Medicaid and CHIP Program System
Date signed: 6/2/2026
| PIA Questions | PIA Answers |
|---|---|
| OPDIV: | CMS |
| PIA Unique Identifier: | P-5080182-650000 |
| Name: | Medicaid and CHIP Program System |
| The subject of this PIA is which of the following? | Major Application |
| Identify the Enterprise Performance Lifecycle Phase of the system. | Operate |
| Is this a FISMA-Reportable system? | Yes |
| Does the system include a Website or online application available to and for the use of the general public? | Yes |
| Identify the operator: | Contractor |
| Is this a new or existing system? | Existing |
| Does the system have Security Authorization (SA)? | Yes |
| Date of Security Authorization | 2/6/2026 |
| Indicate the following reason(s) for updating this PIA. Choose from the following options. |
|
| Describe in further detail any changes to the system that have occurred since the last PIA. | Medicaid and CHIP (Children’s Health Insurance Program) Program (MACPro) Appian Children's Health Insurance Program Annual Reporting Template System (CARTS) Statistical Enrollment Data System (SEDS) Managed Care Reporting (MCR) No major changes. Quality Measures Reporting (QMR) Money Follows the Person (MFP) Newly added application since the last PIA. MFP now allows saving and submission of report data. One Medicaid and CHIP Program System (OneMAC) OneMAC system was upgraded and moved to a new application and architecture to continue to make it usable going into the future. Managed Care Review (MC-Review) This is the first PIA completed for this project. Newly added application since the last PIA. eRegulations (eRegs) Home & Community Based Services (HCBS) Newly added application since the last PIA. HCBS now allows saving and submission of report data. |
| Describe the purpose of the system | Medicaid and CHIP (Children’s Health Insurance Program) Program (MACPro) Appian MACPro automates the uploading of States’ planning documents (SPD), State Plan Amendments (SPA) and Advanced Planning Documents (APDs), as well as applications and amendments to their Medicaid and CHIP demonstrations, and grant programs. Children's Health Insurance Program Annual Reporting Template System (CARTS) Statistical Enrollment Data System (SEDS) Managed Care Reporting (MCR) MCR is the CMS MDCT reporting application for collecting state-reported data related to Medicaid Managed Care program reports, including Managed Care Program Annual Report (MCPAR), Medical Loss Ratio (MLR), and Network Adequacy and Access Assurances Report (NAAAR). It stores the templates for the three reports, as well as a help page to reach the MDCT help desk. Users access the application via Identity Management System (IDM) and are assigned roles that correspond to their permissions. State users can enter report data and submit data to CMS. Quality Measures Reporting (QMR) Edit: Edit the annual measures based on State and Year selected. Submit: Submit the annual measures based on State and Year selected. View: View the annual measures based on State and Year selected. Export measures to a PDF: Export the answers for the state and year selected to a PDF. Money Follows the Person (MFP) MFP is the CMS MDCT reporting application for collecting state-reported data related to Medicaid Money Follows the Person program reports, including MFP Work Plan (WP), and MFP Semi-Annual Progress Report (SAR). It stores the templates for the three reports, as well as a help page to reach the MDCT help desk. Users access the application via IDM and are assigned roles that correspond to their permissions. State users can enter report data and submit data to CMS. One Medicaid and CHIP Program System (OneMAC) The core function of the OneMAC Foundations application is to establish an automated information system, aimed at replacing the existing manual procedure for submitting, reviewing, and adjudicating State Plan Amendments (SPAs) and Policy Waivers, which currently relies on email-based processes. This innovative system offers a unified platform for submission and review, effectively linking metadata with SPA and Waiver submissions. Furthermore, the system plays a pivotal role in enhancing information dissemination and integration. It seamlessly publishes SPA submission events to the internal MACPro BigMAC system, facilitating real-time updates and tracking. Additionally, the application is designed to transmit user submission data to the SEA Tool system, ensuring a streamlined flow of essential information. Managed Care Review (MC-Review) MC-Review is securely hosted within the Amazon Web Services (AWS) cloud environment, utilizing a robust 3-Zone AWS Security Group setup to manage and route traffic effectively. MC-Review is developed as a Single Page Application using the React framework and statically distributed as a single JavaScript bundle run in users’ browsers. Users authenticate using the CMS Identity Management system (IDM) which allows them to submit and review using the system. The web app calls Application Programming Interface (APIs) served by AWS lambdas which read and write data to an AWS Relational Database Service (RDS) Postgres instance. eRegulations (eRegs) Home & Community Based Services (HCBS) Home & Community Based Services is an application that allows users to access and complete the webforms for Quality Measure Set (QMS), Timely Access Report (TA) and Critical Incident Report (CI), as well as a help page to reach the MDCT help desk. It includes a static landing page that contains information related to each of the reports, due date information, and navigation to the report dashboards and webforms, where users can submit and review data for reports. Users access the application via IDM and are assigned roles that correspond to their permissions. The data collected assists CMCS in monitoring and managing grantee progress and identifying challenges and improvement opportunities. |
| Describe the type of information the system will collect, maintain (store), or share. (Subsequent questions will identify if this information is PII and ask about the specific data elements) | MACPro (Appian) The MACPro system collects and stores Medicaid and CHIP program information such as reports on the quality of care; amendments to the Medicaid and CHIP programs within each state; amendments to the administration and benefits, waiver program, types of medical care delivery systems, payment methods and other related operational information. It does not include any details or identifying information about Beneficiaries or Providers.
CARTS Statistical Enrollment Data System (SEDS) Managed Care Reporting (MCR) The system stores all saved and submitted report data and respective timestamps, along with the name associated with the IDM profile which undertook the action. This data is stored indefinitely. Quality Measures Reporting (QMR) Money Follows the Person (MFP) The system stores all saved and submitted report data and respective timestamps, along with the name associated with the IDM profile which undertook the action. This data is stored indefinitely. One Medicaid and CHIP Program System (OneMAC) First name, Last Name, Company Email, Generic information related to Medicare and Medicaid requests, rewards and statuses. MC-Review Authorize client credentials, stored until manually deleted. session data: stored temporarily for the duration of a user’s session This app indefinitely stores: User account information: full name, IDM role, division assignment and email address. When users need to lose access to the system their IDM roles are revoked. All contract and rate submission form field inputs, uploaded documents and documents meta data. Documents may include questions and answers, and rating information including financial or contract specific information. Contact data on submissions may include full name, title, email address, and actuarial firm name. System configuration settings, such as email notification settings, help desk contact information, and file storage URLs. Submission activity and audit information such as submission history, user activity logs, document access logs etc. All error logs. eRegulations (eRegs) Text and metadata of public regulations and Federal Register documents, retrieved from public Application Program Interface (API)s offered by eCFR and the Federal Register. Metadata about policy-related documents published by CMS, HHS, and other public sources relevant to Medicaid & CHIP, entered by contractors on this team. Credentials for contractors who edit document metadata in this application: username created by a system administrator, and a password created by a system administrator and then immediately changed by the individual. When a contractor leaves the project, a system administrator deactivates the account; the username remains in the system, but the individual cannot log into the account. There are fewer than 15 accounts in this application. Home & Community Based Services (HCBS) The system stores all saved and submitted report data and respective timestamps, along with the name associated with the IDM profile which undertook the action. This data is stored indefinitely. |
| Provide an overview of the system and describe the information it will collect, maintain (store), or share, either permanently or temporarily. | MACPro (Appian) MACPro automates the process for States to submit and amend their Medicaid State Plans, CARTS The AWS accounts will collect, store, and share the same data previously collected, stored, and shared within the existing AWS account. Other than the AWS account, there will be no changes to how the data is stored nor any new data types. Statistical Enrollment Data System (SEDS) This system is complementary to the MDCT CHIP Annual Report Template System (CARTS). SEDS converts an existing paper data collection process into web-based application. It also is designed to provide the reporting and exporting of survey answers into a PDF template Managed Care Reporting (MCR) The