Health Net Federal Services Pays $11.2M Over False Cybersecurity Claims

Article Highlights
Off On

In a recent development, Health Net Federal Services (HNFS), a subsidiary of Centene Corporation, agreed to an $11.2 million settlement to address accusations of falsely certifying their cybersecurity compliance to the Department of Defense (DoD). HNFS was responsible for implementing cybersecurity controls necessary for managing the Defense Health Agency’s (DHA) TRICARE program between 2015 and 2018. During this period, the company reportedly failed to fulfill several critical cybersecurity requirements yet certified their compliance in annual reports submitted to the DHA. These allegations raised significant concerns about the integrity of contractor compliance and its potential implications for national security.

Allegations and Specific Failings

The accusations directed toward HNFS spanned various aspects of cybersecurity management, including asset management, access controls, configuration settings, and more. It was alleged that HNFS did not address known vulnerabilities in a timely manner, despite being aware of them. Audit warnings regarding cybersecurity risks were systematically ignored, and the company failed to uphold established response times outlined in its System Security Plan. Additionally, issues such as outdated hardware and software, inadequate patch management, and poor vulnerability scanning practices were highlighted in the claims.

To comply with the cybersecurity requirements of their DoD contract, contractors must adopt stringent protocols to protect sensitive data and maintain the system’s security. HNFS’s failure to meet these standards and the subsequent false certifications have significant implications. By not addressing these vulnerabilities adequately and in a timely manner, HNFS potentially exposed sensitive information to risks, contravening the very statutes put in place to safeguard such data. The enforcement of these standards ensures that contractors are consistently held accountable for upholding cybersecurity measures critical for maintaining national security.

Department of Justice’s Stance

Recent developments have seen Health Net Federal Services (HNFS), a Centene Corporation subsidiary, reaching an $11.2 million settlement to resolve accusations of misleadingly certifying their cybersecurity compliance to the Department of Defense (DoD). HNFS was tasked with implementing essential cybersecurity measures for the Defense Health Agency’s (DHA) TRICARE program from 2015 to 2018. Allegedly, the company did not meet several critical cybersecurity requirements during this period, yet still claimed compliance in annual reports to the DHA. This situation has raised significant concerns regarding the integrity of contractor compliance with cybersecurity standards and the potential risks posed to national security. The settlement highlights the importance of rigorous cybersecurity practices and transparent reporting for those contracting with government entities, ensuring national security is not compromised by misrepresentation.

Explore more

Is Your Brand Just Automating or Truly Orchestrating?

Digital communication platforms currently possess the power to reach billions in milliseconds, yet this technological prowess often results in brands shouting through digital megaphones while customers desperately seek a single moment of genuine relevance. The modern consumer landscape is no longer satisfied with generic interactions that merely use a first name in an email subject line. Instead, there is a

What Is the New Math of E-Commerce Parcel Economics?

A standard procurement negotiation once focused on the simple lever of volume-based discounts to ensure profitability, but the modern landscape of e-commerce has rendered that linear equation dangerously incomplete. As of 2026, the retail sector is witnessing a profound shift where the traditional metrics of success—negotiated carrier rates and total package counts—no longer tell the full story of a company’s

Why is Buying Group Engagement the Key to B2B Revenue?

The once-reliable image of a singular executive sitting behind a heavy mahogany desk and unilaterally signing off on a multi-million dollar contract has effectively dissolved into the ether of corporate history. In the high-stakes environment of modern commerce, a definitive “yes” rarely originates from a single office; instead, it is the hard-won result of a complex and often invisible consensus

How Is AI-Driven MarTech Redefining Modern ABM?

The high-stakes landscape of B2B sales has undergone a fundamental transformation where the ability to interpret invisible buyer intent is now more valuable than the largest possible marketing budget. In the current marketplace, the distinction between a closed deal and a missed opportunity often rests on milliseconds of data processing rather than weeks of manual research. Account-Based Marketing (ABM) has

How Does Automation Redefine the Modern DevOps Lifecycle?

The seamless orchestration of complex digital environments has evolved to a point where a single code commit can trigger a global cascade of automated events, rendering the traditional, friction-filled manual handshakes between departments entirely obsolete in the competitive high-stakes world of enterprise software delivery. Modern software engineering no longer permits the luxury of week-long deployment cycles or manual server provisioning.