CMS pivots to risk‑based cybersecurity
- On August 5, 2026, CMS and Labcorp highlighted cybersecurity from different angles: federal risk management on one side and breach liability on the other. - Keith Busby said CMS is moving beyond compliance-based security toward “threat-informed, risk-based defense,” while Labcorp agreed to a $35 million AMCA settlement. - The next milestones are the Labcorp settlement’s August 20 final approval hearing and the September 3, 2026 claims deadline.
The Centers for Medicare and Medicaid Services is shifting its cybersecurity program away from a checklist model and toward what its chief information security officer, Keith Busby, described as a risk-based approach tied to active defense. In a separate case, Labcorp agreed to a $35 million settlement tied to the AMCA data breach, a long-running dispute over patient information exposed through a third-party collections vendor. The two developments were disclosed in separate reports this week. Together, they put federal cyber policy and private-sector breach liability on the same page for healthcare data systems. ### What exactly did CMS say it is changing? Keith Busby said CMS is moving away from “compliance-based cybersecurity” and toward directly linking regulatory adherence with active defense, according to ExecutiveGov’s report on remarks he made this week. Federal News Network separately described the approach as “threat-informed, risk-based defense,” framing it as an effort to connect compliance requirements with operational security work. (executivegov.com) CMS already publishes a Cyber Risk Management Plan and maintains programs for continuous diagnostics, risk assessment, penetration testing and incident response through its information security and privacy program. The agency’s public security portal says those programs are used to assess, mitigate and monitor cyber risks across FISMA systems. ### Why does that matter for a healthcare agency? CMS oversees systems tied to Medicare, Medicaid and other federal health programs, and its security program covers risk management, privacy, breach response and ongoing authorization for information systems. (executivegov.com) The agency’s public materials show cybersecurity and privacy controls are built into system oversight rather than treated as a separate back-office function. Federal News Network reported that Busby’s comments were made in the context of making compliance support operational defense rather than stand apart from it. (security.cms.gov) That framing matters because healthcare agencies handle patient, payment and claims data that move through multiple systems and vendors. ### What happened in the Labcorp case? (security.cms.gov) Labcorp agreed to a $35 million settlement to resolve litigation tied to the 2018 AMCA breach, according to HIPAA Journal and other reports tracking the case. The claims arose after a cyberattack at American Medical Collection Agency, a third-party billing and collections vendor, exposed personal and medical information connected to Labcorp patients. (federalnewsnetwork.com) HIPAA Journal reported that the incident affected more than 10 million Labcorp patients. News reports on the settlement said eligible consumers may seek an estimated cash payment, reimbursement for documented losses and monitoring benefits, subject to court approval and claims procedures. ### How does a vendor breach become a laboratory issue? American Medical Collection Agency was not the laboratory that performed the testing, but it sat in the billing and collections chain for patient accounts tied to laboratory services. (hipaajournal.com) The settlement reporting says the litigation focused on information shared with that outside vendor, underscoring how exposure can occur beyond the bench or the instrument. CMS’s own security framework points to the same broader problem from the government side: risk has to be assessed across systems, owners, safeguards and continuous monitoring, not only at the point where data is first created. That is an inference from CMS’s published risk-management structure and the vendor-breach facts reported in the Labcorp case. ### What are the next concrete dates to watch? The AMCA settlement’s final approval hearing is scheduled for August 20, 2026, according to settlement-tracking reports, and the deadline to file a claim is September 3, 2026. (msn.com) Payments would be distributed only after final approval and any appeals are resolved, according to those reports. (recordinglaw.com) (security.cms.gov)