Finding 2023-041
Medicaid Cluster, ALN 93.775, 93.777, and 93.778 - ADP Security Program
Management Views
MDHHS agrees with part a. of the finding. MDHHS and DTMB disagree with part b. of the finding.
For part b., although MDHHS agrees that system security plans were not updated timely for the sys...
Finding 2023-041
Medicaid Cluster, ALN 93.775, 93.777, and 93.778 - ADP Security Program
Management Views
MDHHS agrees with part a. of the finding. MDHHS and DTMB disagree with part b. of the finding.
For part b., although MDHHS agrees that system security plans were not updated timely for the systems cited and the authority to operate expired for both systems, MDHHS disagrees that effective controls were not implemented to ensure confidentiality, integrity, and availability of its automated data processing (ADP) information systems. MDHHS also disagrees that the security of critical systems was at risk by failing to mitigate potential vulnerabilities as described above.
MDHHS has compensating controls in place to ensure confidentiality, integrity, and availability of its ADP information systems in addition to mitigating potential vulnerabilities. MDHHS monitors remediation of Plans of Actions and Milestones for all information systems even after expiration of the authority to operate. The ADP systems cited for not having an updated risk assessment are reviewed biennially through the Internal Control Evaluation process where control evidence is updated to demonstrate effectiveness of controls.
For one system cited, MDHHS is required to audit the system as part of the responsibilities related to the Affordable Care Act and the Medicaid Expansion marketplace. Those audits are conducted to show compliance with federal information security and privacy requirements related to data stored in those systems. The other system cited did not have any significant changes and implemented controls are still working as expected.
Planned Corrective Action
For part a., MDHHS will perform annual reviewing and testing of the business continuity plan (BCP). MDHHS has completed annual review and testing of the BCP as of April 22, 2024.
For part b., MDHHS and DTMB will complete the necessary updates to the system security plans, including updating the risk assessments, and anticipate completion for both systems by December 31, 2024. MDHHS and DTMB anticipate that authority to operate renewals will be attained for both systems by December 31, 2024.
Anticipated Completion Date
December 31, 2024
Responsible Individual(s)
Jim Bowen, MDHHS
Nathan Buckwalter, DTMB
Heather Frick, DTMB
Karen Scott, MDHHS
Keelie Honsowitz, MDHHS