Federal law requires that each Medicare administrative contractor (MAC) have its information security program evaluated annually by an independent entity, and these evaluations must address the eight major requirements enumerated in the Federal Information Security Management Act of 2002 (FISMA). To comply with this provision, CMS contracted with PricewaterhouseCoopers (PwC) to evaluate information security programs at the MACs using a set of agreed-upon procedures. To satisfy the requirement to evaluate the information security controls for a subset of systems, CMS expanded the scope of its evaluations to test segments of the Medicare claims processing systems hosted at the Medicare data centers, which support each of the MACs.
| Report Date | Agency Reviewed / Investigated | Report Title | Type | Location | |
|---|---|---|---|---|---|
| Department of Health & Human Services | Review of Medicare Contractor Information Security Program Evaluations for Fiscal Year 2015 | Audit | Agency-Wide | View Report | |
| U.S. Postal Service | Mail Processing Operations at the Roanoke, VA, Processing and Distribution Center | Audit |
|
View Report | |
| Department of Energy | Followup Review of Controls Over the Department’s Classification of National Security Information | Inspection / Evaluation |
|
View Report | |
| Amtrak (National Railroad Passenger Corporation) | Governance: Addressing Remaining Shortcomings Would Lead to a Budget Development Process More Fully Aligned with Leading Practices | Audit | Agency-Wide | View Report | |
| Department of Energy | Management Letter on the Federal Energy Regulatory Commission’s Fiscal Year 2016 Financial Statement Audit | Audit |
|
View Report | |
| Department of Health & Human Services | Review of California Medicaid Managed-Care Program Potential Savings With Minimum Medical Loss Ratio | Audit |
|
View Report | |
| Federal Labor Relations Authority | Audit of the Federal Labor Relations Authority Charge Card Program and Risk Assessment for Fiscal Year 2016 | Audit | Agency-Wide | View Report | |
| National Science Foundation | Management Challenges for NSF in FY 2017 | Top Management Challenges | Agency-Wide | View Report | |
| Department of the Interior | Investigation of Construction Firm Misrepresenting Itself as a Service Disabled Veteran Owned Small Business | Investigation | Agency-Wide | View Report | |
| Amtrak (National Railroad Passenger Corporation) | TWO EMPLOYEES TERMINATED AND EIGHT OTHERS SUSPENDED FOR VIOLATIONS OF AMTRAK POLICIES | Investigation |
|
View Report | |