A CMS ACO evaluation under Part 2 is an audit or evaluation required for a CMS-regulated accountable care organization or similar entity under 42 CFR 2.53(e). It can include a qualified entity. The organization needs specified administrative or clinical systems, leadership and management, governing oversight, a CMS participation agreement or similar document, an authorized executive, and confidentiality controls.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Organizational eligibility needs evidence
42 CFR 2.53 calls for administrative or clinical systems and a leadership and management structure that includes a governing body and chief executive officer responsible for oversight and compliance with the CMS agreement. Preserve current governance and agreement records.
Verify the entity's exact CMS-regulated status, participation or similar agreement, effective period, programs, participating organizations, governing body, chief executive, compliance structure, administrative or clinical systems, and current scope. A marketing claim that an organization is an ACO, network, value-based entity, or qualified data company is not sufficient evidence.
Map related legal entities, affiliates, participants, vendors, data platforms, and delegated functions. Keep patient-identifying information within the entity and activities supported by the applicable agreement and Part 2 route.
A designated executive carries specific responsibility
The CMS agreement or similar document identifies an executive able to legally bind the organization to ensure Part 2 and agreement compliance. That executive approves a confidential, controlled setting for audits involving patient-identifying information. Document delegation and approvals precisely.
Preserve the executive's identity, title, legal authority, designation source, approval, setting, systems, users, purpose, data, dates, controls, conditions, and expiration. A privacy officer or project lead may administer controls without possessing authority to bind the organization. Confirm any delegation through current governing documents.
Test the approved environment for identity, access, role separation, multifactor authentication where appropriate, export, clipboard, screenshot, print, local cache, transfer, vendor access, logging, backups, output, incident response, retention, and destruction. Approval on paper should match how the setting operates.
Control the evaluation population and purpose
Define the CMS-required audit or evaluation, measure, population, period, sources, fields, method, recipients, and outputs. Match patients and records to the regulated activity. Exclude unrelated providers, products, episodes, counseling notes, free text, family information, and direct identifiers unless the method and authority require them.
Separate care-improvement or program-evaluation work from research, marketing, product development, employment, law enforcement, and unrelated commercial analytics. A secondary purpose or new dataset requires qualified review before access.
Outputs cannot identify SUD patients
Communications, reports, and other audit or evaluation documents must prevent direct or indirect identification, including through codes, of a patient as having or having had a substance use disorder. Apply disclosure review, small-cell controls, linkage-risk analysis, and approved distribution.
Review dashboards, tables, charts, maps, narratives, quotes, dates, rare conditions, provider-location combinations, small cohorts, row identifiers, pseudonyms, screenshots, appendices, and metadata. A code can still identify a patient to someone with the key or external context. Preserve the method and final output approval.
Restrict recipient lists and publication routes. Reports that pass one audience's review may become identifying when combined with another dataset or sent to a local organization familiar with the individuals.
Monitor change and closure
Pause access when CMS status, agreement, executive, governance, systems, participants, evaluation purpose, population, fields, vendor, or output changes. Reapprove the setting and controls as needed. Remove accounts and scheduled transfers promptly at expiry.
If an output identifies a patient or data leaves the approved setting, contain access, preserve evidence, and route privacy, security, CMS, compliance, audit, legal, clinical, and patient communication decisions. Review other outputs and projects using the same method.
Example with organization files
Seven CMS-regulated entity files are reviewed. Five contain the required agreement, systems, leadership, executive designation, setting approval, and report controls; two lack current evidence. Readiness is 5 of 7 files.
One entity renews its agreement and executive designation. The other remains held because a new analytics vendor is outside the approved setting. The five complete files proceed with output review and time-limited users.
ACO-evaluation checklist
- Verify exact CMS-regulated status and the current participation agreement.
- Preserve governance, systems, chief-executive, and binding-authority evidence.
- Obtain executive approval for the actual confidential controlled setting.
- Match population, fields, users, vendors, purpose, and evaluation dates.
- Review every output for direct, indirect, coded, and contextual identification.
- Reapprove changes and stop expired accounts or transfers.
- Contain identifying outputs or data outside the approved environment.
Owner controls
The 2024 final rule provides current context. Use agreement inventories, governance attestations, executive designations, approved environments, participant controls, output review, confidentiality policies, and periodic validation.
Monitor entity status, agreements, executive designations, users, vendors, data fields, transfers, outputs, re-identification risk, access expiry, and incidents. Audit from each evaluation record back to supported CMS purpose and from active systems into current approval evidence. Retest after CMS, governance, platform, participant, vendor, or reporting changes.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni