Source: www.infosecurity-magazine.com – Author:
California-based Health Net Federal Services (HNFS), a subsidiary of St Louis-based Centene Corporation, has reached an agreement to pay $11,253,400 to resolve allegations of false cybersecurity compliance certifications.
According to the US Department of Justice (DoJ), the false cybersecurity certifications were used to comply with requirements in a US Department of Defense (DoD) contract to administer the Defense Health Agency’s (DHA) TRICARE health benefits program for servicemembers and their families.
HNFS failed to meet certain cybersecurity controls and falsely certified compliance with them in annual reports to DHA between 2015 and 2018, it is alleged.
The reports were required under HNFS’ contract with the DHA to administer the TRICARE program.
It is also alleged that HNFS failed to timely scan for known vulnerabilities and to remedy security flaws on its networks and systems, in accordance with its System Security Plan and the response times HNFS had established.
The firm is also accused of ignoring reports from third-party security auditors and its internal audit department of cybersecurity risks on HNFS’ networks and systems related to asset management; access controls; configuration settings; firewalls; end-of-life hardware and software in use; patch management; vulnerability scanning; and password policies.
“Companies that hold sensitive government information, including sensitive information of the nation’s servicemembers and their families, must meet their contractual obligations to protect it,” said Acting Assistant Attorney General Brett A. Shumate, head of the Justice Department’s Civil Division.
“We will continue to pursue knowing violations of cybersecurity requirements by federal contractors and grantees to protect Americans’ privacy and economic and national security,” he said.
In 2016, Centene acquired all of the issued and outstanding shares of Health Net Inc., HNFS’s corporate parent, and assumed the liabilities of HNFS.
The claims asserted against defendants are allegations only and there has been no determination of liability, the DoJ has noted.
Original Post URL: https://www.infosecurity-magazine.com/news/dod-contractor-pays-false-cyber/
Category & Tags: –
Views: 2