Centers for Medicare & Medicaid Services Company Cyber Security Posture

cms.gov

The Centers for Medicare & Medicaid Services (CMS), a federal agency within the U.S. Department of Health and Human Services, is one of the largest purchasers of health care in the world. Medicare, Medicaid, the Children's Health Insurance Program (CHIP) and the Health Insurance Marketplace provide coverage for more than 160 million Americans. The United States Government does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factor. Federal agencies must provide reasonable accommodation to applicants with disabilities where appropriate.

CM&MS Company Details

Linkedin ID:

centers-for-medicare-&-medicaid-services

Employees number:

6169 employees

Number of followers:

587848.0

NAICS:

922

Industry Type:

Government Administration

Homepage:

cms.gov

IP Addresses:

1282

Company ID:

CEN_1789392

Scan Status:

In-progress

AI scoreCM&MS Risk Score (AI oriented)

Between 900 and 1000

This score is AI-generated and less favored by cyber insurers, who prefer the TPRM score.

Ailogo

Centers for Medicare & Medicaid Services Company Scoring based on AI Models

Model NameDateDescriptionCurrent Score DifferenceScore
AVERAGE-Industry03-12-2025

This score represents the average cybersecurity rating of companies already scanned within the same industry. It provides a benchmark to compare an individual company's security posture against its industry peers.

N/A

Between 900 and 1000

Centers for Medicare & Medicaid Services Company Cyber Security News & History

Past Incidents
7
Attack Types
2
EntityTypeSeverityImpactSeenUrl IDDetailsView
Centers for Medicare & Medicaid Services (CMS)Breach857/2025CEN821071225Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks: Attack which causes leak of personal information of customers ( only if no ransomware )

Description: In June, two major breaches compromised over 13 million patient records. Now, a newly confirmed Medicare data breach has affected more than 100,000 Americans. Hackers accessed sensitive data linked to Medicare.gov accounts, including full names, dates of birth, ZIP codes, Medicare Beneficiary Identifiers (MBIs), Medicare coverage details, home addresses, provider and diagnosis codes, services received, and plan premium details. CMS has deactivated all affected accounts and is mailing new Medicare cards to the estimated 103,000 individuals affected. No confirmed identity theft cases have been reported yet.

Centers for Medicare & Medicaid Services (CMS)Vulnerability8549/2024CEN000091524Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: CMS, in collaboration with its contractor WPS, is addressing a breach where private health information may have been exposed due to a vulnerability in MOVEit software used for Medicare administrative tasks. The incident exposed personal data of Medicare beneficiaries and additional PII for CMS audits. The breach, discovered between May 27 and May 31, 2023, affected approximately 946,801 individuals, leading to notifications being sent to those impacted.

Centers for Medicare & Medicaid ServicesVulnerability8549/2024CEN000100624Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: CMS, along with WPS, is alerting individuals about a potential compromise of protected health information due to a security vulnerability within the MOVEit software. This third-party application's flaw permitted unauthorized access to personal data of Medicare beneficiaries and PII related to CMS healthcare provider audits between May 27 and May 31, 2023. About 946,801 Medicare recipients are being notified of the incident that involves the breach of sensitive data. The breach was brought to CMS's attention on July 8, potentially affecting the privacy of a substantial number of people.

Centers for Medicare & Medicaid Services (CMS)Vulnerability8549/2024CEN001032425Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: In a security incident revealed by CMS and their contractor WPS, personally identifiable information (PII) of Medicare beneficiaries and others may have been compromised due to a vulnerability exploited in the MOVEit software. Information related to the management of Medicare claims and CMS healthcare provider audits was potentially accessed without authorization. This incident, affecting 946,801 individuals, was discovered to have occurred between May 27 and May 31, 2023, leading to a large-scale notification effort.

Centers for Medicare & Medicaid Services (CMS)Vulnerability8549/2024CEN001032925Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: CMS, alongside WPS, is alerting individuals to a breach stemming from a vulnerability in MOVEit software. This incident, detected on July 8, compromised PII of Medicare beneficiaries and others, potentially impacting 946,801 people. The data breach involved information used in Medicare claim management and CMS audits. Personal information was exposed during the unauthorized access that occurred between May 27 and May 31, 2023.

Centers for Medicare & Medicaid Services (CMS)Vulnerability8549/2024CEN001033025Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: On September 6, CMS announced a data breach notification stemming from a security vulnerability in MOVEit, a file transfer application by Progress Software, used by the contractor WPS. This breach potentially affected the sensitive data of around 946,801 Medicare beneficiaries, compromising personal information collected for Medicare claims management and supporting CMS healthcare provider audits. The data may include PII of both Medicare beneficiaries and non-beneficiaries. The breach was detected between May 27 and 31, 2023, with CMS being notified on July 8. Affected individuals are being contacted via mail.

Centers for Medicare & Medicaid Services (CMS)Vulnerability8549/2024CEN001040525Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: CMS and WPS are notifying individuals of a security incident that resulted from a vulnerability in MOVEit software, leading to potential unauthorized access to personal information. This incident has potentially compromised PII of Medicare beneficiaries, impacting Medicare claims management and healthcare provider CMS audits. Approximately 946,801 people with Medicare are being affected with notifications being dispatched.

