Policy & oversight
Federal Audit Found 97 Cybersecurity Gaps in Medicare Billing Contractors for Fiscal Year 2024, Though the Most Serious Deficiencies Declined
An OIG annual report to Congress found information security deficiencies across all seven Medicare administrative contractors in fiscal year 2024, while noting that high-risk and moderate-risk gaps fell compared with the prior year.
By the Goodsurance editorial teamAugust 6, 2026
The HHS Office of Inspector General published its annual audit of information security programs at Medicare's seven administrative contractors for fiscal year 2024, finding a total of 97 gaps across seven of nine federal cybersecurity control areas evaluated.
Medicare administrative contractors, known as MACs, are private companies that CMS contracts with to process Medicare fee-for-service claims submitted by doctors, hospitals, and other providers. Federal law requires each MAC to have its information security program independently evaluated each year. CMS engaged an independent public accounting firm to conduct the evaluations, and the OIG is required to report findings to Congress and to assess whether the evaluations were adequate.
The auditors found deficiencies in seven of the nine Federal Information Security Modernization Act control areas. In an improvement over fiscal year 2023, the number of high-risk and moderate-risk gaps declined, while low-risk gaps increased. One moderate-risk gap was identified as recurring from the prior year. The OIG concluded that the evaluations were adequate in scope and sufficiency.
The report did not indicate that any breach of beneficiary data or any improper payment resulted from the identified deficiencies. CMS and the MACs receive recommendations to address gaps and are expected to remediate them in subsequent cycles. The annual security audit is a standing requirement under the Social Security Act and represents a key oversight mechanism for the infrastructure that administers Medicare fee-for-service.
In plain words
The government watchdog checked the computer security of the seven companies that handle Medicare billing. These companies are called Medicare administrative contractors. Auditors found 97 security problems in total. The good news is that the most serious problems went down compared to the year before. The report said no patient data was known to have been stolen and no payments were known to have been made incorrectly because of these issues. The government does this security check every year and reports the results to Congress.
Understand the basics first
Source: OIG
Read at the source →