Reston, Virginia-based ASRC Federal Data Solutions LLC, a contractor for the Centers for Medicare and Medicaid Services, has agreed to settle False Claims Act allegations related to its storage of unsecured personally identifiable information of Medicare beneficiaries.
Under the resolution, ASRC Federal Data Solutions LLC will pay $306,722. The company will also waive any rights to reimbursement for remediating a data breach involving the information, including at least $877,578 in costs it incurred notifying beneficiaries and providing credit monitoring.
“Government contractors that handle personal information must take required steps to safeguard that information from cyberattacks,” said Principal Deputy Assistant Attorney General Brian M. Boynton. “We will vigilantly pursue contractors that fail to comply with required cybersecurity protocols, while at the same time extending cooperation credit where warranted for self-disclosure, cooperation and remediation.”
ASRC Federal Data Solutions LLC provided certain Medicare support services under a contract with the Centers for Medicare and Medicaid Services. The settlement resolves allegations that from March 10, 2021, through Oct. 8, 2022, the company and a subcontractor stored screenshots from CMS systems containing personally identifiable information and potentially personal health information of Medicare beneficiaries on the subcontractor’s server without individually encrypting the files to protect them against exposure in the event of a breach.
The subcontractor’s server employed disk-level encryption that protected files from unauthorized access but not from access using authorized credentials. The subcontractor’s server was breached by a third party in October 2022 and the unencrypted screenshots were allegedly compromised during that breach.
The United States alleged that the storing of screenshots on the subcontractor’s server violated ASRC Federal Data Solutions LLC’s contractual cybersecurity requirements, and that the company knowingly billed CMS in violation of these requirements.
“Safeguarding patients’ sensitive personal information is of paramount importance,” said Special Agent in Charge Stephen Niemczak of the Department of Health and Human Services Office of the Inspector General. “This settlement demonstrates the commitment by HHS-OIG and our law enforcement partners to use every available tool to protect the health care data of all Americans and to investigate allegations of fraud, waste and abuse against the public and taxpayer-funded health care programs.”
Related Federal Cases
- Sean Andrew Duncan, Obstruction of Terrorism Investigation, Virginia 2016 · Washington
- John Edgar Rust, Transmitting Threats, Virginia 2015 · Arkansas
- Julian Paul Assange, Espionage Conspiracy, Virginia 2023 · North Carolina
- Joseph Bourabah, Cyberstalking, Virginia 2022 · Alabama
- Ebuka Raphael Umeti, BEC Scheme, Virginia 2024 · Colorado
Key Facts
- State: Virginia
- Category: Cybercrime
- Source: DOJ Press Release â†â€â€
ðŸâ€Â’ Get the grimiest stories delivered weekly. Subscribe free →

