Skip to main content

Medicaid Drug Programs

Date signed: 4/21/2026

PIA information for the Medicaid Drug Programs 
PIA QuestionsPIA Answers
OPDIV:CMS
PIA Unique Identifier:P-9577496-276883
Name:Medicaid Drug Programs
The subject of this PIA is which of the following?Major Application
Identify the Enterprise Performance Lifecycle Phase of the system.Operate
Is this a FISMA-Reportable system?Yes
Does the system include a Website or online application available to and for the use of the general public?Yes
Identify the operator:Agency
Is this a new or existing system?Existing
Does the system have Security Authorization (SA)?Yes
Date of Security Authorization6/27/2025
Indicate the following reason(s) for updating this PIA. Choose from the following options.
  • PIA Validation (PIA Refresh/Annual Review)
Describe in further detail any changes to the system that have occurred since the last PIA.There have not been any business or operational changes to MDP since its latest PIA update.
Describe the purpose of the systemMedicaid Drug Programs (MDP) is the modernized solution for Center of Medicare and Medicaid Services (CMS), states, and drug manufacturers to manage and oversee the Medicaid Drug Rebate program to ensure that Medicaid drug expenses comply with Federal regulations and statutes. MDP has assumed responsibility and business functions previously provided by the legacy Medicaid Drug Rebate (MDR) system, Federal Upper Limit pricing (FUL) processes, annual Drug Utilization Review survey and report (DUR), and the Branded Prescription Drugs (BPD) processes with the Internal Revenue Service (IRS). The MDP Product improves upon the technology, functionality, and efficiency of the existing out-patience prescription drug reporting processes and the continuous development of this product will further improve analysis, data sharing, program monitoring, impact analysis, metrics, program-to-operations comparisons, state-to-state comparisons, and the support manufacturers and other stakeholders receive. MDP will provide CMS with the ability to properly oversee the Medicaid Drug Programs while providing support to drug manufacturing companies and state agencies, and data to the IRS for the Branded Prescription Drug program. The MDP product supports rebate agreement administration, product, monthly pricing and the quarterly data file submission process, state data submissions processes; drug utilization review process, drug utilization discrepancy process, federal upper limit calculation process; and rebate calculation process.
Describe the type of information the system will collect, maintain (store), or share. (Subsequent questions will identify if this information is PII and ask about the specific data elements)The system will collect and store user credentialing information (user ID, username, user email address), however, the user's access to the application is validated by the CMS Enterprise Portal through CMS Identity Management (IDM). IDM is covered by its own Privacy Impact Assessment. The system also collects Drug Manufacturer Information (Drug Product and confidential drug pricing data per OMB #0938-0578 (Expiration: 06/30/2026), OMB No. 0938-0582 (Expires 06/30/2027), OMB No. 0938-0659 (Expires 06/30/2026); and stores State Drug Utilization Information (State Drug Utilization data). The system also collects phone numbers, mailing addresses and names. The users of the system are CMS Employees, Drug Manufacturers, and States.
Provide an overview of the system and describe the information it will collect, maintain (store), or share, either permanently or temporarily.The product and quarterly pricing data that is collected by MDP is used to calculate quarterly rebate amounts that drug manufacturers pay to the states, who in turn collect the Federal and State Government's portion. The product and monthly pricing data also is used to determine the Federal Upper Limit (FUL) amounts. The state drug utilization data does not contain confidential data fields. The data is stored in MDP for use by CMS, States and drug manufacturers to verify utilization, reflected on state drug rebate invoices.
Does the system collect, maintain, use or share PII?Yes
Indicate the type of PII that the system will collect or maintain.
  • Name
  • E-Mail Address
  • Mailing Address
  • Phone Numbers
  • Other - User ID, Username
Indicate the categories of individuals about whom PII is collected, maintained or shared.
  • Employees
  • Vendors/Suppliers/Contractors
  • Other - Direct Contractors & Internal Users
How many individuals' PII in the system?500-4,999
For what primary purpose is the PII used?The PII is required to create a user account within IDM which allows the user to access the application. During the rebate collection process, contact information is captured, several of which already reside in IDM. Contact information may be listed in National Drug Rebate Agreements as a part of the drug rebate process that may not be MDP users.
Describe the secondary uses for which the PII will be used (e.g. testing, training or research)There is not a secondary use for PII.
Describe the function of the SSN.Not Applicable
Cite the legal authority to use the SSN.Not Applicable
Identify legal authorities​ governing information use and disclosure specific to the system and program.5 USC 301, Departmental Regulations
Are records on the system retrieved by one or more PII data elements?No
Identify the sources of PII in the system: Directly from an individual about whom the information pertains
  • In-person
  • Online
  • Email
Identify the sources of PII in the system: Government Sources
  • Within the OPDIV
Identify the sources of PII in the system: Non-Government Sources
  • Private Sector
Identify the OMB information collection approval number and expiration date
  • OMB No. 0938-0582 (Expires 06/30/2027)
  • OMB No. 0938-0659 (Expires 12/31/2027)
  • OMB No. 0938-0578 (Expires 06/30/2026)
Is the PII shared with other organizations?No
Describe the process in place to notify individuals that their personal information will be collected. If no prior notice is given, explain the reason.Users are notified as part of the process to access CMS systems that PII will be collected.
Is the submission of the PII by individuals voluntary or mandatory?Voluntary
Describe the method for individuals to opt-out of the collection or use of their PII. If there is no option to object to the information collection, provide a reason.A system notification banner is displayed when users log into the IDM Portal which explains that you are agreeing to be monitored while using the MDP system. When users accept the conditions and continue to log in, this shows acceptance of the conditions within the warning. Non-acceptance of the conditions will not allow users to proceed with accessing the MDP application or any data within. The PII being collected is limited to name and email address for federal employees, direct contractors, and other users of MDP.
Describe the process to notify and obtain consent from the individuals whose PII is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changes since the notice at the time of original collection). Alternatively, describe why they cannot be notified or have their consent obtained.If changes occur regarding the collection or handling of PII related to MDP. CMS and IDM will adopt measures to provide any required notice and obtain consent from individuals regarding the collection and/or use of PII. This may include e-mail to individuals, adding or updating online notices, or other available means to inform the individual.
Describe the process in place to resolve an individual's concerns when they believe their PII has been inappropriately obtained, used, or disclosed, or that the PII is inaccurate. If no process exists, explain why not.In the event an employee believes that their PII has been inappropriately obtained, used, or disclosed, the employee may contact the CMS IT Service Desk to report an incident via email or by phone. If external users of the MDP system believe their PII has been inappropriately used, they would be instructed to contact the MDP Help Desk.
Describe the process in place for periodic reviews of PII contained in the system to ensure the data's integrity, availability, accuracy and relevancy. If no processes are in place, explain why not.MDP relies on IDM to perform periodic reviews of PII stored within the IDM system. Contractor support staff do not have direct access to this PII. When the data reaches internal MDP systems, only limited support personnel with strict need-to-know, have the ability to access this information.
Identify who will have access to the PII in the system and the reason why they require access.
  • Administrators: CMS Administrators only. PII will be used exclusively by MDP for identification, and confirmation, only. These administrators have gone through the CMS background investigation and onboarding processes for the level of clearance that is appropriate for the work that they perform.
  • Contractors: Direct Contractors in their roles as administrators or developers may have access to PII to research system issues and perform system functionality.
Describe the procedures in place to determine which system users (administrators, developers, contractors, etc.) may access PII.Individuals designated as administrators of the MDP system may access PII. Accessing PII is limited in accordance with the least privilege and need-to-know principles.
Describe the methods in place to allow those with access to PII to only access the minimum amount of information necessary to perform their job.MDP uses the principle of least privilege as well as a role based access control to ensure system administrators, and users are granted access on a "need-to-know" and "need-to-access" commensurate with their assigned duties. Any anomalies are addressed and resolved by the IDM team.  Activities of all users including system administrators are logged by internal CMS security monitoring tools which we inherit services from. If any abnormal behavior is detected, the MDP Information System Security Officers (ISSOs) are notified to perform further investigation related to the activity.
Identify training and awareness provided to personnel (system owners, managers, operators, contractors and/or program managers) using the system to make them aware of their responsibilities for protecting the information being collected and maintained.All users are required to complete the annual CMS Information System Security and Privacy Awareness (ISSPA) training which covers the basics of information security and privacy. This training is performed during the onboarding process of CMS personnel and contractor staff and annually thereafter.
Describe training system users receive (above and beyond general security and privacy awareness training)CMS employees and direct contractors that have a security/ISSO role are required to provide evidence of role-based training to meet continuous education requirements commensurate with their role.
Do contracts include Federal Acquisition Regulation and other appropriate clauses ensuring adherence to privacy provisions and practices?Yes
Describe the process and guidelines in place with regard to the retention and destruction of PII. Cite specific records retention schedules.

