An inspector general’s report has found that select data facilities at the Centers for Medicare and Medicaid Studies are vulnerable to cyberattack through its wireless networks.
The Aug. 17 report identified four vulnerabilities in CMS’s wireless security controls, but didn’t specify what the vulnerabilities were due to the sensitivity of the information.
Related: Read the report
“The vulnerabilities that we identified were collectively and, in some cases, individually significant,” the report said.
“Although we did not identify evidence that the vulnerabilities had been exploited, exploitation could have resulted in unauthorized access to and disclosure of personally identifiable information, as well as disruption of critical operations. In addition, exploitation could have compromised the confidentiality, integrity, and availability of CMS’s data and systems.”
The vulnerabilities were discovered when the OIG ran a wireless network penetration test at 13 CMS data centers from Aug. 31 to Dec. 4, 2015, using some common cyberattack techniques.
CMS said that the breaches were caused by “improper configurations and failure to complete necessary upgrades” that the agency had identified and were in the midst of addressing.
Due to the sensitive nature of the information accessible through the breaches, the OIG said it informed CMS of its findings ahead of its issuance of the draft report.
The OIG offered recommendations for improving security controls, but did not list them in the report, due to the nature of the security threats.
In a July 8 CMS response to the OIG report, acting CMS Administrator Andrew Slavitt noted that there was no evidence that personally identifiable information was compromised during the the test and concurred with the report’s recommendations, saying that it had already addressed some of them and was in the process of implementing the rest.
“CMS acknowledges that risks exist inherently for every IT system and that as technology progresses, additional safeguards will be needed,” Slavitt said.
“Through the enforcement of documented policies and procedures, as well as dedicated information security staff, CMS protects the security and privacy of data. CMS appreciates the OIG’s suggestion of controls and processes that could be improved to further reduce or mitigate risk.”




