US · guidance
CMS Pub. 100-08, ch. 4, § 4.2.2.7
Program Integrity Security Requirements
This section applies to UPICs.
To ensure a high level of security for the UPIC functions, the UPIC shall develop,
implement, operate, and maintain security policies and procedures that meet and
conform to the requirements of the Business Partners System Security Manual (BPSSM)
and the CMS Informational Security Acceptable Risk Safeguards (ISARS). Further, the
UPIC shall adequately inform and train all UPIC employees to follow UPIC security
policies and procedures so that the information the UPIC obtain is confidential.
Note: The data UPICs collect in administering UPIC contracts belong to CMS. Thus, the
UPICs collect and use individually identifiable information on behalf of the Medicare
program to routinely perform the business functions necessary for administering the
Medicare program, such as MR and program integrity activities to prevent fraud, waste,
and abuse. Consequently, any disclosure of individually identifiable information without
prior consent from the individual to whom the information pertains, or without statutory
or contract authority, requires CMS’ prior approval.
This section discusses broad security requirements that UPICs shall follow. The
requirements listed below are in the BPSSM or ARS. There are several exceptions. The
first is requirement A (concerning UPIC operations), which addresses several broad
requirements; CMS has included requirement A here for emphasis and clarification. Two
others are in requirement B (concerning sensitive information) and requirement G
(concerning telephone security). Requirements B and G relate to security issues that are
not systems related and are not in the BPSSM.
A. Unified Program Integrity Contractor Operations
• The UPIC shall conduct their activities in areas not accessible to the general
public.
• The UPIC shall completely segregate itself from all other operations.
Segregation shall include floor-to-ceiling walls and/or other measures
described in ARS Appendix B PE-3 and CMS-2 that prevent unauthorized
persons access to or inadvertent observation of sensitive and investigative
information.
• Other requirements regarding UPIC operations shall include sections 3.1,
3.1.2, 4.2, 4.2.5, and 4.2.6 of the BPSSM.
B. Handling and Physical Security of Sensitive and Investigative Material
Refer to ARS Appendix B PE-3 and CMS-1 for definitions of sensitive and investigative
material.
In addition, the UPIC shall follow the requirements provided below:
• Establish a policy that employees shall discuss specific allegations of fraud
only within the context of their professional duties and only with those who
have a valid need to know, which includes (this is not an exhaustive list):
- Appropriate CMS personnel
- UPIC staff
- MAC MR staff
- UPIC or MAC audit staff
- UPIC or MAC data analysis staff
- UPIC or MAC senior management
- UPIC or MAC corporate counsel
• The ARSs require that:
- The following workstation security requirements are specified and
implemented: (1) what workstation functions can be performed, (2) the
manner in which those functions are to be performed, and (3) the
physical attributes of the surroundings of a specific workstation or class
of workstation that can access sensitive CMS information. CMS
requires that for UPICs all local workstations as well as workstations
used at home by UPICs comply with these requirements.
- If UPIC employees are authorized to work at home on sensitive data,
they shall observe the same security practices that they observe at the
office. These shall address such items as viruses, virtual private
networks, and protection of sensitive data, including printed
documents.
- Users are prohibited from installing desktop modems.
- The connection of portable computing or portable network devices on
the CMS claims processing network is restricted to approved devices
only. Removable hard drives and/or a Federal Information Processing
Standards (FIPS)-approved method of cryptography shall be employed
to protect information residing on portable and mobile information
systems.
- Alternate work sites are those areas where employees, subcontractors,
consultants, auditors, etc. perform work associated duties. The most
common alternate work site is an employee’s home. However, there
may be other alternate work sites such as training centers, specialized
work areas, processing centers, etc. For alternate work site equipment
controls, (1) only CMS Business Partner-owned computers and
software are used to process, access, and store sensitive information;
(2) a specific room or area that has the appropriate space and facilities
is used; (3) means are available to facilitate communication with the
managers or other members of the Business Partner Security staff in
case of security problems; (4) locking file cabinets or desk drawers; (5)
“locking hardware” to secure IT equipment to larger objects such as
desks or tables; and (6) smaller Business Partner- owned equipment is
locked in a storage cabinet or desk when not in use. If wireless
networks are used at alternate work sites, wireless base stations are
placed away from outside walls to minimize transmission of data
outside of the building.
The UPIC shall also adhere to the following:
• Ensure the mailroom, general correspondence, and telephone inquiries
procedures maintain confidentiality whenever the UPIC receives
correspondence, telephone calls, or other communication alleging fraud.
Further, all internal written operating procedures shall clearly state security
procedures.
• Direct mailroom staff not to open UPIC mail in the mailroom unless the UPIC
has requested the mailroom do so for safety and health precautions.
Alternately, if mailroom staff opens UPIC mail, mailroom staff shall not read
the contents.
• For mail processing sites separate from the UPIC, the UPIC shall minimize the
handling of UPIC mail by multiple parties before delivery to the UPIC.
• The UPIC shall mark mail to CMS Central Office or to another UPIC
“personal and confidential” and address it to a specific person.
• Where more specialized instructions do not prohibit UPIC employees, they
may retain sensitive and investigative materials at their desks, in office work
baskets, and at other points in the office during the course of the normal work
day. Regardless of other requirements, the employees shall restrict access to
sensitive and investigative materials, and UPIC staff shall not leave such
material unattended.
• The UPIC staff shall safeguard all sensitive or investigative material when the
materials are being transported or sent by UPIC staff.