application provides state users with the ability to save and submit report data for each of the three MCR reports (MCPAR, MLR, NAAAR). When reported, the gathered information will enable CMCS to better monitor and support state efforts in improving managed care program performance. Data is not requested or stored that pertains to individuals, rather the data requested and stored pertains to state managed care programs and entities. All information is collected in aggregate. Quality Measures Reporting (QMR) MDCT-QMR contains web forms for states input information about their collected data regarding Medicaid and CHIP. Money Follows the Person (MFP) The application provides state users with the ability to save and submit report data for each of the MFP reports (WP, SAR). When reported, the gathered information will enable CMCS to better monitor and support state efforts in improving managed care program performance. Data is not requested or stored that pertains to individuals, rather the data requested and stored pertains to state managed care programs and entities. All information is collected in aggregate. One Medicaid and CHIP Program System (OneMAC) The OneMAC system collects First name, Last Name, Company Email while connecting data from States to help CMCS make informed decisions about program oversight. MC-Review MC-Review facilitates the review and approval of Medicaid managed care contracts and rate certifications between state agencies and the Centers for Medicare & Medicaid Services (CMS). The system collects, maintains, and shares information to support federal oversight of state Medicaid programs and ensure compliance with regulatory requirements. Each state user's data (name, email address, state assignments, activity data) is stored distinguish between users and track submission activities for accountability. Each CMS user's data (name, email address, state assignments, activity data) is stored to distinguish between users, track reviewer actions, and maintain audit trails of federal review decisions. A state user submits contract and or rate data in a submission(s), then the CMS users can see all this data and perform actions on the submission, such as unlocking, or withdrawing it. Question and answer documents provide a way for the state user and CMS user to send questions and corresponding answers back and forth, without using email. State contact data is recorded on submissions to allow CMS to message contacts directly for follow-up questions or otherwise discuss the submission. Rate and actuary information is crucial for the review of rates and for communication with actuaries if questions arise. Rate data is also pulled via an Application Program Interface (API) into the ARMS app for further evaluation. eRegulations (eRegs) The application stores and displays policy-related text and metadata to help CMCS staff users do policy research. CMCS staff and contractors can request EUA job codes with reader, editor, or admin roles. This application integrates with CMS IDM Okta. When a person with an approved job code logs into this application, it retrieves the person's email address and name from IDM and stores it in the application. Contractors on the team use EUA credentials with admin roles, or a unique username and password, to log into the application's metadata editing tool, to help keep the policy-related information up to date for users. CMCS staff may also request editor access and log in to update policy-related information. A system administrator creates a username for each contractor on the team with an abbreviation derived from the contractor's name. The application keeps an audit log of content changes by all users, so that a change can be correlated with an individual user. When offboarding a contractor who has a username and password account, the system administrator deactivates the individual's account, instead of completely deleting it, to preserve the integrity of the audit log. Home & Community Based Services (HCBS) The application provides users with the ability to save and submit report data for each of the HCBS reports (QMS, CI, TACM). When reported, the gathered information will enable CMCS to better monitor and support state efforts in improving managed care program performance. Data is not requested or stored that pertains to individuals, rather the data requested and stored pertains to state managed care programs and entities. All information is collected in aggregate. |
| Does the system collect, maintain, use or share PII? | Yes |
| Indicate the type of PII that the system will collect or maintain. |
|
| Indicate the categories of individuals about whom PII is collected, maintained or shared. |
|
| How many individuals' PII in the system? | 500-4,999 |
