Framework Healthcare & Human Services
CMS Programs
CMS Programs is an umbrella label used by consulting firms for the set of security, privacy, and program-integrity requirements that CMS imposes on organizations that connect to or operate on behalf of the agency. It is not a single framework, so verify which program is meant before using this profile.
The main members of the family are: the Acceptable Risk Safeguards (ARS) for CMS systems and contractors; ARC-AMPE for state marketplaces, Medicaid and CHIP agencies, and Direct Enrollment Entities (which replaced MARS-E and the EDE-specific control set); the Enhanced Direct Enrollment audit program; and the Medicare Conditions of Participation for providers, which are covered in their own profile.
Across the family the written expectations are similar because they all descend from NIST SP 800-53: a System Security and Privacy Plan, a risk assessment, incident response and contingency plans, policies for each control family, and an independent assessment package that CMS reviews before granting an authorization or approval.
Program-integrity requirements add business process documentation and consumer protection procedures.
help
Who has to comply
Depends on the program: CMS contractors and subcontractors (ARS); state-based marketplaces, Medicaid and CHIP agencies, and Basic Health Program agencies (ARC-AMPE AE); web brokers, issuers, and platforms on the federal marketplace (ARC-AMPE DEE and EDE audits); Medicare and Medicaid providers (CoPs).
What the assessor asks to see
Assessors across these programs ask for the system boundary and data flows, the SSPP, the risk assessment and privacy impact assessment, control-family policies and procedures, technical evidence (access reviews, logs, scans, configuration baselines), incident response and contingency plans with tests, training records, third-party and interconnection agreements, the plan of action and milestones, and, for EDE, business process documentation and consumer-facing content.
Scope caution
This entry exists because a vendor's service list used the label. It should be split into or redirected to the specific program (ARS, ARC-AMPE, EDE, CoPs, CLIA) once the intended meaning is confirmed.
Assessors
Who assesses CMS Programs
Varies: CMS security control assessors and authorizing officials for ARS; independent third-party assessors and auditors chosen by the entity for ARC-AMPE and EDE, with CMS review; state survey agencies and CMS-approved accrediting organizations for the CoPs. in the certification sense.
CMS defines assessor requirements per program and approves accrediting organizations for the CoPs.
No firm has claimed a CMS Programs assessor listing yet. Claim yours →
Consultants
Who helps with CMS Programs
Healthcare GRC consultancies and security assessment firms that package these programs together for state agencies, health IT vendors, and marketplace partners. Engagements typically include gap analysis against the relevant CMS framework, SSPP authoring, and the independent assessment or audit.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CMS Programs consultant listing yet. Claim yours →
Software
Tools for CMS Programs
Tools that name this framework in their own material.
No firm has claimed a CMS Programs tool listing yet. Claim yours →
Need a hand implementing it?
Find a Consultant for CMS Programs
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with CMS Programs
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.