• The UPIC shall maintain a controlled filing system (refer to section 4.2.2.6.1).
C. Designation of a Security Officer
The security officer shall take such action as is necessary to correct breaches of the
security standards and to prevent recurrence of the breaches. In addition, the security
officer shall document the action taken and maintain that documentation for at least
seven (7) years.
Actions shall include:
• Within one (1) hour of discovering a security incident, clearly and accurately
report the incident following BPSSM requirements for reporting of security
incidents. For purposes of this requirement, a security incident is the same as
the definition in section 3.6 of the BPSSM, Incident Reporting and Response.
• Specifically, the report shall address the following where appropriate:
- Types of information about beneficiaries shall at a minimum address
whether the compromised information includes name, address, HICNs,
and date of birth;
- Types of information about providers/suppliers shall at a minimum
address if the compromised information includes name, address, and
provider/supplier ID;
- Whether LE is investigating any of the providers/suppliers with
compromised information; and
- Police reports.
• Provide additional information that CMS requests within 72 hours of the
request.
• If CMS requests, issue a Fraud Alert to all CMS Medicare contractors within
72 hours of the discovery that the data was compromised, listing the HICNs
and provider/supplier IDs that were compromised.
• Within 72 hours of discovery of a security incident, when feasible, review all
security measures and revise them if necessary so they are adequate to protect
data against physical or electronic theft.
Refer to section 3.1 of the BPSSM and Attachment 1 of this manual section (letter from
Director, Office of Financial Management, concerning security and confidentiality of
UPIC data) for additional requirements.
D. Staffing of the Unified Program Integrity Contractor and Security Training
The UPIC shall perform thorough background and character reference checks, including
at a minimum credit checks, for potential employees to verify their suitability for
employment. Specifically, background checks shall at least be at level 2- moderate risk.
(People with access to sensitive data at CMS have a level 5 risk). The UPIC may require
investigations above a level 2 if the UPIC believes the higher level is required to protect
sensitive information.
At the point the UPIC makes a hiring decision for a UPIC position, and prior to the
selected person’s starting work, the UPIC shall require the proposed candidate to fill out
a conflict of interest declaration, as well as a confidentiality statement.
Annually, the UPICs shall require existing employees to complete a conflict of interest
declaration, as well as a confidentiality statement.
At least once a year, the UPICs shall thoroughly explain to and discuss with employees
the special security considerations under which the UPIC operates. Further, this training
shall emphasize that in no instance shall employees disclose sensitive or investigative
information, even in casual conversation. The UPIC shall ensure that employees
understand the training provided.
Refer to section 2.0 of the BPSSM and ARS Appendix B AT-2, AT-3, AT-4, SA-6, MA-
5.0, PE-5.CMS.1, IR2-2.2, CP 3.1, CP 3.2, CP 3.3, and SA 3.CMS.1 for additional
training requirements.
E. Access to Unified Program Integrity Contractor Information
Refer to section 2.3.4 of the BPSSM for requirements regarding access to UPIC
information.
The UPIC shall notify the OIG if parties without a need to know are asking
inappropriate questions regarding any investigations. The UPICs shall refer all requests
from the press related to the Medicare Integrity Program to the CMS contracting officer
with a copy to the CORs and BFLs for approval prior to release. This includes, but is not
limited to, contractor initiated press releases, media questions, media interviews, and
Internet postings.
F. Computer Security
Refer to section 4.1.1 of the BPSSM for the computer security requirements.
G. Telephone and Fax Security
The UPICs shall implement phone security practices. The UPICs shall discuss
investigations only with those individuals who need to know the information and shall
not divulge information to individuals not known to the UPIC involved in the
investigation of the related issue.
Additionally, the UPICs shall only use CMS, the OIG, the DOJ, and the FBI phone
numbers that they can verify. To assist with this requirement, UPIC management shall
provide UPIC staff with a list of the names and telephone numbers of the individuals of
the authorized agencies that the UPICs deal with and shall ensure that this list is properly
maintained and periodically updated.
Employees shall be polite and brief in responding to phone calls but shall not volunteer
any information or confirm or deny that an investigation is in process. However, UPICs
shall not respond to questions concerning any case the OIG, the FBI, or any other LE
agency is investigating. The UPICs shall refer such questions to the OIG, the FBI, etc.,
as appropriate.
Finally, the UPICs shall transmit sensitive and investigative information via facsimile
(fax) lines only after the UPIC has verified that the receiving fax machine is secure.
Unless the fax machine is secure, UPICs shall make arrangements with the addressee to
have someone waiting at the receiving machine while the fax is transmitting. The UPICs
shall not transmit sensitive and investigative information via fax if the sender must delay
a feature, such as entering the information into the machine’s memory.
Each UPIC and I-MEDIC shall develop and utilize a fax cover sheet with standardized
elements to ensure consistency in messaging and to facilitate sender validation.
A standardized fax cover sheet shall include several key elements to verify the
legitimacy of the fax sent by the UPIC and/or I-MEDIC. These elements shall include:
• Official logo and address of the program integrity contractor sending the fax,
• CMS logo,
• Case number reference, and
• Verification of UPIC and I-MEDIC contact information.
See example at Exhibit 50 – UPIC and I-MEDIC Fax Cover Sheet.
History
(Rev. 13821; Issued:06-09-26; Effective: 02-26-26; Implementation: 02-26-26)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
72c7e4cf3e3ed50096e746971c16957a72ef054515733f120108df7fdf767922
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.