MDP adheres to CMS Security Policies to ensure the confidentiality, integrity, and availability of PII. This includes FIPS 140-2/3 compliant encryption, role-based access controls, and chain of custody processes.

National Archives & Record Administration (NARA) record retention parameters are detailed below:

CMS Bucket 3 – Programmatic Financial Records - DAA-0440-2015-0004-0001

Financial Records (non-GRS), regardless of CMS Program. Includes Medicare Part A, Part B, Part C, and Part D; Medicaid; CHIP; Affordable Health Care Act.

Temporary - Destroy no sooner than 7 year(s) after cutoff but longer retention is authorized

GRS 3.1 Item 51 – Data Administration Records – DAA-GRS-2013-0005-0003

All documentation for temporary electronic records and documentation not necessary for preservation of permanent records. Data administration records and documentation relating to electronic records that are scheduled as temporary in the GRS or in a NARA-approved agency schedule or any types of data administration records not listed as permanent in item DAA-GRS-2013-0005-0002.

Temporary - Destroy 5 years after the project/activity/ transaction is completed or superseded, or the associated system is terminated, or the associated data is migrated to a successor system, but longer retention is authorized if required for business use.

Describe, briefly but with specificity, how the PII will be secured in the system using administrative, technical, and physical controls.

Administrative: Only designated personnel will have accounts within the MDP system and access control will be implemented based on the user's role. 

Technical: Sensitive data, including PII, are required to meet federal encryption standards during transmission and storage. 

Physical: Details are provided in the MDP SSP under controls CM-6, SC-28, and SI-7. These standards are assessed annually or every three years during CMS Cybersecurity and Risk Assessment Program (CSRAP) assessments to confirm compliance.

Identify the publicly-available URL:CMS Enterprise Portal
Does the website have a posted privacy notice?Yes
Is the privacy policy available in a machine-readable format?Yes
Does the website use web measurement and customization technology?Yes
Select the type of website measurement and customization technologies is in use and if is used to collect PII. (Select all that apply)
  • Session Cookies - Collects PII?: No
  • Persistent Cookies - Collects PII?: No
Does the website have any information or pages directed at children under the age of thirteen?No
Does the website contain links to non-federal government website external to HHS?No

Privacy Impact Assessment (PIA) published by CMS as an Operating Division of the U.S. Department of Health and Human Services