§155.221. Standards for direct enrollment entities and for third-parties to perform audits of direct enrollment entities. — Inbound Citations
45 C.F.R. § 155.221
Statutory Authority
Cited by 8 regulations in release Current.
Citations to 45 U.S.C. § 155.221 as a whole
Citations to §155.221(b)(1)
-
(j) Exchanges that do not use the Federal platform. A direct enrollment entity that enrolls qualified individuals, qualified employers, or qualified employees in coverage in a manner that constitutes enrollment through the State Exchange, or assists consumers with submission of applications for advance payments of the premium tax credit and cost-sharing reductions through the State Exchange, must comply with the Federally-facilitated Exchange standards in paragraphs (b)(1) through (3) and (d) of this section, including the exceptions in paragraph (c) of this section, where applicable; any additional State-specific standards under paragraph (j)(1) of this section; the State Exchange's operational readiness standards under paragraph (j)(2) of this section; and the State Exchange's website display change standards under paragraph (j)(3) of this section. References to §§ 155.415(b), and 155.415(b)(1) in paragraph (d) of this section will be understood to also apply to State Exchanges.(1) State Exchanges may add State-specific information to the standardized disclaimer under paragraph (b)(2) of this section that does not conflict with the HHS-provided language.(2) State Exchanges must establish the form and manner for their direct enrollment entities to demonstrate operational readiness and compliance with applicable requirements in order for the direct enrollment entity's internet website being used to complete an Exchange eligibility application or a QHP selection, which may include submission or completion of the following documentation to the State Exchange, in the form and manner specified by the Exchange:(A) Notices of intent to participate including auditor information;(B) Documentation packages including privacy questionnaires, privacy policy statements, and terms of service; and(A) Interconnection security agreements;(B) Security and privacy controls assessment test plans;(C) Security and privacy assessment reports;(D) Plans of action and milestones;(E) Privacy impact assessments;(F) System security and privacy plans;(G) Incident response plans; and(3) State Exchanges must require their direct enrollment entities to implement and prominently display website changes in a manner that is consistent with the display changes made by State Exchanges to the State Exchanges' websites, consistent with the process of defining and communicating standards and setting advance notice periods in paragraph (b)(6) of this section, except that all references in paragraph (b)(6) of this section to “Federally-Facilitated Exchange website” would be understood to mean “State Exchange website,” references to “HHS” would be understood to mean “State Exchange,” and the reference to “unless HHS approves a deviation from those standards” would be understood to mean “unless the State Exchange approves a deviation from those standards under the deviation request process it is required to establish should the State Exchange elect to permit deviation requests.”
Citations to §155.221(b)(2)
-
(j) Exchanges that do not use the Federal platform. A direct enrollment entity that enrolls qualified individuals, qualified employers, or qualified employees in coverage in a manner that constitutes enrollment through the State Exchange, or assists consumers with submission of applications for advance payments of the premium tax credit and cost-sharing reductions through the State Exchange, must comply with the Federally-facilitated Exchange standards in paragraphs (b)(1) through (3) and (d) of this section, including the exceptions in paragraph (c) of this section, where applicable; any additional State-specific standards under paragraph (j)(1) of this section; the State Exchange's operational readiness standards under paragraph (j)(2) of this section; and the State Exchange's website display change standards under paragraph (j)(3) of this section. References to §§ 155.415(b), and 155.415(b)(1) in paragraph (d) of this section will be understood to also apply to State Exchanges.(1) State Exchanges may add State-specific information to the standardized disclaimer under paragraph (b)(2) of this section that does not conflict with the HHS-provided language.(2) State Exchanges must establish the form and manner for their direct enrollment entities to demonstrate operational readiness and compliance with applicable requirements in order for the direct enrollment entity's internet website being used to complete an Exchange eligibility application or a QHP selection, which may include submission or completion of the following documentation to the State Exchange, in the form and manner specified by the Exchange:(A) Notices of intent to participate including auditor information;(B) Documentation packages including privacy questionnaires, privacy policy statements, and terms of service; and(A) Interconnection security agreements;(B) Security and privacy controls assessment test plans;(C) Security and privacy assessment reports;(D) Plans of action and milestones;(E) Privacy impact assessments;(F) System security and privacy plans;(G) Incident response plans; and(3) State Exchanges must require their direct enrollment entities to implement and prominently display website changes in a manner that is consistent with the display changes made by State Exchanges to the State Exchanges' websites, consistent with the process of defining and communicating standards and setting advance notice periods in paragraph (b)(6) of this section, except that all references in paragraph (b)(6) of this section to “Federally-Facilitated Exchange website” would be understood to mean “State Exchange website,” references to “HHS” would be understood to mean “State Exchange,” and the reference to “unless HHS approves a deviation from those standards” would be understood to mean “unless the State Exchange approves a deviation from those standards under the deviation request process it is required to establish should the State Exchange elect to permit deviation requests.”
