Federal law requires that each Medicare administrative contractor (MAC) have its information security program evaluated annually by an independent entity, and these evaluations must address the eight major requirements enumerated in the Federal Information Security Management Act of 2002 (FISMA). To comply with this provision, CMS contracted with PricewaterhouseCoopers (PwC) to evaluate information security programs at the MACs using a set of agreed-upon procedures. The Office of Inspector General must submit to Congress annual reports on the results of these evaluations, to include assessments of their scope and sufficiency. This report fulfills that responsibility for fiscal year 2016.
Report File
Date Issued
Submitting OIG
Department of Health & Human Services OIG
Other Participating OIGs
Department of Health & Human Services OIG
Agencies Reviewed/Investigated
Department of Health & Human Services
Report Number
A-18-17-11300
Report Description
Report Type
Audit
Agency Wide
Yes
Questioned Costs
$0
Funds for Better Use
$0
Additional Details