Medicare Program Integrity Manual (Pub. 100-08), Ch. 4 § 4.2.2.7

Program Integrity Security Requirements

Last amended: 2026Year: 2026Length: 1,989 wordsOfficial source
4.2.2.7 – Program Integrity Security Requirements (Rev. 13821; Issued:06-09-26; Effective: 02-26-26; Implementation: 02-26-26) This section applies to UPICs. To ensure a high level of security for the UPIC functions, the UPIC shall develop, implement, operate, and maintain security policies and procedures that meet and conform to the requirements of the Business Partners System Security Manual (BPSSM) and the CMS Informational Security Acceptable Risk Safeguards (ISARS). Further, the UPIC shall adequately inform and train all UPIC employees to follow UPIC security policies and procedures so that the information the UPIC obtain is confidential. Note: The data UPICs collect in administering UPIC contracts belong to CMS. Thus, the UPICs collect and use individually identifiable information on behalf of the Medicare program to routinely perform the business functions necessary for administering the Medicare program, such as MR and program integrity activities to prevent fraud, waste, and abuse. Consequently, any disclosure of individually identifiable information without prior consent from the individual to whom the information pertains, or without statutory or contract authority, requires CMS’ prior approval. This section discusses broad security requirements that UPICs shall follow. The requirements listed below are in the BPSSM or ARS. There are several exceptions. The first is requirement A (concerning UPIC operations), which addresses several broad requirements; CMS has included requirement A here for emphasis and clarification. Two others are in requirement B (concerning sensitive information) and requirement G (concerning telephone security). Requirements B and G relate to security issues that are not systems related and are not in the BPSSM. A. Unified Program Integrity Contractor Operations • The UPIC shall conduct their activities in areas not accessible to the general public. • The UPIC shall completely segregate itself from all other operations. Segregation shall include floor-to-ceiling walls and/or other measures described in ARS Appendix B PE-3 and CMS-2 that prevent unauthorized persons access to or inadvertent observation of sensitive and investigative information. • Other requirements regarding UPIC operations shall include sections 3.1, 3.1.2, 4.2, 4.2.5, and 4.2.6 of the BPSSM. B. Handling and Physical Security of Sensitive and Investigative Material Refer to ARS Appendix B PE-3 and CMS-1 for definitions of sensitive and investigative material. In addition, the UPIC shall follow the requirements provided below: • Establish a policy that employees shall discuss specific allegations of fraud only within the context of their professional duties and only with those who have a valid need to know, which includes (this is not an exhaustive list): - Appropriate CMS personnel - UPIC staff - MAC MR staff - UPIC or MAC audit staff - UPIC or MAC data analysis staff - UPIC or MAC senior management - UPIC or MAC corporate counsel • The ARSs require that: - The following workstation security requirements are specified and implemented: (1) what workstation functions can be performed, (2) the manner in which those functions are to be performed, and (3) the physical attributes of the surroundings of a specific workstation or class of workstation that can access sensitive CMS information. CMS requires that for UPICs all local workstations as well as workstations used at home by UPICs comply with these requirements. - If UPIC employees are authorized to work at home on sensitive data, they shall observe the same security practices that they observe at the office. These shall address such items as viruses, virtual private networks, and protection of sensitive data, including printed documents. - Users are prohibited from installing desktop modems. - The connection of portable computing or portable network devices on the CMS claims processing network is restricted to approved devices only. Removable hard drives and/or a Federal Information Processing Standards (FIPS)-approved method of cryptography shall be employed to protect information residing on portable and mobile information systems. - Alternate work sites are those areas where employees, subcontractors, consultants, auditors, etc. perform work associated duties. The most common alternate work site is an employee’s home. However, there may be other alternate work sites such as training centers, specialized work areas, processing centers, etc. For alternate work site equipment controls, (1) only CMS Business Partner-owned computers and software are used to process, access, and store sensitive information; (2) a specific room or area that has the appropriate space and facilities is used; (3) means are available to facilitate communication with the managers or other members of the Business Partner Security staff in case of security problems; (4) locking file cabinets or desk drawers; (5) “locking hardware” to secure IT equipment to larger objects such as desks or tables; and (6) smaller Business Partner- owned equipment is locked in a storage cabinet or desk when not in use. If wireless networks are used at alternate work sites, wireless base stations are placed away from outside walls to minimize transmission of data outside of the building. The UPIC shall also adhere to the following: • Ensure the mailroom, general correspondence, and telephone inquiries procedures maintain confidentiality whenever the UPIC receives correspondence, telephone calls, or other communication alleging fraud. Further, all internal written operating procedures shall clearly state security procedures. • Direct mailroom staff not to open UPIC mail in the mailroom unless the UPIC has requested the mailroom do so for safety and health precautions. Alternately, if mailroom staff opens UPIC mail, mailroom staff shall not read the contents. • For mail processing sites separate from the UPIC, the UPIC shall minimize the handling of UPIC mail by multiple parties before delivery to the UPIC. • The UPIC shall mark mail to CMS Central Office or to another UPIC “personal and confidential” and address it to a specific person. • Where more specialized instructions do not prohibit UPIC employees, they may retain sensitive and investigative materials at their desks, in office work baskets, and at other points in the office during the course of the normal work day. Regardless of other requirements, the employees shall restrict