Health Net Federal Services Pays $11.2M Over False Cybersecurity Claims

Article Highlights
Off On

In a recent development, Health Net Federal Services (HNFS), a subsidiary of Centene Corporation, agreed to an $11.2 million settlement to address accusations of falsely certifying their cybersecurity compliance to the Department of Defense (DoD). HNFS was responsible for implementing cybersecurity controls necessary for managing the Defense Health Agency’s (DHA) TRICARE program between 2015 and 2018. During this period, the company reportedly failed to fulfill several critical cybersecurity requirements yet certified their compliance in annual reports submitted to the DHA. These allegations raised significant concerns about the integrity of contractor compliance and its potential implications for national security.

Allegations and Specific Failings

The accusations directed toward HNFS spanned various aspects of cybersecurity management, including asset management, access controls, configuration settings, and more. It was alleged that HNFS did not address known vulnerabilities in a timely manner, despite being aware of them. Audit warnings regarding cybersecurity risks were systematically ignored, and the company failed to uphold established response times outlined in its System Security Plan. Additionally, issues such as outdated hardware and software, inadequate patch management, and poor vulnerability scanning practices were highlighted in the claims.

To comply with the cybersecurity requirements of their DoD contract, contractors must adopt stringent protocols to protect sensitive data and maintain the system’s security. HNFS’s failure to meet these standards and the subsequent false certifications have significant implications. By not addressing these vulnerabilities adequately and in a timely manner, HNFS potentially exposed sensitive information to risks, contravening the very statutes put in place to safeguard such data. The enforcement of these standards ensures that contractors are consistently held accountable for upholding cybersecurity measures critical for maintaining national security.

Department of Justice’s Stance

Recent developments have seen Health Net Federal Services (HNFS), a Centene Corporation subsidiary, reaching an $11.2 million settlement to resolve accusations of misleadingly certifying their cybersecurity compliance to the Department of Defense (DoD). HNFS was tasked with implementing essential cybersecurity measures for the Defense Health Agency’s (DHA) TRICARE program from 2015 to 2018. Allegedly, the company did not meet several critical cybersecurity requirements during this period, yet still claimed compliance in annual reports to the DHA. This situation has raised significant concerns regarding the integrity of contractor compliance with cybersecurity standards and the potential risks posed to national security. The settlement highlights the importance of rigorous cybersecurity practices and transparent reporting for those contracting with government entities, ensuring national security is not compromised by misrepresentation.

Explore more

How Is Silk Typhoon Targeting Cloud Systems in North America?

In the ever-evolving world of cybersecurity, few threats are as persistent and sophisticated as state-linked hacker groups. Today, we’re diving deep into the activities of Silk Typhoon, a China-nexus espionage group making waves with their targeted attacks on cloud environments. I’m thrilled to be speaking with Dominic Jainy, an IT professional with extensive expertise in artificial intelligence, machine learning, and

Why Is Small Business Data a Goldmine for Cybercriminals?

What if the greatest danger to a small business isn’t a failing economy or fierce competition, but an invisible predator targeting its most valuable asset—data? In 2025, cybercriminals are zeroing in on small enterprises, exploiting their often-overlooked vulnerabilities with devastating precision. A single breach can shatter a company’s finances and reputation, yet many owners remain unaware of the looming risk.

Is the Traditional CDP Obsolete? Meet Customer Data Fabric

As we dive into the evolving world of marketing technology, I’m thrilled to sit down with Aisha Amaira, a seasoned MarTech expert whose passion for integrating technology into marketing has helped countless businesses unlock powerful customer insights. With her deep expertise in CRM marketing technology and customer data platforms, Aisha is the perfect guide to help us understand the shift

Trend Analysis: AI-Driven Cloud Security Solutions

In an era where cyber threats evolve at an unprecedented pace, with over 53% of IT leaders reporting a surge in AI-driven attacks as revealed by the latest Hybrid Cloud Security Survey, the digital landscape stands at a critical juncture, demanding innovative solutions. The proliferation of hybrid cloud environments has amplified vulnerabilities, making traditional security measures insufficient against sophisticated adversarial

SEO 2026: Navigating AI Threats and Original Content Wins

What happens when machines start outranking humans in the digital race for attention? As search engines evolve at lightning speed, artificial intelligence (AI) is rewriting the rules of search engine optimization (SEO), leaving professionals scrambling to adapt. By 2026, the battle for visibility could hinge on a single factor: the ability to balance cutting-edge technology with the irreplaceable value of