Bindinglaw

US · guidance

CMS Pub. 100-08, ch. 4, § 4.2.2.7

Program Integrity Security Requirements

activein force · 2026-08-25 – presentas-observed

This section applies to UPICs.

To ensure a high level of security for the UPIC functions, the UPIC shall develop,

implement, operate, and maintain security policies and procedures that meet and

conform to the requirements of the Business Partners System Security Manual (BPSSM)

and the CMS Informational Security Acceptable Risk Safeguards (ISARS). Further, the

UPIC shall adequately inform and train all UPIC employees to follow UPIC security

policies and procedures so that the information the UPIC obtain is confidential.

Note: The data UPICs collect in administering UPIC contracts belong to CMS. Thus, the

UPICs collect and use individually identifiable information on behalf of the Medicare

program to routinely perform the business functions necessary for administering the

Medicare program, such as MR and program integrity activities to prevent fraud, waste,

and abuse. Consequently, any disclosure of individually identifiable information without

prior consent from the individual to whom the information pertains, or without statutory

or contract authority, requires CMS’ prior approval.

This section discusses broad security requirements that UPICs shall follow. The

requirements listed below are in the BPSSM or ARS. There are several exceptions. The

first is requirement A (concerning UPIC operations), which addresses several broad

requirements; CMS has included requirement A here for emphasis and clarification. Two

others are in requirement B (concerning sensitive information) and requirement G

(concerning telephone security). Requirements B and G relate to security issues that are

not systems related and are not in the BPSSM.

A. Unified Program Integrity Contractor Operations

• The UPIC shall conduct their activities in areas not accessible to the general

public.

• The UPIC shall completely segregate itself from all other operations.

Segregation shall include floor-to-ceiling walls and/or other measures

described in ARS Appendix B PE-3 and CMS-2 that prevent unauthorized

persons access to or inadvertent observation of sensitive and investigative

information.

• Other requirements regarding UPIC operations shall include sections 3.1,

3.1.2, 4.2, 4.2.5, and 4.2.6 of the BPSSM.

B. Handling and Physical Security of Sensitive and Investigative Material

Refer to ARS Appendix B PE-3 and CMS-1 for definitions of sensitive and investigative

material.

In addition, the UPIC shall follow the requirements provided below:

• Establish a policy that employees shall discuss specific allegations of fraud

only within the context of their professional duties and only with those who

have a valid need to know, which includes (this is not an exhaustive list):

- Appropriate CMS personnel

- UPIC staff

- MAC MR staff

- UPIC or MAC audit staff

- UPIC or MAC data analysis staff

- UPIC or MAC senior management

- UPIC or MAC corporate counsel

• The ARSs require that:

- The following workstation security requirements are specified and

implemented: (1) what workstation functions can be performed, (2) the

manner in which those functions are to be performed, and (3) the

physical attributes of the surroundings of a specific workstation or class

of workstation that can access sensitive CMS information. CMS

requires that for UPICs all local workstations as well as workstations

used at home by UPICs comply with these requirements.

- If UPIC employees are authorized to work at home on sensitive data,

they shall observe the same security practices that they observe at the

office. These shall address such items as viruses, virtual private

networks, and protection of sensitive data, including printed

documents.

- Users are prohibited from installing desktop modems.

- The connection of portable computing or portable network devices on

the CMS claims processing network is restricted to approved devices

only. Removable hard drives and/or a Federal Information Processing

Standards (FIPS)-approved method of cryptography shall be employed

to protect information residing on portable and mobile information

systems.

- Alternate work sites are those areas where employees, subcontractors,

consultants, auditors, etc. perform work associated duties. The most

common alternate work site is an employee’s home. However, there

may be other alternate work sites such as training centers, specialized

work areas, processing centers, etc. For alternate work site equipment

controls, (1) only CMS Business Partner-owned computers and

software are used to process, access, and store sensitive information;

(2) a specific room or area that has the appropriate space and facilities

is used; (3) means are available to facilitate communication with the

managers or other members of the Business Partner Security staff in

case of security problems; (4) locking file cabinets or desk drawers; (5)

“locking hardware” to secure IT equipment to larger objects such as

desks or tables; and (6) smaller Business Partner- owned equipment is

locked in a storage cabinet or desk when not in use. If wireless

networks are used at alternate work sites, wireless base stations are

placed away from outside walls to minimize transmission of data

outside of the building.

The UPIC shall also adhere to the following:

• Ensure the mailroom, general correspondence, and telephone inquiries

procedures maintain confidentiality whenever the UPIC receives

correspondence, telephone calls, or other communication alleging fraud.

Further, all internal written operating procedures shall clearly state security

procedures.

• Direct mailroom staff not to open UPIC mail in the mailroom unless the UPIC

has requested the mailroom do so for safety and health precautions.

Alternately, if mailroom staff opens UPIC mail, mailroom staff shall not read

the contents.

• For mail processing sites separate from the UPIC, the UPIC shall minimize the

handling of UPIC mail by multiple parties before delivery to the UPIC.

• The UPIC shall mark mail to CMS Central Office or to another UPIC

“personal and confidential” and address it to a specific person.

• Where more specialized instructions do not prohibit UPIC employees, they

may retain sensitive and investigative materials at their desks, in office work

baskets, and at other points in the office during the course of the normal work

day. Regardless of other requirements, the employees shall restrict access to

sensitive and investigative materials, and UPIC staff shall not leave such

material unattended.

• The UPIC staff shall safeguard all sensitive or investigative material when the

materials are being transported or sent by UPIC staff.

