US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 1
Introduction
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
This manual addresses the following key Medicare Fee-For-Service (FFS) business
partner security elements:
• A business partner is a contractor involved in Medicare FFS claims processing
• An overview of primary roles and responsibilities
• A program management planning table to assist System Security Officers (SSOs)
and other security staff in coordinating system security programs at business
partner sites
• The collection of CMS policies, procedures, standards, and guidelines can be
found on the CMS Information Security Web site at: https://security.cms.gov
• The specific version of the ARS to be used by the Medicare Administrative
Contractors (MAC) is the MAC ARS, which is Attachment A of this document
• MACs shall implement the ARS High Value Asset (HVA) controls contained
within the MAC ARS
The Centers for Medicare and Medicaid Services (CMS) provides health coverage to more than 100
million people through Medicare, Medicaid, the Children’s Health Insurance Program, and the
Health Insurance Marketplace. As a Federal agency, the systems used to process data are required
to follow the Federal Information Security Modernization Act (FISMA) of 2014.
FISMA defines three security objectives for information and information systems: Confidentiality,
Integrity and Availability (CIA). FISMA also directs the promulgation of Federal standards for: (i)
the security categorization of Federal information and information systems based on the objectives
of providing appropriate levels of information security according to a range of risk levels; and (ii)
minimum security requirements for information and information systems in each such category.
These Federal standards are issued in the form of Federal Information Processing Standards (FIPS)
199, Standards for Security Categorization of Federal Information and Information Systems, and
FIPS 200, Minimum Security Requirements for Federal Information and Information Systems,
respectively.
Using FIPS 199, CMS categorized its information according to information type. An information
type is a specific category of information (e.g., privacy, medical, proprietary, financial,
investigative, contractor sensitive, security management) defined by an organization or, in some
instances, by a specific law, Executive Order, directive, policy, or regulation.
For each information type, CMS used FIPS 199 to determine its associated security category by
evaluating the potential impact value (e.g., High, Moderate, or Low) for each of the three FISMA
security objectives—CIA. The resultant security categorization is the CMS System Security Level.
This is the basis for assessing the risks to CMS operations and assets, and in selecting the
appropriate minimum-security controls and techniques (i.e., MAC Acceptable Risk Safeguards
[ARS] controls).
Federal Information Processing Standards (FIPS) 200 specifies minimum security requirements for
information and information systems supporting the executive agencies of the federal government
and a risk-based process for selecting the security controls necessary to satisfy the minimum-security requirements. To comply with FIPS 200, agencies shall first determine the security
category (i.e., information type) of their information system in accordance with the provisions of
FIPS 199 and then apply the appropriate set of baseline security controls contained in the current
version of NIST SP 800-53. Recommended Security Controls for Federal Information Systems.
Agencies have flexibility in applying the baseline security controls in accordance with the tailoring
guidance provided in NIST SP 800-53. This allows agencies, such as CMS, to adjust the security
controls to more closely fit its mission requirements and operational environments.
The CMS Information Security and Privacy Policy contains individual policy statements, along
with the CMS Minimum Security Requirements, provide technical guidance to CMS and its
contractors as to the minimum level of security controls that shall be implemented to protect CMS’
information and information systems. These two CMS documents, along with other federal and
CMS requirements, are used to form the basis for the CMS ARS.
The “Medicare Prescription Drug, Improvement, and Modernization Act of 2003 (MMA) - Section
912: Requirements for Information Security for Medicare Administrative Contractors” (Section 912
of the MMA) provided for a new type of contractor relationship, the “Medicare Administrative
Contractor (MAC),” and implemented requirements for annual evaluation, testing, and reporting on
security programs at both MACs and existing carrier and intermediary business partners (to include
their respective data centers). In this manual, the terms “business partner” and “contractor” are used
interchangeably, and all provisions that apply to business partners also apply to MACs. In addition,
the term ARS is used in this manual to mean the ARS that includes the required security and
privacy control baselines and tailored with the supplemental controls identified by the Business
Owner and Information System Security Officer (ISSO). For the MACs, this will be known as the
MAC ARS.
CMS requires that the MACs, the primary CMS Medicare claims processing business partner,
implement information security controls on their information technology (IT) systems to maintain
the CIA of Medicare systems operations in the event of computer incidents or physical disasters.
A sound entity-wide security program is the cornerstone of effective security control
implementation and maintenance. Security controls cannot be effective without a robust entity-wide
security program that is fully sponsored and supported by senior management and staffed by
individuals with proper training and knowledge.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
33b992f96b3a1682f0305469f27ae906720e00b68ac66d84f9cc6cde3287dd84
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.