Accelerating and Enhancing Access to Critical Medical Benefits for Low-Income Individuals & Families 

Overview

The Centers for Medicare & Medicaid Services (CMS) administers key U.S. healthcare programs, including Medicaid, CHIP, and the Basic Health Program (BHP). The Center for Medicaid and CHIP Services (CMCS) oversees Medicaid and CHIP, providing health coverage to low-income individuals and families. Medicaid covers low-income people, CHIP provides health coverage for children in families with incomes too high for Medicaid, and BHP offers affordable coverage for those with fluctuating incomes. CMCS manages Medicaid.gov and InsureKidsNow.gov to provide critical information about eligibility, benefits, application processes, and policy updates to millions of users.

Goal

To modernize CMS’s website infrastructure, enhance security, improve user experience, and ensure compliance with accessibility and federal regulations by upgrading to the latest Drupal versions, implementing Agile and DevSecOps practices, and leveraging cloud technologies for scalability and reliability. This initiative aimed to streamline content deployment, optimize business processes, and maintain the highest standards of security and accessibility for Medicaid, CHIP, and BHP users.

Challenge

Administering benefits through Medicaid, CHIP, and BHP is complex and constantly evolving due to policy changes, budget constraints, health crises, outdated technology, and growing user expectations. Sky Solutions led a website modernization to address these challenges, including outdated infrastructure, security vulnerabilities, inefficient processes, and accessibility issues. The existing Drupal-based CMS limited capabilities, impacting the delivery of updates and features. Compliance risks, ineffective collaboration, and performance issues further hindered progress. A comprehensive overhaul was needed to align with modern cloud technologies, improve user experience, and ensure compliance with security standards.

Solutions

To address these challenges, Sky initiated a comprehensive modernization effort. We tackled the outdated technology stack by migrating to the latest Drupal versions and implementing advanced technologies such as ServiceNow to enhance performance and security. Additionally, we introduced an Agile and DevSecOps culture that streamlined business processes therefore facilitating faster development cycles and improved collaboration. We also optimized content deployment processes, ensuring the rapid dissemination of up-to-date information. With security being of the utmost importance, Sky implemented robust measures to ensure compliance with ATO and FISMA requirements, along with significant infrastructure upgrades that leveraged cloud-based solutions on AWS to enhance scalability and reliability.

Sky embarked on a comprehensive modernization journey targeting various facets critical to transforming the landscape. At the forefront was the cultivation of an Agile and DevSecOps culture, introducing automation that streamlined processes, significantly reducing the time and effort required for new feature delivery and content posting. To fortify compliance and security measures, robust cloud and platform management strategies were implemented. Governance standards were established to ensure adherence to regulations and security requirements, alongside the execution of a meticulously devised cloud strategy for Acquia cloud Drupal version upgrades. This initiative also encompassed migrating legacy business processes to the ServiceNow digital workflow platform, optimizing operational efficiency.

An equally vital focus was the ability to maintain stringent compliance with accessibility standards and regulations. Sky diligently ensured compliance with a spectrum of stringent standards, including U.S. Web Design/DigitalGov, OMB Federal Web Standards, CMS and HHS policies, and W3C Web Accessibility Initiative (WAI) standards. Upholding Section 508 of the Rehabilitation Act was pivotal, demonstrating a commitment to inclusivity and accessibility for all users.

Security was paramount in the transformational journey, with Sky implementing robust controls and mechanisms to safeguard data and content. Rigorous security measures included regular application of patches and upgrades to minimize the risk of data breaches. Further fortification involved establishing comprehensive processes and tools for encryption, network security, and threat detection, significantly mitigating potential risks and vulnerabilities.

Sky strategically engineered a robust CI/CD pipeline, ushering in a DevOps culture and embracing test-driven development methodologies. The integration of security and compliance tools into the CI/CD pipeline ensured proactive identification and resolution of vulnerabilities before deployment, enhancing the overall security posture of the platforms. The introduction of Mini Orange for single sign-on (SSO) to Drupal sites and the utilization of Akamai for CDN configuration significantly improved user experience and site performance, underlining the commitment to enhancing accessibility and usability.

Technologies Used

  • Drupal
  • ServiceNow
  • Agile & DevSecOps
  • AWS (Amazon Web Services)
  • Acquia Cloud
  • DevSecOps
  • CI/CD Pipeline
  • Security Tools compliance with security standards like ATO and FISMA
  • Section 508 Compliance

Outcome

Ultimately, our efforts enabled CMCS to keep pace with the changing health landscape and continue to provide a fast and reliable web presence via Medicaid.gov and IKN platforms, available to the public 24 hours a day, 7 days a week. We will help accelerate speed-to-market as it relates to ongoing regulatory and benefit changes that need to be communicated and accessible to beneficiaries in a timely manner. We will help to drive the best consumer and usability experience possible, making it easier and more intuitive for beneficiaries to find and use the information and resources they need. Lastly, we ensured compliance with all security guidelines and accessibility requirements, aligning to CMS’s aspiration to be a model employer of people with disabilities and provide equally effective access to its programs and services.

Reach Out to Discuss Your Program

Our consultants provide in-depth domain expertise in healthcare, financial services, and national security to develop a roadmap to simplify critical processes and challenges that create long term resilience and growth.