Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 2.1

Key Personnel Roles

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Key Requirements

Business partners shall designate a principal (i.e., primary) SSO who is qualified to manage the

Medicare information security program and ensure the implementation of necessary safeguards.

The SSO shall be organizationally independent of IT operations. The SSO can be within the CIO

organizational domain but cannot have responsibility for operation, maintenance, or

development.

See Section 1.1 for additional requirements that pertain to the Medicare Administrative

Contractor SSO position.

The business partners that process Medicare data shall maintain an Authority to Operate (ATO) for

the information technology systems that are used. The ATO requires that certain roles be filled by

Federal personnel and other roles to be filled by business partner personnel. Many of the roles, and

the associated responsibilities, are listed in the CMS Information Systems Security and Privacy

Policy (IS2P2) and the HHS Information Systems Security and Privacy Policy (IS2P)0F

1 manuals.

Some of the key personnel listed in the IS2P2 include:

- Business Owner (BO)

- Contracting Officer Representative (COR)

- Information System Security Officer (ISSO)

- System Developer Maintainer (SDM)

In addition to the above roles, the business partner personnel shall include a principal System

Security Officer (SSO). The SSO position for each contractor should be full-time and fully

qualified - preferably credentialed in systems security (e.g., Certified Information Systems Security

Professional [CISSP]). Having an individual with appropriate education and experience to execute

security administration duties will help reinforce that security must be a cultural norm that guides

daily activities, and not a set of compliance directives. A qualified SSO who is available to direct

security operations full-time provides the foundation for the security culture and awareness of the

organization. The SSO should also encourage their systems security personnel to pursue security

accreditation.

A business partner may have additional SSOs at various organizational levels, but all security

actions that affect Medicare operations shall be coordinated through the principal SSO. The

principle SSO ensures compliance with the CMS information security program and MAC ARS by:

• Facilitating the Medicare IT system information security program and ensuring that

necessary safeguards are in place and working

• Coordinating information security system activities throughout the organization

• Ensuring that IT system information security requirements are considered during budget

development and execution

• Reviewing compliance of all components with the MAC ARS and reporting vulnerabilities

to management

• Ensuring an incident response capability is established for investigating system security and

privacy breaches and reporting significant problems (see section 3.6) to business partner

management and CMS

1 The HHS IS2P document is available by requesting it from your Federal Information System Security Officer

• Ensuring that technical and operational information security controls are incorporated into

new IT systems by participating in and reviewing all new systems/installations and major

changes

• Ensuring that IT systems information security requirements are addressed in Requests for

Proposal (RFP) and subcontracts involving the handling, processing, and/or analysis of

Medicare data

• Maintaining information security documentation in the System Security Profile for review

by CMS and external auditors and keeping all elements of the System Security Profile (see

section 3.7)

• Cooperating in all official external evaluations of the business partner’s information security

program

• Facilitating the completion of the Information Security Risk Assessment (see section 3.2)

• Ensuring that an operational IT Systems Contingency Plan (ITSCP) is in place and tested

(see section 3.3)

• Documenting and updating the monthly Plan of Action and Milestones (POA&M) (see

section 3.5.2). Additional updates may occur whenever a POA&M scheduled completion

date passes, and/or following the issuance of new requirements, risk assessments, internal

audits, and external evaluations

• Ensuring that appropriate safety and control measures are arranged with local fire, police,

and health agencies for handling emergencies (see Appendix A)

The principal SSO shall earn a minimum of 40 hours in continuing professional education credits

each year. The educational sessions conducted at the CMS Security Controls Oversight and Update

Training (CSCOUT) can be u

sed toward fulfilling the continuing professional education credits. The associated credit hours will

be noted on the CSCOUT agenda.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
3c42dcd7c45d612df89046c72b51bec91cd924274e2a92dc9ffffaee0066d01f
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.