Skip to main content
U.S. flag

An official website of the United States government

Return to Search

CMS Information Security and Privacy Acceptable Risk Safeguards (ARS)

Guidance for this document provides guidance to CMS and its contractors as to the minimum acceptable level of required security controls (i.e., the minimum security and privacy control baselines, collectively known as the CMS Minimum Security Requirement [CMSR] baselines) that must be implemented by CMS and CMS contractors to protect CMS’ information and information systems, including CMS Sensitive Information.

Download the Guidance Document

Issued by: Centers for Medicare & Medicaid Services (CMS)

Issue Date: November 21, 2017

HHS is committed to making its websites and documents accessible to the widest possible audience, including individuals with disabilities. We are in the process of retroactively making some documents accessible. If you need assistance accessing an accessible version of this document, please reach out to the guidance@hhs.gov.

DISCLAIMER: The contents of this database lack the force and effect of law, except as authorized by law (including Medicare Advantage Rate Announcements and Advance Notices) or as specifically incorporated into a contract. The Department may not cite, use, or rely on any guidance that is not posted on the guidance repository, except to establish historical facts.