationship as defined at [§ 401.703(r)](/cfr/42/401.703.md?p=r).
- (c) **Data use agreement between a qualified entity and an authorized user.** A qualified entity must contractually require an authorized user to comply with the requirements in [§ 401.713(d)](/cfr/42/401.713.md?p=d) prior to providing or selling data to an authorized user under § 401.718.

## Notes

### Amendments

[81 FR 44481, July 7, 2016]

### Source

Source: 76 FR 76567, Dec. 7, 2011, unless otherwise noted.

### Authority

Authority: 42 U.S.C. 1302, 1395hh, 1395w-5, and 1395kk-2.

### Amendments

[81 FR 44481, July 7, 2016]