Citations to §155.221(b)(3)
-
(j) Exchanges that do not use the Federal platform. A direct enrollment entity that enrolls qualified individuals, qualified employers, or qualified employees in coverage in a manner that constitutes enrollment through the State Exchange, or assists consumers with submission of applications for advance payments of the premium tax credit and cost-sharing reductions through the State Exchange, must comply with the Federally-facilitated Exchange standards in paragraphs (b)(1) through (3) and (d) of this section, including the exceptions in paragraph (c) of this section, where applicable; any additional State-specific standards under paragraph (j)(1) of this section; the State Exchange's operational readiness standards under paragraph (j)(2) of this section; and the State Exchange's website display change standards under paragraph (j)(3) of this section. References to §§ 155.415(b), and 155.415(b)(1) in paragraph (d) of this section will be understood to also apply to State Exchanges.(1) State Exchanges may add State-specific information to the standardized disclaimer under paragraph (b)(2) of this section that does not conflict with the HHS-provided language.(2) State Exchanges must establish the form and manner for their direct enrollment entities to demonstrate operational readiness and compliance with applicable requirements in order for the direct enrollment entity's internet website being used to complete an Exchange eligibility application or a QHP selection, which may include submission or completion of the following documentation to the State Exchange, in the form and manner specified by the Exchange:(A) Notices of intent to participate including auditor information;(B) Documentation packages including privacy questionnaires, privacy policy statements, and terms of service; and(A) Interconnection security agreements;(B) Security and privacy controls assessment test plans;(C) Security and privacy assessment reports;(D) Plans of action and milestones;(E) Privacy impact assessments;(F) System security and privacy plans;(G) Incident response plans; and(3) State Exchanges must require their direct enrollment entities to implement and prominently display website changes in a manner that is consistent with the display changes made by State Exchanges to the State Exchanges' websites, consistent with the process of defining and communicating standards and setting advance notice periods in paragraph (b)(6) of this section, except that all references in paragraph (b)(6) of this section to “Federally-Facilitated Exchange website” would be understood to mean “State Exchange website,” references to “HHS” would be understood to mean “State Exchange,” and the reference to “unless HHS approves a deviation from those standards” would be understood to mean “unless the State Exchange approves a deviation from those standards under the deviation request process it is required to establish should the State Exchange elect to permit deviation requests.”
Citations to §155.221(b)(4)
-
(6) In addition to applicable requirements under § 155.221(b)(4), a web-broker must demonstrate operational readiness and compliance with applicable requirements prior to the web-broker's internet website being used to complete an Exchange eligibility application or a QHP selection, which may include submission or completion, in the form and manner specified by HHS, of the following:(i) Operational data including licensure information, points of contact, and third-party relationships;(ii) Enrollment testing, prior to approval or renewal;(iii) Website reviews performed by HHS;(A) Penetration testing results;(B) Security and privacy assessment reports;(C) Vulnerability scan results;(D) Plans of action and milestones; and