| For what primary purpose is the PII used? | MACPro (Appian) The PII data in MACPro is used for following: Username to show Point-Of-Contact, User action information on User Interface and System reports Email address to send notifications Phone number for Helpdesk to reach out to User CARTS N/A Statistical Enrollment Data System (SEDS) N/A Managed Care Reporting (MCR) N/A Quality Measures Reporting (QMR) N/A Money Follows the Person (MFP) N/A One Medicaid and CHIP Program System (OneMAC) The PII data in OneMAC is used for following: Username to show Point-Of-Contact, User action information on User Interface and System reports Email address to send notifications Also used for user access to the application MC-Review Identification for the purpose of tracking the history of actions for audit purposes and accountability for actions completed in the system. eRegulations (eRegs) Enable employees and contractors to have user accounts that allow them to view and manage policy-related documents in the application. Enable associating user accounts with changes to documents and metadata for audit logging purposes. Home & Community Based Services (HCBS) N/A |
| Describe the secondary uses for which the PII will be used (e.g. testing, training or research) | Not Applicable. There is no other secondary use of PII. |
| Describe the function of the SSN. | Not Applicable. There is no use of PII within the application. |
| Cite the legal authority to use the SSN. | Not applicable. There is no use of PII within the application. |
| Identify legal authorities governing information use and disclosure specific to the system and program. | Title 5 (TITLE 5—GOVERNMENT ORGANIZATION AND EMPLOYEES) USC 301, Departmental regulations. |
| Are records on the system retrieved by one or more PII data elements? | No |
| Identify the sources of PII in the system: Directly from an individual about whom the information pertains |
|
| Identify the sources of PII in the system: Government Sources |
|
| Identify the sources of PII in the system: Non-Government Sources | |
| Identify the OMB information collection approval number and expiration date | OMB Control Number: 0938-1188 Expiration Date: 07/31/2027 |
| Is the PII shared with other organizations? | No |
| Describe the process in place to notify individuals that their personal information will be collected. If no prior notice is given, explain the reason. | MACPro (Appian) During the first attempt to register and every time that user accesses the CMS Identity Management System (IDM) and MACPro the user must agree to the Terms & Conditions of the usage. As part of the User Terms & Conditions, it is mentioned that the user should not have any reasonable expectation of privacy regarding any communication or data transiting or stored on these systems. The user data will be monitored, intercepted, searched and seized any communication or data transiting or stored on this system at any time and for any lawful Government purpose. The notification process occurs at the IDM new user registration screen and then subsequently at the user access screen of IDM. CARTS N/A. PII is not collected. Statistical Enrollment Data System (SEDS) N/A, PII is not collected. Managed Care Reporting (MCR) N/A. PII is not collected. Quality Measures Reporting (QMR) N/A. PII is not collected. Money Follows the Person (MFP) N/A. PII is not collected. One Medicaid and CHIP Program System (OneMAC) During the first attempt to register and every time that user accesses the CMS Identity Management System (IDM) and OneMAC the user must agree to the Terms & Conditions of the usage. As part of the User Terms & Conditions, it is mentioned that the user should not have any reasonable expectation of privacy regarding any communication or data transiting or stored on these systems. The user data will be monitored, intercepted, searched and seized any communication or data transiting or stored on this system at any time and for any lawful Government purpose. The notification process occurs at the IDM new user registration screen and then subsequently at the user access screen of IDM. MC-Review The application's notification is carried out by the IDM login system itself. Login is completed via IDM, which requires users to accept the Terms & Conditions, which state clearly that information will be recorded and that there is no reasonable expectation of privacy when using the system. eRegulations (eRegs) This is done via CMS IDM Okta. Home & Community Based Services (HCBS) N/A. PII is not collected. |
| Is the submission of the PII by individuals voluntary or mandatory? | Voluntary |
| Describe the method for individuals to opt-out of the collection or use of their PII. If there is no option to object to the information collection, provide a reason. | MACPro (Appian) The ability to opt-out of the collection of PII is handled at the CMS IDM Okta level. Any individual seeking access must first have an IDM account. The users must accept the Terms & Conditions before accessing the MACPro application. The Terms & Conditions advises the user that they are accessing a U.S. Government system and there should be no reasonable expectation of privacy. CARTS N/A. PII is not collected directly from users. Access is handled via CMS IDM Okta. Users may choose to request access to applications via IDM roles or decline if they don’t want to provide their information/contacts to the application. Statistical Enrollment Data System (SEDS) N/A. PII is not collected directly from users. Access is handled via CMS EUA. Requesting a job code for the application and using the application are both optional. Managed Care Reporting (MCR) N/A. PII is not collected directly from users. Access is handled via CMS IDM Okta. Users may choose to request access to applications via IDM roles or decline if they don’t want to provide their information/contacts to the application. Quality Measures Reporting (QMR) N/A. PII is not collected directly from users. Access is handled via CMS IDM Okta. Users may choose to request access to applications via IDM roles or decline if they don’t want to provide their information/contacts to the application. Money Follows the Person (MFP) N/A. PII is not collected directly from users. Access is handled via CMS IDM Okta. Users may choose to request access to applications via IDM roles or decline if they don’t want to provide their information/contacts to the application. One Medicaid and CHIP Program System (OneMAC) N/A. PII is not collected directly from users. Access is handled via CMS IDM Okta. Users may choose to request access to applications via IDM roles or decline if they don’t want to provide their information/contacts to the application. MC-Review PII is not collected directly from users. Access is managed through CMS IDM Okta. Users may opt out by declining to provide their email address; however, an email address is required to enable system generated notifications and to allow CMS users to contact state users associated with a submission under review. eRegulations (eRegs) PII is not collected directly from users. Requesting a job code for the application and using the application are both optional. Home & Community Based Services (HCBS) N/A. PII is not collected directly from users. Access is handled via CMS IDM Okta. Users may choose to request access to applications via IDM roles or decline if they don’t want to provide their information/contacts to the application. |
| Describe the process to notify and obtain consent from the individuals whose PII is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changes since the notice at the time of original collection). Alternatively, describe why they cannot be notified or have their consent obtained. | The ability to opt out of the collection of PII is managed at the CMS IDM Okta level. Any individual seeking access to the application must first establish an IDM account. When a user submits a job code or IDM role request to obtain access, their user details and contact information are transmitted to the application through IDM/EUA. This contact information is used to notify system users of major changes to the system, including changes to disclosures or data uses. Consent to collect and use PII is obtained as part of the IDM account creation and access request process. |
| Describe the process in place to resolve an individual's concerns when they believe their PII has been inappropriately obtained, used, or disclosed, or that the PII is inaccurate. If no process exists, explain why not. | Individuals who believe their PII has been inappropriately obtained, used, disclosed, or is inaccurate may contact the CMS IDM/EUA Help Desk by phone or email to report their concerns. The CMS IDM/EUA Help Desk documents the issue, investigates the concern in accordance with CMS policies and procedures, and coordinates with appropriate system owners or security personnel as needed to resolve the issue and help the individual. |
| Describe the process in place for periodic reviews of PII contained in the system to ensure the data's integrity, availability, accuracy and relevancy. If no processes are in place, explain why not. | Periodic reviews of PII contained in the system are conducted to ensure data integrity, availability, accuracy, and relevancy. User PII is sourced from CMS IDM Okta/EUA and is reviewed as part of routine access management activities, including role validation, access recertification, and account maintenance. System administrators and authorized CMS personnel monitor user access and associated PII to ensure it remains accurate and relevant to the user’s role. Inactive or outdated accounts are reviewed and deactivated in accordance with CMS policies, and any identified discrepancies are addressed promptly to maintain data quality and integrity. |
| Identify who will have access to the PII in the system and the reason why they require access. |
|
| Describe the procedures in place to determine which system users (administrators, developers, contractors, etc.) may access PII. | PII is not collected directly from users. Access is handled via CMS IDM Okta. System users, including administrators, developers, and contractors, are granted access based on role-based access controls and the principle of least privilege. Users must have a validated business need for access, and access requests are approved through the IDM/EUA process by authorized CMS officials. User roles and permissions determine the level of PII access granted. Access is reviewed periodically during access recertification and account maintenance, and permissions are modified or revoked promptly when no longer required. |
| Describe the methods in place to allow those with access to PII to only access the minimum amount of information necessary to perform their job. | Access to PII is controlled through role-based access controls and the principle of least privilege. Users, administrators, and contractors are granted only the minimum level of access necessary to perform their job functions. System permissions are assigned based on approved roles in CMS IDM/Okta role and EUA job code. Access is regularly reviewed through access recertification processes |
| Identify training and awareness provided to personnel (system owners, managers, operators, contractors and/or program managers) using the system to make them aware of their responsibilities for protecting the information being collected and maintained. | Personnel using the system, including system owners, managers, operators, contractors, and program managers, are provided with comprehensive role-based training to ensure awareness of their responsibilities for protecting information collected and maintained by the system. Training addresses management, operational, and technical roles and responsibilities and covers physical, personnel, and technical safeguards and countermeasures. In addition, users are required to complete CMS privacy and security awareness training on an annual basis as a condition of continued system access. |
| Describe training system users receive (above and beyond general security and privacy awareness training) | Personnel using the system, including system owners, managers, operators, contractors, and program managers, are provided with comprehensive role-based training to ensure awareness of their responsibilities for protecting information collected and maintained by the system. Training addresses management, operational, and technical roles and responsibilities and covers physical, personnel, and technical safeguards and countermeasures. In addition, users are required to complete CMS privacy and security awareness training on an annual basis as a condition of continued system access. |
| Do contracts include Federal Acquisition Regulation and other appropriate clauses ensuring adherence to privacy provisions and practices? | Yes |
| Describe the process and guidelines in place with regard to the retention and destruction of PII. Cite specific records retention schedules. | MACPro follows the National Archives and Records Administration (NARA) General Records Schedule (GRS) 3.1, which states that records will be destroyed after five years. The Medicaid and CHIP program information follows the CMS Records Schedule Section V. Medicaid, G. Medicaid State Plans & Amendments. It outlines several schedules that range from destroying "when no longer needed" to up to retaining for seven years and then destroying the records. |
| Describe, briefly but with specificity, how the PII will be secured in the system using administrative, technical, and physical controls. | PII in the system is protected through a combination of administrative, technical, and physical controls. Administrative: Administrative controls include CMS policies and procedures, role-based access approvals through CMS IDM Okta, annual privacy and security training requirements, and periodic access reviews. Technical: Technical controls include role-based access controls, authentication via IDM Okta, encryption of data in transit and at rest, audit logging, and system monitoring to detect unauthorized access or activity. Physical: Physical controls include CMS-approved data center protections, such as facility access controls, surveillance, and environmental safeguards, which prevent unauthorized physical access to system infrastructure. |
| Identify the publicly-available URL: | MACPro (Appian) CARTS Statistical Enrollment Data System (SEDS) Managed Care Reporting (MCR) Quality Measures Reporting (QMR) Money Follows the Person (MFP) One Medicaid and CHIP Program System (OneMAC) MC-Review eRegulations (eRegs) N/A – Internal to CMS only Home & Community Based Services (HCBS) |
| Does the website have a posted privacy notice? | Yes |
| Is the privacy policy available in a machine-readable format? | Yes |
| Does the website use web measurement and customization technology? | No |
| Does the website have any information or pages directed at children under the age of thirteen? | No |
| Does the website contain links to non-federal government website external to HHS? | No |
Privacy Impact Assessment (PIA) published by CMS as an Operating Division of the U.S. Department of Health and Human Services