Centers for Medicare & Medicaid Services Company Subsidiaries

SubsidiaryImage

The Centers for Medicare & Medicaid Services (CMS), a federal agency within the U.S. Department of Health and Human Services, is one of the largest purchasers of health care in the world. Medicare, Medicaid, the Children's Health Insurance Program (CHIP) and the Health Insurance Marketplace provide coverage for more than 160 million Americans. The United States Government does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factor. Federal agencies must provide reasonable accommodation to applicants with disabilities where appropriate.

Loading...

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=centers-for-medicare-&-medicaid-services' -H 'apikey: YOUR_API_KEY_HERE'
newsone

CM&MS Cyber Security News

2025-07-01T23:41:00.000Z
103K Medicare beneficiaries issued new IDs after โ€˜data incidentโ€™ at CMS

More than 100,000 people on Medicare will need a new ID number after a โ€œdata incidentโ€ at the Centers for Medicare & Medicaid Services ledย ...

2025-03-10T07:00:00.000Z
AHA podcast: Critical Condition โ€” Cybersecurity in Rural Hospitals with Microsoft, Part 1

Discuss the unique vulnerabilities rural hospitals face, the latest cyberthreats and actionable strategies to strengthen defenses.

2025-07-02T05:40:24.000Z
CMS data breach potentially affects 103,000 Medicare beneficiaries

Approximately 103000 beneficiaries may have been affected by a data breach in May affecting Medicare.gov accounts, CMS said.

2025-01-16T08:00:00.000Z
EnforceMintz โ€” Healing Healthcare? DOJโ€™s Cybersecurity Enforcement Trained Up for 2025

According to DOJ, Georgia Tech submitted false cybersecurity assessment scores and created a culture of cybersecurity noncompliance, did notย ...

2025-05-20T07:00:00.000Z
The government should invest now in healthcare cybersecurity, says HSCC

Financially constrained hospitals and health systems need federal funding and support to augment their cybersecurity workforces.

2025-03-23T07:00:00.000Z
Health Care: Cyber Attacks, Worrying Trends and Solutions

Cyber threats against hospitals are surging. What steps are being taken by the health-care sector to address the increasing impacts of cyberย ...

2025-01-17T08:00:00.000Z
How HHS has strengthened cybersecurity of hospitals and health care systems

Hospitals and health systems across the country are experiencing a significant rise in cyberattacks. These cyber incidents have caused extendedย ...

2024-09-09T07:00:00.000Z
CMS Notifies People Potentially Impacted by Data Breach

CMS stated that a vulnerability in the MOVEit software allowed unauthorized third parties to access personal information transferred usingย ...

2024-09-09T07:00:00.000Z
MOVEit victims are still coming forward. This time itโ€™s Wisconsin Medicare.

The Texas Dow Employees Credit Union last month notified more than 500,000 people their sensitive data was compromised during an attack on itsย ...

similarCompanies

CM&MS Similar Companies

Salford City Council

Salford City Council exists to serve its residents and provides a complete and comprehensive range of services and facilities. The council's mission statement is "to create the best possible quality of life for the people of Salford." Salford is a city constantly changing and moving into an exciti

Kรธbenhavns Kommune

Kรธbenhavns Kommune er Danmarks stรธrste arbejdsplads med ca. 45.000 medarbejdere. Vi udvikler hovedstaden og servicerer over 500.000 kรธbenhavnere. Vores mรฅl er at fastholde og udvikle Kรธbenhavn som en af verdens bedste byer at bo i โ€“ og skabe รธget vรฆkst gennem viden, innovation og beskรฆftigelse. Fi

Queimados - RJ

NรšMEROS O municรญpio de Queimados ocupa uma รกrea de 76,921 quilรดmetros quadrados e se localiza a 22ยบ42'58" de latitude sul e 43ยบ33'19" de longitude oeste, a uma altitude de 29 metros. A populaรงรฃo aferida na contagem do Instituto Brasileiro de Geografia e Estatรญstica (IBGE), em 2008, foi de 137.870

State of Michigan

Every day the contributions and achievements of State of Michigan employees have a direct impact on over 10 million Michiganders across the state. If you're looking for a fulfilling career in state government that can make a real difference in the lives of others, you can find your place working wit

I WORK FOR SA

The OFFICIAL careers page for the South Australian Government. The South Australian Public Sector is the State's largest workforce. We are an employer of choice that reflects the diverse community we serve. Our people are from a range of backgrounds and vocations, from entry level, mid-career and

Department for Work and Pensions (DWP)

The Department for Work and Pensions (DWP) is the UKโ€™s largest government department and is responsible for welfare, pensions and child maintenance policy. It administers the State Pension and a range of working age, disability and ill health benefits, serving around 20 million customers. DWP is re

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

CM&MS CyberSecurity History Information

How many cyber incidents has CM&MS faced?

Total Incidents: According to Rankiteo, CM&MS has faced 7 incidents in the past.

What types of cybersecurity incidents have occurred at CM&MS?

Incident Types: The types of cybersecurity incidents that have occurred incidents .

Additional Questions

What Do We Measure?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge