decisionhealth Newsletters, Answer Books - 2006 Issue 3 (March)
Program_Memos / 2001 / AB-01-11
Subscribe or sign in to view the full article.
Article Overview
This program memorandum explains updated HCFA information technology security requirements for Medicare contractors and related entities, along with the expected implementation approach, assessment documentation, funding support, and reporting deadlines. It is relevant to organizations responsible for Medicare systems security, compliance, planning, and budget preparation, and it includes general guidance on core security requirements, security plan development, gap analysis, and internet policy considerations.
Why This Topic Matters
The memorandum affects how Medicare contractors document security compliance, plan system protections, and prepare future funding requests. It also sets deadlines and clarifies which security activities are expected under existing operating budgets versus the new funding process.
Article Sections
-
Overview
Introduces the broader HCFA initiative to improve Medicare contractor information systems security and describes the high-level objectives of the effort.
-
Implementation and Funding
Summarizes the new and existing security-related responsibilities and explains the general funding approach for contractor implementation activities.
-
HCFA Core Security Requirements Assessment
Describes the mandatory assessment tool, the documentation submission process, and the intended uses of the contractor report.
-
Annual Compliance Audit
Explains the annual audit requirement and identifies the broad compliance areas to be reviewed during the fiscal year.
-
Security Plans
Covers the requirement for security planning across contractor systems and the related architecture and crosswalk documentation.
-
Gap Analysis and Future Funding
Outlines the future funding information HCFA will request and the categories of cost information contractors must estimate.
-
Follow-on Program Memorandum (PM)
Notes that additional submission instructions will follow and briefly addresses internet-related policy limitations and protected data handling.
-
Summary of Key Dates
Lists the major deadlines for assessments, documentation, funding requirements, audits, risk assessments, and contingency plan updates.
-
Security Questions and Concerns
Provides contact and reference information for questions about the memorandum and related security resources.
What You Will Learn
- How HCFA organized its Medicare contractor security initiative
- What types of assessment and documentation are expected
- How security planning and gap analysis are framed in the memorandum
- Which general deadlines and reporting milestones apply
- What broad policy areas are included in the update
Who Should Read This
- Medicare contractors
- Carrier and intermediary organizations
- DME regional carriers
- Data center operators
- Standard system maintainers
- Program safeguard contractors
- Health information systems security personnel
- Compliance and budget staff
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com