access to sensitive and investigative materials, and UPIC staff shall not leave such material unattended. • The UPIC staff shall safeguard all sensitive or investigative material when the materials are being transported or sent by UPIC staff. • The UPIC shall maintain a controlled filing system (refer to section 4.2.2.6.1). C. Designation of a Security Officer The security officer shall take such action as is necessary to correct breaches of the security standards and to prevent recurrence of the breaches. In addition, the security officer shall document the action taken and maintain that documentation for at least seven (7) years. Actions shall include: • Within one (1) hour of discovering a security incident, clearly and accurately report the incident following BPSSM requirements for reporting of security incidents. For purposes of this requirement, a security incident is the same as the definition in section 3.6 of the BPSSM, Incident Reporting and Response. • Specifically, the report shall address the following where appropriate: - Types of information about beneficiaries shall at a minimum address whether the compromised information includes name, address, HICNs, and date of birth; - Types of information about providers/suppliers shall at a minimum address if the compromised information includes name, address, and provider/supplier ID; - Whether LE is investigating any of the providers/suppliers with compromised information; and - Police reports. • Provide additional information that CMS requests within 72 hours of the request. • If CMS requests, issue a Fraud Alert to all CMS Medicare contractors within 72 hours of the discovery that the data was compromised, listing the HICNs and provider/supplier IDs that were compromised. • Within 72 hours of discovery of a security incident, when feasible, review all security measures and revise them if necessary so they are adequate to protect data against physical or electronic theft. Refer to section 3.1 of the BPSSM and Attachment 1 of this manual section (letter from Director, Office of Financial Management, concerning security and confidentiality of UPIC data) for additional requirements. D. Staffing of the Unified Program Integrity Contractor and Security Training The UPIC shall perform thorough background and character reference checks, including at a minimum credit checks, for potential employees to verify their suitability for employment. Specifically, background checks shall at least be at level 2- moderate risk. (People with access to sensitive data at CMS have a level 5 risk). The UPIC may require investigations above a level 2 if the UPIC believes the higher level is required to protect sensitive information. At the point the UPIC makes a hiring decision for a UPIC position, and prior to the selected person’s starting work, the UPIC shall require the proposed candidate to fill out a conflict of interest declaration, as well as a confidentiality statement. Annually, the UPICs shall require existing employees to complete a conflict of interest declaration, as well as a confidentiality statement. At least once a year, the UPICs shall thoroughly explain to and discuss with employees the special security considerations under which the UPIC operates. Further, this training shall emphasize that in no instance shall employees disclose sensitive or investigative information, even in casual conversation. The UPIC shall ensure that employees understand the training provided. Refer to section 2.0 of the BPSSM and ARS Appendix B AT-2, AT-3, AT-4, SA-6, MA- 5.0, PE-5.CMS.1, IR2-2.2, CP 3.1, CP 3.2, CP 3.3, and SA 3.CMS.1 for additional training requirements. E. Access to Unified Program Integrity Contractor Information Refer to section 2.3.4 of the BPSSM for requirements regarding access to UPIC information. The UPIC shall notify the OIG if parties without a need to know are asking inappropriate questions regarding any investigations. The UPICs shall refer all requests from the press related to the Medicare Integrity Program to the CMS contracting officer with a copy to the CORs and BFLs for approval prior to release. This includes, but is not limited to, contractor initiated press releases, media questions, media interviews, and Internet postings. F. Computer Security Refer to section 4.1.1 of the BPSSM for the computer security requirements. G. Telephone and Fax Security The UPICs shall implement phone security practices. The UPICs shall discuss investigations only with those individuals who need to know the information and shall not divulge information to individuals not known to the UPIC involved in the investigation of the related issue. Additionally, the UPICs shall only use CMS, the OIG, the DOJ, and the FBI phone numbers that they can verify. To assist with this requirement, UPIC management shall provide UPIC staff with a list of the names and telephone numbers of the individuals of the authorized agencies that the UPICs deal with and shall ensure that this list is properly maintained and periodically updated. Employees shall be polite and brief in responding to phone calls but shall not volunteer any information or confirm or deny that an investigation is in process. However, UPICs shall not respond to questions concerning any case the OIG, the FBI, or any other LE agency is investigating. The UPICs shall refer such questions to the OIG, the FBI, etc., as appropriate. Finally, the UPICs shall transmit sensitive and investigative information via facsimile (fax) lines only after the UPIC has verified that the receiving fax machine is secure. Unless the fax machine is secure, UPICs shall make arrangements with the addressee to have someone waiting at the receiving machine while the fax is transmitting. The UPICs shall not transmit sensitive and investigative information via fax if the sender must delay a feature, such as entering the information into the machine’s memory. Each UPIC and I-MEDIC shall develop and utilize a fax cover sheet with standardized elements to ensure consistency in messaging and to facilitate sender validation. A standardized fax cover sheet shall include several key elements to verify the legitimacy of the fax sent by the UPIC and/or I-MEDIC. These elements shall include: • Official logo and address of the program integrity contractor sending the fax, • CMS logo, • Case number reference, and • Verification of UPIC and I-MEDIC contact information. See example at Exhibit 50 – UPIC and I-MEDIC Fax Cover Sheet.
Medicare Program Integrity Manual (Pub. 100-08), Ch. 4 § 4.2.2.7: Program Integrity Security Requirements | Justis AI