Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 1

Introduction

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Key Requirements

This manual addresses the following key Medicare Fee-For-Service (FFS) business

partner security elements:

• A business partner is a contractor involved in Medicare FFS claims processing

• An overview of primary roles and responsibilities

• A program management planning table to assist System Security Officers (SSOs)

and other security staff in coordinating system security programs at business

partner sites

• The collection of CMS policies, procedures, standards, and guidelines can be

found on the CMS Information Security Web site at: https://security.cms.gov

• The specific version of the ARS to be used by the Medicare Administrative

Contractors (MAC) is the MAC ARS, which is Attachment A of this document

• MACs shall implement the ARS High Value Asset (HVA) controls contained

within the MAC ARS

The Centers for Medicare and Medicaid Services (CMS) provides health coverage to more than 100

million people through Medicare, Medicaid, the Children’s Health Insurance Program, and the

Health Insurance Marketplace. As a Federal agency, the systems used to process data are required

to follow the Federal Information Security Modernization Act (FISMA) of 2014.

FISMA defines three security objectives for information and information systems: Confidentiality,

Integrity and Availability (CIA). FISMA also directs the promulgation of Federal standards for: (i)

the security categorization of Federal information and information systems based on the objectives

of providing appropriate levels of information security according to a range of risk levels; and (ii)

minimum security requirements for information and information systems in each such category.

These Federal standards are issued in the form of Federal Information Processing Standards (FIPS)

199, Standards for Security Categorization of Federal Information and Information Systems, and

FIPS 200, Minimum Security Requirements for Federal Information and Information Systems,

respectively.

Using FIPS 199, CMS categorized its information according to information type. An information

type is a specific category of information (e.g., privacy, medical, proprietary, financial,

investigative, contractor sensitive, security management) defined by an organization or, in some

instances, by a specific law, Executive Order, directive, policy, or regulation.

For each information type, CMS used FIPS 199 to determine its associated security category by

evaluating the potential impact value (e.g., High, Moderate, or Low) for each of the three FISMA

security objectives—CIA. The resultant security categorization is the CMS System Security Level.

This is the basis for assessing the risks to CMS operations and assets, and in selecting the

appropriate minimum-security controls and techniques (i.e., MAC Acceptable Risk Safeguards

[ARS] controls).

Federal Information Processing Standards (FIPS) 200 specifies minimum security requirements for

information and information systems supporting the executive agencies of the federal government

and a risk-based process for selecting the security controls necessary to satisfy the minimum-security requirements. To comply with FIPS 200, agencies shall first determine the security

category (i.e., information type) of their information system in accordance with the provisions of

FIPS 199 and then apply the appropriate set of baseline security controls contained in the current

version of NIST SP 800-53. Recommended Security Controls for Federal Information Systems.

Agencies have flexibility in applying the baseline security controls in accordance with the tailoring

guidance provided in NIST SP 800-53. This allows agencies, such as CMS, to adjust the security

controls to more closely fit its mission requirements and operational environments.

The CMS Information Security and Privacy Policy contains individual policy statements, along

with the CMS Minimum Security Requirements, provide technical guidance to CMS and its

contractors as to the minimum level of security controls that shall be implemented to protect CMS’

information and information systems. These two CMS documents, along with other federal and

CMS requirements, are used to form the basis for the CMS ARS.

The “Medicare Prescription Drug, Improvement, and Modernization Act of 2003 (MMA) - Section

912: Requirements for Information Security for Medicare Administrative Contractors” (Section 912

of the MMA) provided for a new type of contractor relationship, the “Medicare Administrative

Contractor (MAC),” and implemented requirements for annual evaluation, testing, and reporting on

security programs at both MACs and existing carrier and intermediary business partners (to include

their respective data centers). In this manual, the terms “business partner” and “contractor” are used

interchangeably, and all provisions that apply to business partners also apply to MACs. In addition,

the term ARS is used in this manual to mean the ARS that includes the required security and

privacy control baselines and tailored with the supplemental controls identified by the Business

Owner and Information System Security Officer (ISSO). For the MACs, this will be known as the

MAC ARS.

CMS requires that the MACs, the primary CMS Medicare claims processing business partner,

implement information security controls on their information technology (IT) systems to maintain

the CIA of Medicare systems operations in the event of computer incidents or physical disasters.

A sound entity-wide security program is the cornerstone of effective security control

implementation and maintenance. Security controls cannot be effective without a robust entity-wide

security program that is fully sponsored and supported by senior management and staffed by

individuals with proper training and knowledge.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
33b992f96b3a1682f0305469f27ae906720e00b68ac66d84f9cc6cde3287dd84
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS Pub. 100-17, ch. 117_systems_security, § 1 · binding.law