Lazarus Alliance provides independent ARC-AMPE audit, assessment, readiness, gap analysis and compliance services for ACA, Medicaid and CMS partner entities.

Independent ARC-AMPE Security & Privacy Assessments for ACA, Medicaid and Partner Entities

Organizations that exchange sensitive information with the Centers for Medicare & Medicaid Services (CMS) face rigorous cybersecurity, privacy, risk management and continuous monitoring requirements.

Lazarus Alliance provides independent ARC-AMPE audit, assessment, readiness and compliance services to help organizations evaluate their security and privacy controls, identify compliance gaps, prepare required evidence and demonstrate a defensible security and privacy posture.

ARC-AMPE — Acceptable Risk Controls for Affordable Care Act (ACA), Medicaid, and Partner Entities — is the CMS security and privacy framework that succeeds the legacy MARS-E framework.

Organizations that previously maintained MARS-E compliance should evaluate their existing controls, policies, System Security and Privacy Plan (SSPP), assessment evidence and continuous monitoring processes against the ARC-AMPE requirements rather than assuming their previous MARS-E implementation remains sufficient.

Lazarus Alliance helps organizations make that transition efficiently and confidently.

What Is ARC-AMPE?

ARC-AMPE is the CMS security and privacy control framework for applicable ACA Administering Entities, Medicaid organizations and other partner entities that exchange information with CMS systems.

The framework establishes security and privacy requirements designed to protect sensitive information and manage the risks associated with systems connecting to CMS.

ARC-AMPE modernizes the previous CMS compliance approach and aligns its controls with NIST Special Publication 800-53 Revision 5.

The framework incorporates security, privacy and risk-management requirements into an integrated control structure covering areas such as:

  • Access control
  • Identification and authentication
  • Audit and accountability
  • Configuration management
  • Incident response
  • Risk assessment
  • Security assessment and authorization
  • System and communications protection
  • System and information integrity
  • Personally identifiable information processing and transparency
  • Supply-chain risk management
  • Continuous monitoring

For affected organizations, ARC-AMPE compliance is more than a documentation exercise. Controls must be appropriately implemented, supported by evidence and capable of demonstrating that security and privacy risks are being effectively managed.