Skip to main content

What does it take to trust Medicaid data? Inside a new benchmark for security.

For state Medicaid agencies, data is essential to virtually every decision. It supports program oversight, financial management, compliance reporting, provider operations and efforts to improve outcomes for the people they serve.

That makes protecting the data, and the systems that manage it, a mission-critical responsibility. 

The challenge is growing. Government and healthcare organizations face increasingly sophisticated cyber threats while managing large volumes of sensitive information, including protected health information (PHI). At the same time, agencies need to modernize, expand their use of analytics and make information more accessible without introducing unnecessary risk. 

Security, in other words, can’t simply be promised. Agencies increasingly need evidence that the systems supporting their programs are designed and operated with security in mind. 

Related: Building stronger Medicaid data operations 

Turning security practices into measurable assurance 

Cybersecurity can be difficult for clients to evaluate from the outside. Policies, processes and technology all matter, but agencies also need a consistent way to understand whether security controls are actually in place. 

HITRUST i1 provides that independent measure. The assessment evaluates 182 curated security control requirements focused on implementation and evolving cyber risks. HITRUST describes i1 as a threat-adaptive, one-year assurance designed to address real-world cybersecurity risk and demonstrate security maturity. The assessment includes testing by an authorized external assessor as well as HITRUST quality assurance. 

For clients, that distinction is important. Instead of relying solely on a provider’s description of its security program, agencies gain third-party validation that defined controls have been evaluated against a recognized framework. The HITRUST CSF itself harmonizes requirements from more than 60 authoritative frameworks and standards, helping organizations connect cybersecurity practices with broader compliance and risk-management expectations. 

The result is greater visibility into an issue where confidence matters: how sensitive information is protected. 

In July 2026, one of our clients achieved HITRUST Implemented, 1-Year (i1) Certification, becoming the first Conduent public business unit team to achieve HITRUST certification. 

More than a milestone, the certification provides independent validation of the security practices protecting an environment that supports critical Medicaid analytics, reporting and data management. 

Protecting the foundation for Medicaid analytics 

The certification covers the technology environment supporting the state’s Medicaid Enterprise Data Warehouse. 

That includes Tableau Server and Tableau Gateway, Informatica, Oracle/Exadata, Cognos components, ForgeRock, MOVEit platforms, SQL Server and supporting infrastructure. It also encompasses supporting data center facilities in Somerset, New Jersey, and Salt Lake City and Sandy, Utah. 

Together, these technologies provide capabilities spanning data warehousing, analytics and reporting, data integration, identity and access management, and secure information transfer. 

For Medicaid agencies, those capabilities are closely connected to everyday program operations. Data may inform financial oversight, regulatory reporting, program integrity efforts, operational decisions and a clearer understanding of how programs are serving members. 

Protecting that foundation therefore protects more than technology. It helps agencies use their information with greater confidence. 

 
Related: Modernizing Medicaid without a full system replacement

Reducing uncertainty for clients 

The business value of certification comes down to assurance. 

State agencies must evaluate technology partners not only on what they can deliver, but also on how responsibly they manage the information entrusted to them. HITRUST i1 provides another independent data point for making that assessment. 

For current and prospective clients, the certification can help provide: 

  • Greater confidence in the protection of sensitive healthcare information, including PHI
  • Independent validation of security controls rather than reliance on self-assessment alone
  • Alignment with recognized cybersecurity practices and standards
  • Additional assurance for risk management and vendor oversight
  • A secure foundation for data warehouse, analytics and reporting services 

The certification does not eliminate cyber risk, nor is cybersecurity ever a finished task. Instead, it demonstrates that defined controls within the certified environment have been independently evaluated against a current, threat-focused assurance framework. 

That distinction is especially important as ransomware, phishing and other cyber threats continue to evolve. HITRUST updates its i1 control requirements to remain aligned with changing real-world risks, making the certification a measure of security practices designed for today’s threat environment. 

Security as a shared responsibility 

Achieving certification also required work well beyond any single technology or team. 
Delivery, infrastructure, security, compliance and operational teams collaborated to prepare our client’s EDW environment for assessment and demonstrate that required controls were implemented. 

That cross-functional effort matters because strong cybersecurity depends on more than tools. It requires disciplined processes, clear accountability, and an organization-wide commitment to protecting client information. 

In that sense, the certification serves as a valuable report card. It provides clients with independent evidence of security practices while giving Conduent another benchmark for continuous improvement. 

Building confidence as government modernizes 

As Medicaid agencies modernize, data will only become more important. 
The opportunity is significant. Better-connected data and analytics can help agencies strengthen oversight, improve decision-making and operate programs more effectively. But modernization works only when agencies can trust the foundation underneath it. 

Our client’s EDW HITRUST i1 certification provides another measure of that trust. 

For our teams at Conduent, this represents an important security achievement. For clients, the value is more fundamental: greater confidence that the sensitive information behind critical government healthcare programs is being managed within an independently validated, security-focused environment. 

How secure is the foundation behind your Medicaid data? 
Learn how Conduent can help your agency protect sensitive information while building a stronger foundation for analytics, reporting and modernization. Connect with an expert now at www.conduent.com/government-solutions/medicaid-public-health-solutions

About the Author

Michele Romeo is a Account Executive at Conduent, specializing in Medicaid technology and data solutions. She leads client relationships, contract management, and strategic initiatives for state healthcare agencies, helping organizations improve operational performance, compliance, and data-driven decision making through innovative technology solutions.

Profile Photo of Michele Romeo
Print