Health Net Federal Services Pays $11.2M Over False Cybersecurity Claims

Article Highlights
Off On

In a recent development, Health Net Federal Services (HNFS), a subsidiary of Centene Corporation, agreed to an $11.2 million settlement to address accusations of falsely certifying their cybersecurity compliance to the Department of Defense (DoD). HNFS was responsible for implementing cybersecurity controls necessary for managing the Defense Health Agency’s (DHA) TRICARE program between 2015 and 2018. During this period, the company reportedly failed to fulfill several critical cybersecurity requirements yet certified their compliance in annual reports submitted to the DHA. These allegations raised significant concerns about the integrity of contractor compliance and its potential implications for national security.

Allegations and Specific Failings

The accusations directed toward HNFS spanned various aspects of cybersecurity management, including asset management, access controls, configuration settings, and more. It was alleged that HNFS did not address known vulnerabilities in a timely manner, despite being aware of them. Audit warnings regarding cybersecurity risks were systematically ignored, and the company failed to uphold established response times outlined in its System Security Plan. Additionally, issues such as outdated hardware and software, inadequate patch management, and poor vulnerability scanning practices were highlighted in the claims.

To comply with the cybersecurity requirements of their DoD contract, contractors must adopt stringent protocols to protect sensitive data and maintain the system’s security. HNFS’s failure to meet these standards and the subsequent false certifications have significant implications. By not addressing these vulnerabilities adequately and in a timely manner, HNFS potentially exposed sensitive information to risks, contravening the very statutes put in place to safeguard such data. The enforcement of these standards ensures that contractors are consistently held accountable for upholding cybersecurity measures critical for maintaining national security.

Department of Justice’s Stance

Recent developments have seen Health Net Federal Services (HNFS), a Centene Corporation subsidiary, reaching an $11.2 million settlement to resolve accusations of misleadingly certifying their cybersecurity compliance to the Department of Defense (DoD). HNFS was tasked with implementing essential cybersecurity measures for the Defense Health Agency’s (DHA) TRICARE program from 2015 to 2018. Allegedly, the company did not meet several critical cybersecurity requirements during this period, yet still claimed compliance in annual reports to the DHA. This situation has raised significant concerns regarding the integrity of contractor compliance with cybersecurity standards and the potential risks posed to national security. The settlement highlights the importance of rigorous cybersecurity practices and transparent reporting for those contracting with government entities, ensuring national security is not compromised by misrepresentation.

Explore more

Is Huawei Dominating China’s Chip Supply Chain?

The escalating influence of Huawei in China’s semiconductor industry has raised questions about the balance of power within this crucial sector. While the company initially emerged as a leading manufacturer of telecommunications equipment, its strategic expansion into semiconductor manufacturing has turned it into a formidable player in the chip supply chain. Huawei operates more than 11 fabrication plants under various

AMD Unveils Ambitious 2025 CPU Lineup with Ryzen and Threadripper

AMD is making significant strides in its product offerings with a planned expansion of its CPU lineup, suggesting a dynamic trajectory for the company. The spotlight is firmly on the Ryzen 9000G “Gorgon Point” series, which is set to replace the Ryzen 8000G lineup for the AM5 socket. These advanced APUs are designed to incorporate Zen 5 CPU cores alongside

NVIDIA GeForce RTX 5050 Hits Budget Laptops with GDDR7 Boost

The landscape of budget gaming laptops is undergoing a transformative shift as NVIDIA’s GeForce RTX 5050 makes its debut equipped with the latest GDDR7 memory technology. This launch aligns with a growing demand for affordable yet highly capable hardware, altering perceptions regarding the potential of budget-friendly devices in gaming. Manufacturer takeover is evident with LG and Lenovo integrating this potent

Will MSI’s 500Hz Monitors Revolutionize Gaming Performance?

The rapid advancement in gaming technology has catalyzed an era where performance benchmarks are continuously being redefined. MSI has recently made a groundbreaking stride in the gaming monitor arena by introducing two new QD-OLED monitors at Computex. The MPG 271QR X50 and MAG 272QP boast an unprecedented 500Hz refresh rate, marking a significant advancement for 2K QD-OLED displays. This technological

Why Is QTS Expanding Its Dallas Data Center Campus?

In an ever-evolving digital age marked by unprecedented demand for data storage and processing power, the actions of key industry players like QTS are under scrutiny. QTS, a data center provider owned by Blackstone, is embarking on a significant expansion of its Dallas campus. This decision reflects a strategic move to meet the escalating customer demand within a region that