Accessibility Statement Skip Navigation
  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing
  • Login
  • GDPR
  • Create a Free Account
Return to PRWeb homepage
  • News
  • Resources
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
  • Business & Money
      • Auto & Transportation

      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Hamburger menu
  • Cision PRWeb provides efficient communication tools to continuously engage with target audiences across multiple online channels
  • Create a Free Account
    • ALL CONTACT INFO
    • Contact Us


      11AM ET Sunday – 8PM ET Friday

  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR

Adopting NIST SP 800-171 Saved Us From Losing a $900M IDIQ Contract


News provided by

Healthcare Resolution Services

Apr 19, 2023, 15:30 ET

Share this article

Share toX

Share this article

Share toX

Principal Brenda Doles, RN, MBA
Principal Brenda Doles, RN, MBA

HCRS shares their firsthand experience with preparing for the NIST SP 800-171 (nist.gov) requirements and Cybersecurity Maturity Model Certification (CMMC). Relying on untrained and unprepared resources almost cost them a substantial contract.

COLUMBIA, Md., April 19, 2023 /PRNewswire-PRWeb/ -- Healthcare Resolution Services wants to stress how vital it is for all organizations that contract with the DoD to verify that they meet compliance for both FAR 52.204-21 and DFARS 252.204-7012, which have been in place since 2017. Failure to do so will lead to the loss of active and scheduled contracts. HCRS doesn't make this claim lightly. They experienced this concern roughly a year ago when the Defense Health Agency (DHA) notified them to submit a basic NIST SP 800-171 DoD assessment in the Supplier Performance Risk System (SPRS) for all covered contractor information systems, or DHA would not exercise the option years. This meant a potential loss of a $900-million IDIQ contract. Here's what HCRS learned from the experience.

The Call
Brenda Doles, principal of HCRS, vividly remembers getting the notice. "It's one of the worst wakeup calls you can ever have, and I was left flabbergasted. We've been helping government agencies at the local, state, and federal levels for 20+ years when it comes to their data management and compliance. We've been advocating for these crucial measures that were important even before CMMC was created to enforce them. And to be told at that time that we were missing a piece of that framework ourselves was eye-opening, to say the least."

The point of talking about this is to make it clear to business owners that they shouldn’t treat the NIST SP 800-171 and CMMC requirements with complacency or arrogance, because there’s likely more work to be accomplished.

Post this

The Reason
Any contractor that processes, stores, or exchanges Controlled Unclassified Information (CUI) and/or Federal Contract Information (FCI) on behalf of the DoD is required to have CMMC certification via an independent assessor. HCRS was told that they needed to have a current assessment score in SPRS prior to task order renewal. Upon further review with their IT, it was determined that their internal resources, while highly competent, had not received training or certification specific to the upcoming CMMC accreditation process.

"They were certain that they were compliant, but it turned out that we were missing critical policies, procedures, processes, and workflow tools needed to succinctly process, store, and transmit FCI and CUI according to the NIST SP 800-171 and CMMC requirements," Doles explains.

Over the past year, HCRS coordinated with its managed service provider (MSP), which also serves as a Registered Provider Organization (RPO), to perform a third-party assessment of its NIST 800-171 compliance posture. Subsequently, they upgraded systems, secured CMMC-AB resources, and brought their company into compliance. They're proud of the fact that they are now a Cyber AB-certified Registered Provider Organization (RPO) with credentialed resources on staff.

The Takeaway
Doles notes that this misunderstanding with IT has happened with other organizations they've partnered with. "Their departments swear they know it all and that they're compliant. Then we review their networks and find one or more areas where they are not fully aligned with NIST SP 800-171 or CMMC, and their IT teams are surprised — probably as much as ours was the day we got that call."

Doles also emphasizes the point of sharing this experience isn't to cast blame or doubt on those IT departments. "These are new requirements. Without proper training, we can't hold our employees accountable. NIST 800-171 entails 110 practice requirements that must be met. Organizations Seeking Certification (OSC) must submit two pieces of evidence per practice requirement to validate compliance. Such evidence must be adequate and sufficient as defined by the government. Fortunately, the scoring methodology used by DoD permits Plans of Action and Milestones (POA&Ms), which give 180-day extensions for any requirements that are not met at the time of an assessment. The point of talking about this is to make it clear to business owners that they shouldn't treat the NIST SP 800-171 and CMMC requirements with complacency or arrogance, because there's likely more work to be accomplished. Be proactive. Secure an RPO like HCRS to start with a gap analysis, prepare a SPRS score, develop POA&Ms as needed, and ultimately create a successful path to accreditation."

Contractors that would like additional information regarding CMMC compliance are encouraged to contact HCRS.

Media Contact

Delacia Johnson, Healthcare Resolution Services, 1 (301) 497-1187, [email protected]

SOURCE Healthcare Resolution Services

Modal title

Contact PRWeb

  • 11AM ET Sunday – 8PM ET Friday
  • Contact Us

About PRWeb

  • About PRWeb
  • Partners
  • Partnership Programs
  • Editorial Guidelines
  • Resources

Why PRWeb

  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing

Accounts

  • Create a Free Account
  • Log in
  • Contact Us

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Center
  • ProfNet
Cision Distribution Helpline
888-776-0942
  • Legal
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 Cision US Inc.