MARS-E Compliance Guide: Security Controls, ATO Requirements & ARC-AMPE Transition

Every year, millions of Americans use the Affordable Care Act (ACA) Marketplace to enrol in health insurance. Large amounts of sensitive data are being exchanged behind these exchanges, such as Personally Identifiable Information (PII), Protected Health Information (PHI), and Federal Tax Information (FTI). The Centers for Medicare & Medicaid Services (CMS) has adopted the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to ensure that all entities providing assistance to ACA marketplaces are adhering to the necessary requirements to safeguard the data.

MARS-E compliance is the process of meeting the security and privacy requirements established by the Centers for Medicare & Medicaid Services for ACA exchanges and their supporting organizations. To achieve MARS-E compliance, organisations need to identify systems that fall within the MARS-E boundary, implement security and privacy controls based on NIST SP 800-53, maintain documentation such as the System Security Plan (SSP) and Plan of Action and Milestones (POA&M), complete independent security assessments, and obtain an Authority to Operate (ATO). Failure to meet these requirements can result in penalties of up to $25,000 per violation, suspension or revocation of an Authority to Operate (ATO), and restricted access to CMS systems.

CMS has announced that MARS-E is being replaced with the Acceptable Risk Controls for ACA, Marketplace, Privacy, and Enhanced Security (ARC-AMPE) framework. Although many of the security controls are aligned with NIST SP 800-53, organizations must be aware of the change and ensure compliance.

This guide explains what MARS-E compliance is, who must comply, its key security requirements, the assessment process, common documentation, and best practices.

Source: https://qualysec.com/mars-e ...
New York, Technical, MARS-E Compliance Guide: Security Controls, ATO Requirements & ARC-AMPE Transition
واپس جائیں اگلا