US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 2.1
Key Personnel Roles
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
Business partners shall designate a principal (i.e., primary) SSO who is qualified to manage the
Medicare information security program and ensure the implementation of necessary safeguards.
The SSO shall be organizationally independent of IT operations. The SSO can be within the CIO
organizational domain but cannot have responsibility for operation, maintenance, or
development.
See Section 1.1 for additional requirements that pertain to the Medicare Administrative
Contractor SSO position.
The business partners that process Medicare data shall maintain an Authority to Operate (ATO) for
the information technology systems that are used. The ATO requires that certain roles be filled by
Federal personnel and other roles to be filled by business partner personnel. Many of the roles, and
the associated responsibilities, are listed in the CMS Information Systems Security and Privacy
Policy (IS2P2) and the HHS Information Systems Security and Privacy Policy (IS2P)0F
1 manuals.
Some of the key personnel listed in the IS2P2 include:
- Business Owner (BO)
- Contracting Officer Representative (COR)
- Information System Security Officer (ISSO)
- System Developer Maintainer (SDM)
In addition to the above roles, the business partner personnel shall include a principal System
Security Officer (SSO). The SSO position for each contractor should be full-time and fully
qualified - preferably credentialed in systems security (e.g., Certified Information Systems Security
Professional [CISSP]). Having an individual with appropriate education and experience to execute
security administration duties will help reinforce that security must be a cultural norm that guides
daily activities, and not a set of compliance directives. A qualified SSO who is available to direct
security operations full-time provides the foundation for the security culture and awareness of the
organization. The SSO should also encourage their systems security personnel to pursue security
accreditation.
A business partner may have additional SSOs at various organizational levels, but all security
actions that affect Medicare operations shall be coordinated through the principal SSO. The
principle SSO ensures compliance with the CMS information security program and MAC ARS by:
• Facilitating the Medicare IT system information security program and ensuring that
necessary safeguards are in place and working
• Coordinating information security system activities throughout the organization
• Ensuring that IT system information security requirements are considered during budget
development and execution
• Reviewing compliance of all components with the MAC ARS and reporting vulnerabilities
to management
• Ensuring an incident response capability is established for investigating system security and
privacy breaches and reporting significant problems (see section 3.6) to business partner
management and CMS
1 The HHS IS2P document is available by requesting it from your Federal Information System Security Officer
• Ensuring that technical and operational information security controls are incorporated into
new IT systems by participating in and reviewing all new systems/installations and major
changes
• Ensuring that IT systems information security requirements are addressed in Requests for
Proposal (RFP) and subcontracts involving the handling, processing, and/or analysis of
Medicare data
• Maintaining information security documentation in the System Security Profile for review
by CMS and external auditors and keeping all elements of the System Security Profile (see
section 3.7)
• Cooperating in all official external evaluations of the business partner’s information security
program
• Facilitating the completion of the Information Security Risk Assessment (see section 3.2)
• Ensuring that an operational IT Systems Contingency Plan (ITSCP) is in place and tested
(see section 3.3)
• Documenting and updating the monthly Plan of Action and Milestones (POA&M) (see
section 3.5.2). Additional updates may occur whenever a POA&M scheduled completion
date passes, and/or following the issuance of new requirements, risk assessments, internal
audits, and external evaluations
• Ensuring that appropriate safety and control measures are arranged with local fire, police,
and health agencies for handling emergencies (see Appendix A)
The principal SSO shall earn a minimum of 40 hours in continuing professional education credits
each year. The educational sessions conducted at the CMS Security Controls Oversight and Update
Training (CSCOUT) can be u
sed toward fulfilling the continuing professional education credits. The associated credit hours will
be noted on the CSCOUT agenda.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
3c42dcd7c45d612df89046c72b51bec91cd924274e2a92dc9ffffaee0066d01f
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.