Stories

More information requested by McMorris Rodgers regarding CMS-related data breach

U.S. Rep. Cathy McMorris Rodgers (R-WA) wants more details about a ransomware attack on a subcontractor for the Centers for Medicare & Medicare Services (CMS) that impacted the personally identifiable information of some 254,000 Medicare beneficiaries. 

The U.S. House Energy and Commerce Committee, which is chaired by Rep. McMorris Rodgers, and the U.S. House Oversight and Accountability Committee are investigating the Oct. 8, 2022 data breach on the corporate network of Healthcare Management Solutions LLC (HMS), a subcontractor to ASRC Federal Data Solutions LLC (ASRC), which supports the CMS Office of Hearings and Inquiries. 

CMS found out about the data breach a day after it happened and determined on Oct. 18, 2002 that “some Medicare beneficiaries” had been impacted, according to a March 20 letter that the congresswoman and U.S. Rep. James Comer (R-KY) sent to CMS Administrator Chiquita Brooks-LaSure.

“However, it was not until Dec. 1, 2022 that CMS made the determination that the data breach constituted a “major incident,” as defined in the Federal Information Security Modernization Act of 2014,” wrote Rep. McMorris Rodgers and her colleague. “In other words, bad actors had access to Medicare beneficiaries’ information for two months before CMS determined this ransomware attack was a “major incident” triggering a legal obligation to inform Congress of such an incident.”

CMS provided a briefing to congressional staff on Dec. 15, 2022 about the incident, but Rep. McMorris Rodgers and Rep. Comer, who chairs the House Oversight and Accountability Committee, in their letter requested additional documents and communications to assist in the committees’ investigation.

The compromised information potentially includes personally identifiable information and protected health information of enrollees, including name, address, date of birth, phone number, Social Security Number, Medicare beneficiary identifier, banking information, and Medicare entitlement, enrollment, and premium information, according to the lawmakers’ letter.

They requested that Brooks-LaSure provide myriad documents and communications regarding any aspect of the ransomware attack, including any action proposed or taken by CMS, HMS, and ASRC as a result of the ransomware attack, to their committee offices by April 3.

Ripon Advance News Service

Recent Posts

Nationwide VA shortages of nursing assistants must be addressed, says Emmer

U.S. Rep. Tom Emmer (R-MN) urged the U.S. Department of Veterans Affairs (VA) to solve…

1 day ago

Capito’s bill seeks to encourage opioid overdose help from Good Samaritans

Bipartisan legislation recently cosponsored by U.S. Sen. Shelley Moore Capito (R-WV) aims to provide more…

1 day ago

Wicker, Graves, colleagues seek updated fisheries management data

To improve fisheries management across the country, U.S. Rep. Garret Graves (R-LA) and U.S. Sen.…

1 day ago

Buchanan, colleagues urge caution on finalization of proposed regs for donor-advised funds

Proposed federal regulations could have the unintended consequence of impeding charitable giving in America’s communities,…

1 day ago

Balderson offers resolution supporting importance of U.S.-produced natural gas

U.S. Rep. Troy Balderson (R-OH) on April 23 sponsored a resolution to recognize natural gas…

1 day ago

Valadao sponsors bipartisan bill to promote financial literacy in secondary schools

U.S. Rep. David Valadao (R-CA-22) on Tuesday sponsored bipartisan legislation to make financial literacy more…

2 days ago

This website uses cookies.