The government did not measure this contractor against an outside benchmark. It measured the contractor against the remediation deadlines the contractor wrote for itself — and that was enough to support an $11.25 million False Claims Act resolution.
Health Net Federal Services, LLC (HNFS) of Rancho Cordova, California, and its corporate parent, Centene Corporation, agreed to pay $11,253,400 to resolve allegations that HNFS falsely certified compliance with cybersecurity requirements in annual reports to the Defense Health Agency under its contract to administer the TRICARE health benefits program. The resolution deserves attention from any contractor that has ever written a System Security Plan, because of what the government used as its yardstick: not a control the contractor had never heard of, but the response times the contractor had set for itself.
What the Government Alleged
According to the Justice Department, between 2015 and 2018 HNFS failed to meet certain cybersecurity controls and falsely certified compliance with them in the annual reports its contract required it to submit to the Defense Health Agency (DHA).
Two categories of allegation drive the case.
First, missed self-imposed deadlines. The United States alleged that HNFS failed to timely scan for known vulnerabilities and to remedy security flaws on its networks and systems in accordance with its System Security Plan and the response times HNFS had established. The standard the government invoked was HNFS's own documented plan.
Second, ignored warnings. The government further alleged that HNFS disregarded reports — from third-party security auditors and from its own internal audit department — flagging cybersecurity risks across asset management, access controls, configuration settings, firewalls, end-of-life hardware and software still in use, patch management, vulnerability scanning, and password policies.
The matter was handled by the Civil Division's Commercial Litigation Branch (Fraud Section) and the U.S. Attorney's Office for the Eastern District of California, with assistance from the DoD Office of Inspector General — including the Defense Criminal Investigative Service and the Inspector General's Office of Audits — and DoD's Defense Contract Management Agency, Defense Industrial Base Cybersecurity Assessment Center. Centene acquired Health Net, Inc. in 2016 and assumed HNFS's liabilities.
(A settlement is not an admission of liability. As DOJ stated, "the claims asserted against defendants are allegations only; there has been no determination of liability.")
The SSP Cuts Both Ways
Contractors are trained to view the System Security Plan as a compliance asset — the document that demonstrates you have thought carefully about your environment. That is true. But this case illustrates the other edge of it.
An SSP is a set of written representations about how your organization secures a system. When it specifies that critical vulnerabilities will be remediated within a defined window, that is not aspirational language. It is the standard you have told the government you meet, and it becomes the benchmark against which your certifications of compliance are measured.
That dynamic matters because contractors have considerable latitude in setting those parameters. NIST SP 800-171 leaves many timing decisions to the organization. A contractor that writes a 30-day remediation window and hits it is compliant; a contractor that writes a 7-day window and consistently takes 45 days has manufactured its own evidence of non-compliance — and has done so in a document the government already has.
The practical implication is not "write weaker plans." It is that the plan and the practice must match, and that a gap between them should trigger a revision to the plan or a fix to the practice — documented either way. Our explainer on what a System Security Plan must contain walks through the required elements; the discipline this case adds is that every parameter you set is a commitment.
The Ignored-Audit Problem
The second allegation is arguably more dangerous than the first, because it goes to knowledge.
The False Claims Act requires scienter — knowing submission of a false claim, including reckless disregard or deliberate ignorance. Internal audit findings and third-party assessment reports are the clearest possible documentary proof that an organization was on notice of a deficiency. When such reports exist and nothing changed, the "we did not know" defense narrows sharply.
Contractors sometimes treat unresolved audit findings as an accepted cost of doing business. In a regulated cybersecurity context tied to federal payment, they are better understood as a dated, written record of what leadership knew and when. The right response is a tracked remediation record — which is precisely the function a plan of action and milestones is supposed to serve. An open finding with an active, resourced POA&M tells a very different story than an open finding with nothing attached to it.
Health Contracting Is In Scope
It is easy to read the Civil Cyber-Fraud Initiative docket as a defense-manufacturing story: SPRS scores, DFARS 252.204-7012, NIST SP 800-171 flowdowns. This case sits somewhere else. HNFS is a health-services administrator, its counterparty was the Defense Health Agency, and the data at issue was servicemember and family health information.
The obligation arose from a contract requirement to certify cybersecurity compliance in annual reports. That is a structure familiar to health-sector, benefits-administration, claims-processing, and services contractors across government — and it carries the same False Claims Act exposure as any defense clause. Contractors in healthcare and defense alike should assume that a periodic compliance certification is a claim-adjacent representation, not an administrative formality.
What Contractors Should Do
1. Reconcile your SSP against actual practice. Pull every timing parameter, scanning cadence, and remediation window in your plan and confirm you are meeting it. Where you are not, either fix the practice or revise the parameter deliberately and document the rationale.
2. Close out audit findings on a tracked schedule. Any third-party or internal-audit finding that touches a certified control should map to a POA&M entry with an owner, a date, and evidence at closure.
3. Inventory your certification obligations. Identify every recurring report, annual attestation, or representation your contracts require. Use Find My Requirements to see which standards attach to your work, and treat each certification as a legally operative statement.
4. Do not assume your sector is outside the perimeter. Review the pattern of cases on the enforcement page; the through-line is a cybersecurity representation tied to federal payment, not an industry code.
Key Takeaways
- HNFS and Centene paid $11,253,400 to resolve allegations that HNFS falsely certified cybersecurity compliance in annual reports to the Defense Health Agency under its TRICARE administration contract, covering conduct between 2015 and 2018.
- The government's benchmark was the contractor's own System Security Plan and self-established response times — a reminder that every parameter you write into an SSP becomes a standard your compliance certifications are measured against.
- Ignored third-party and internal audit reports supply the documentary knowledge element the False Claims Act requires; open findings should always be paired with a tracked, resourced remediation record.