Enhancing Cybersecurity in Medicare and VA Through Zero Trust

The Centers for Medicare & Medicaid Services (CMS), as part of the Department of Health and Human Services, plays a crucial role in overseeing major health programs, including Medicare and Medicaid. These programs significantly impact over 160 million people. To effectively manage extensive sensitive data, CMS has adopted cutting-edge zero-trust security frameworks to enhance their risk management strategy.

Wade Zarriello, the acting director of the Infrastructure and User Services Group at CMS, underscores the critical nature of securing data access. "We process over a billion Medicare claims a year," he states. "Maintaining public trust in our secure data systems is a priority. Zero trust is the system that helps us achieve that goal."

CMS has implemented zero trust across four security dimensions: device, network, application, and data. A notable initiative includes an enterprise identity, credential, and access management (ICAM) program aimed at unifying identity systems across the agency. This approach ensures robust cybersecurity in compliance with regulatory requirements.

Enhancing Security Through Zero Trust

Tim Morrow from Carnegie Mellon University highlights the complicated nature of managing identity services within zero-trust environments. He points out the advantages of federating ICAM services as integral to zero trust. This complexity underscores the importance of streamlined identity integration in mitigating compliance challenges.

CMS is not only focused on identity management but also on advancing security through endpoint detection and response (EDR) solutions. By centralizing data logging, CMS enhances its network security and systematically employs threat analysis to tackle emerging claims processing threats.

Zero trust's adoption requires significant adjustments, particularly in managing internal and partner developer access. The collaboration with Zscaler has facilitated adoption by limiting developer access to specific segments, refining underwriting processes with explicit control measures.

Adopting Zero Trust at the VA

The Department of Veterans Affairs (VA) also manages vast data sets under zero-trust principles, as outlined in the Office of Management and Budget's Memorandum M-22-09. Enhanced identity verification and infrastructure modernization are pivotal to the VA’s improved cybersecurity strategy.

Jeff Spaeth, VA's deputy Chief Information Security Officer (CISO), emphasizes ongoing risk-based verification. "Zero trust enhances cybersecurity by transitioning from implicit trust to continuous verification," he remarks, highlighting the challenges posed by outdated systems lacking modern security features.

Within the VA, Microsoft Purview assists in enforcing zero-trust architecture through data classification and monitoring insider risk. The agency's alignment with a continuous threat exposure management (CTEM) framework ensures that security protocols adapt to evolving threats, enhancing claims management and regulatory compliance.

Zarriello articulates the complementary relationship between zero trust and CTEM, stating, "Zero trust is about design and enforcement, while CTEM is about continuous risk reduction." This dual approach fosters security agility, shifting focus from static compliance to proactive threat management, thereby protecting critical systems and services for veterans.