MARS-E compliance is the process of meeting the security and privacy requirements established by the Centers for Medicare & Medicaid Services for ACA exchanges and their supporting organizations. To achieve MARS-E compliance, organisations need to identify systems that fall within the MARS-E boundary, implement security and privacy controls based on NIST SP 800-53, maintain documentation such as the System Security Plan (SSP) and Plan of Action and Milestones (POA&M), complete independent security assessments, and obtain an Authority to Operate (ATO). Failure to meet these requirements can result in penalties of up to $25,000 per violation, suspension or revocation of an Authority to Operate (ATO), and restricted access to CMS systems.
CMS has announced that MARS-E is being replaced with the Acceptable Risk Controls for ACA, Marketplace, Privacy, and Enhanced Security (ARC-AMPE) framework. Although many of the security controls are aligned with NIST SP 800-53, organizations must be aware of the change and ensure compliance.
This guide explains what MARS-E compliance is, who must comply, its key security requirements, the assessment process, common documentation, and best practices.
Source: https://qualysec.com/mars-e ...