Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Review of Medicare Contractor Information Security Program Evaluations for Fiscal Year 2008

Issued on  | Posted on  | Report number: A-18-09-30200

Report Materials

Executive Summary

The Medicare Prescription Drug, Improvement, and Modernization Act of 2003 added information security requirements for Medicare contractors to the Social Security Act (the Act). Each Medicare contractor must have its information security program evaluated annually by an independent entity. To comply with this provision, CMS contracted with PricewaterhouseCoopers (PwC) to evaluate information security programs at the contractors using a set of agreed-upon procedures. The Act also requires evaluations of the information security controls for a subset of systems. To satisfy this requirement, CMS developed an information security assessment methodology and contracted with JANUS Associates, Inc. (JANUS), to perform technical assessments at Medicare data centers using the methodology.

OIG must submit to Congress annual reports on the results of these evaluations, to include assessments of their scope and sufficiency. This report fulfills that responsibility for fiscal year 2008.

PwC's evaluations of the contractor information security programs were adequate in scope and sufficiency. We could not determine the scope and sufficiency of the JANUS work for all of the data center technical assessments because of several issues with its working papers. PwC reported a total of 161 gaps at 26 Medicare contractors. JANUS reported a total of 48 gaps at 8 data centers.

We recommended that CMS review all contractor documentation related to future data center technical assessments and ensure that the work performed complies with CMS contractual requirements. At a minimum, this should include a review of test plans to ensure that the contractor has completed all required testing procedures and a review of contractor working papers to verify that reported gaps have been adequately supported, identified, and included in the technical assessment reports. CMS concurred with our recommendation and stated that it would take the appropriate actions to address the identified issues.

Complete Report


-
-
-