• The UPIC shall maintain a controlled filing system (refer to section 4.2.2.6.1).

C. Designation of a Security Officer

The security officer shall take such action as is necessary to correct breaches of the

security standards and to prevent recurrence of the breaches. In addition, the security

officer shall document the action taken and maintain that documentation for at least

seven (7) years.

Actions shall include:

• Within one (1) hour of discovering a security incident, clearly and accurately

report the incident following BPSSM requirements for reporting of security

incidents. For purposes of this requirement, a security incident is the same as

the definition in section 3.6 of the BPSSM, Incident Reporting and Response.

• Specifically, the report shall address the following where appropriate:

- Types of information about beneficiaries shall at a minimum address

whether the compromised information includes name, address, HICNs,

and date of birth;

- Types of information about providers/suppliers shall at a minimum

address if the compromised information includes name, address, and

provider/supplier ID;

- Whether LE is investigating any of the providers/suppliers with

compromised information; and

- Police reports.

• Provide additional information that CMS requests within 72 hours of the

request.

• If CMS requests, issue a Fraud Alert to all CMS Medicare contractors within

72 hours of the discovery that the data was compromised, listing the HICNs

and provider/supplier IDs that were compromised.

• Within 72 hours of discovery of a security incident, when feasible, review all

security measures and revise them if necessary so they are adequate to protect

data against physical or electronic theft.

Refer to section 3.1 of the BPSSM and Attachment 1 of this manual section (letter from

Director, Office of Financial Management, concerning security and confidentiality of

UPIC data) for additional requirements.

D. Staffing of the Unified Program Integrity Contractor and Security Training

The UPIC shall perform thorough background and character reference checks, including

at a minimum credit checks, for potential employees to verify their suitability for

employment. Specifically, background checks shall at least be at level 2- moderate risk.

(People with access to sensitive data at CMS have a level 5 risk). The UPIC may require

investigations above a level 2 if the UPIC believes the higher level is required to protect

sensitive information.

At the point the UPIC makes a hiring decision for a UPIC position, and prior to the

selected person’s starting work, the UPIC shall require the proposed candidate to fill out

a conflict of interest declaration, as well as a confidentiality statement.

Annually, the UPICs shall require existing employees to complete a conflict of interest

declaration, as well as a confidentiality statement.

At least once a year, the UPICs shall thoroughly explain to and discuss with employees

the special security considerations under which the UPIC operates. Further, this training

shall emphasize that in no instance shall employees disclose sensitive or investigative

information, even in casual conversation. The UPIC shall ensure that employees

understand the training provided.

Refer to section 2.0 of the BPSSM and ARS Appendix B AT-2, AT-3, AT-4, SA-6, MA-

5.0, PE-5.CMS.1, IR2-2.2, CP 3.1, CP 3.2, CP 3.3, and SA 3.CMS.1 for additional

training requirements.

E. Access to Unified Program Integrity Contractor Information

Refer to section 2.3.4 of the BPSSM for requirements regarding access to UPIC

information.

The UPIC shall notify the OIG if parties without a need to know are asking

inappropriate questions regarding any investigations. The UPICs shall refer all requests

from the press related to the Medicare Integrity Program to the CMS contracting officer

with a copy to the CORs and BFLs for approval prior to release. This includes, but is not

limited to, contractor initiated press releases, media questions, media interviews, and

Internet postings.

F. Computer Security

Refer to section 4.1.1 of the BPSSM for the computer security requirements.

G. Telephone and Fax Security

The UPICs shall implement phone security practices. The UPICs shall discuss

investigations only with those individuals who need to know the information and shall

not divulge information to individuals not known to the UPIC involved in the

investigation of the related issue.

Additionally, the UPICs shall only use CMS, the OIG, the DOJ, and the FBI phone

numbers that they can verify. To assist with this requirement, UPIC management shall

provide UPIC staff with a list of the names and telephone numbers of the individuals of

the authorized agencies that the UPICs deal with and shall ensure that this list is properly

maintained and periodically updated.

Employees shall be polite and brief in responding to phone calls but shall not volunteer

any information or confirm or deny that an investigation is in process. However, UPICs

shall not respond to questions concerning any case the OIG, the FBI, or any other LE

agency is investigating. The UPICs shall refer such questions to the OIG, the FBI, etc.,

as appropriate.

Finally, the UPICs shall transmit sensitive and investigative information via facsimile

(fax) lines only after the UPIC has verified that the receiving fax machine is secure.

Unless the fax machine is secure, UPICs shall make arrangements with the addressee to

have someone waiting at the receiving machine while the fax is transmitting. The UPICs

shall not transmit sensitive and investigative information via fax if the sender must delay

a feature, such as entering the information into the machine’s memory.

Each UPIC and I-MEDIC shall develop and utilize a fax cover sheet with standardized

elements to ensure consistency in messaging and to facilitate sender validation.

A standardized fax cover sheet shall include several key elements to verify the

legitimacy of the fax sent by the UPIC and/or I-MEDIC. These elements shall include:

• Official logo and address of the program integrity contractor sending the fax,

• CMS logo,

• Case number reference, and

• Verification of UPIC and I-MEDIC contact information.

See example at Exhibit 50 – UPIC and I-MEDIC Fax Cover Sheet.

History

(Rev. 13821; Issued:06-09-26; Effective: 02-26-26; Implementation: 02-26-26)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
72c7e4cf3e3ed50096e746971c16957a72ef054515733f120108df7fdf767922
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.