Goodsurance

Policy & oversight

Federal Audit Found 97 Cybersecurity Gaps in Medicare Billing Contractors for Fiscal Year 2024, Though the Most Serious Deficiencies Declined

An OIG annual report to Congress found information security deficiencies across all seven Medicare administrative contractors in fiscal year 2024, while noting that high-risk and moderate-risk gaps fell compared with the prior year.

By the Goodsurance editorial teamAugust 6, 2026

The HHS Office of Inspector General published its annual audit of information security programs at Medicare's seven administrative contractors for fiscal year 2024, finding a total of 97 gaps across seven of nine federal cybersecurity control areas evaluated.

Medicare administrative contractors, known as MACs, are private companies that CMS contracts with to process Medicare fee-for-service claims submitted by doctors, hospitals, and other providers. Federal law requires each MAC to have its information security program independently evaluated each year. CMS engaged an independent public accounting firm to conduct the evaluations, and the OIG is required to report findings to Congress and to assess whether the evaluations were adequate.

The auditors found deficiencies in seven of the nine Federal Information Security Modernization Act control areas. In an improvement over fiscal year 2023, the number of high-risk and moderate-risk gaps declined, while low-risk gaps increased. One moderate-risk gap was identified as recurring from the prior year. The OIG concluded that the evaluations were adequate in scope and sufficiency.

The report did not indicate that any breach of beneficiary data or any improper payment resulted from the identified deficiencies. CMS and the MACs receive recommendations to address gaps and are expected to remediate them in subsequent cycles. The annual security audit is a standing requirement under the Social Security Act and represents a key oversight mechanism for the infrastructure that administers Medicare fee-for-service.

In plain words

The government watchdog checked the computer security of the seven companies that handle Medicare billing. These companies are called Medicare administrative contractors. Auditors found 97 security problems in total. The good news is that the most serious problems went down compared to the year before. The report said no patient data was known to have been stolen and no payments were known to have been made incorrectly because of these issues. The government does this security check every year and reports the results to Congress.

Source: OIG
Read at the source →

More news

Other stories on what is moving in Medicare.

Policy & oversight

OIG Found More Than 15 Million Dollars in Medicare Payments Where Emergency Room Billing Codes Were Used at Non-Emergency Sites

A March 2026 federal audit identified improper and potentially improper Medicare payments made when physicians and hospitals used emergency department billing codes for care not actually delivered in an emergency department, and found that Medicare lacked automated safeguards to catch the mismatches.

August 8, 2026

Policy & oversight

Federal Audit Found at Least 4.7 Million Dollars in Medicare Overpayments at an Arkansas Hospital

An OIG audit of Jefferson Regional Medical Center found a high rate of billing errors on claims flagged as elevated risk, producing an estimated 4.7 million dollars in improper Medicare payments. The hospital disputed most of the findings.

August 7, 2026

Policy & oversight

CMS Publishes Plan to Speed Medicare Coverage for Breakthrough Medical Devices

A new pathway would give FDA-cleared breakthrough devices a national Medicare coverage decision within weeks of regulatory approval, rather than waiting years under the standard process.

August 7, 2026

Policy & oversight

CMS Published Second-Quarter 2026 Drug Coding Decisions That Shape How Medicare Identifies and Pays for New Medicines

The quarterly HCPCS drug coding update, posted July 29 and highlighted in the August 6 MLN Connects newsletter, determines which new medications and biologicals get a dedicated Medicare billing code.

August 6, 2026

Policy & oversight

CMS Sets a Sunset Date for the NTAP Alternative Track for Breakthrough Devices and Advances the RAPID Pathway

The fiscal year 2027 hospital payment final rule phases out the alternative NTAP track that breakthrough-designated devices used to qualify for Medicare reimbursement, while a new CMS-FDA program called RAPID is positioned to take its place.

August 5, 2026

Policy & oversight

Medicare Rights Center Says New Medicaid Work Requirements Rule Threatens Low-Income Medicare Enrollees

A CMS final rule implementing Medicaid work and reporting requirements drew sharp criticism from the Medicare Rights Center, which warns that dual-eligible beneficiaries could lose the Medicaid coverage that helps them afford Medicare premiums and cost-sharing.

August 5, 2026