CMS Policy & Guidance

Executive Order on Improving the Nation’s Cybersecurity: What it means for you

What is the Executive Order?

The Executive Order on Improving the Nation's Cybersecurity (Executive Order 14028) is an important step forward in protecting Americans from cyber threats. The order, signed by President Biden on May 11, 2021, focuses on strengthening the cybersecurity of the federal government, critical infrastructure, and the private sector.

Zero Trust: what you need to know

Zero Trust is a cybersecurity model that offers protection for CMS systems, employees and beneficiaries through continuous validation at every stage of a digital interaction

As CMS continues to modernize its systems and practices, the agency is implementing Zero Trust and its strong authentication methods, network segmentation, threat prevention, and “least access” policies to benefit everyone. 

CMS Privacy Program Plan

​​​​​Privacy program at CMS

Use and disclosure

As authorized by statute, regulation, or Executive Order, CMS conducts activities involving the collection, use, and disclosure of Protected Health Information (PHI) and Personally Identifiable Information (PII). CMS collects, uses, and discloses PII/PHI for payment and health care operations if and only if CMS can identify a statute or Executive Order that provides CMS with the authority for that action.

CMS Information System Contingency Plan (ISCP) Exercise Handbook

Contingency Planning at CMS 

Contingency planning at the Center for Medicare and Medicaid Services (CMS) is essential for protecting the organization from potential risks and ensuring the continuity of its operations. An Information System Contingency Plan (ISCP) is the cornerstone document of contingency planning for information systems, and every CMS FISMA system must have one in place.

Data Guardian Handbook

CMS Beneficiary Data Protection Initiative (BDPI)

CMS created the Beneficiary Data Protection Initiative (BDPI) in July 2015 in response to public breach events. CMS’ BDPI is managed by the Information Security Privacy Group (ISPG), Division of Security and Privacy Compliance (DSPC), and provides information security and privacy training and education for all employees and contractors. Its key principles are:

CMS Information Systems Security & Privacy Policy (IS2P2)

Purpose

As required under the Federal Information Security Modernization Act (FISMA) of 2014 (44 U.S.C. Chapter 35), and in compliance with the updated requirements of the National Institute of Standards and Technology's (NIST) Special Publications (SP) 800-53, Revision 5, and other federal requirements, this Policy defines the framework for protecting and controlling the confidentiality, integrity, and availability of CMS information and information systems.