OIG reviewed Alabama’s Medicaid Management Information System policies and procedures, interviewed staff and used vulnerability assessment scanning software to conduct its evaluation.
Although Alabama’s MMIS adopted a security program, numerous significant vulnerabilities remained. Specifically, the state did not ensure HP, the state’s Medicaid fiscal agent, implemented contract security requirements.
“Although we did not identify evidence that anyone had exploited these vulnerabilities, exploitation could have resulted in unauthorized access to and disclosure of Medicaid data, as well as the disruption of critical Medicaid operations,” the report reads.
Alabama concurred with OIG’s recommendations, but objected to the report’s title, writing, “Alabama has always, and will continue to always, strive to secure its Medicare data and information systems.”
More articles on cybersecurity:
Washington VA notifies patients of compromised PHI after laptop goes missing
Phishing attack at Morehead Memorial Hospital exposes PHI of 66k
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.