Accelerating and Enhancing Access to Critical Medical Benefits for Low-Income Individuals & Families 

Overview

The Centers for Medicare & Medicaid Services (CMS) administers key U.S. healthcare programs, including Medicaid, CHIP, and the Basic Health Program (BHP). The Center for Medicaid and CHIP Services (CMCS) oversees Medicaid and CHIP, providing health coverage to low-income individuals and families. Medicaid covers low-income people, CHIP provides health coverage for children in families with incomes too high for Medicaid, and BHP offers affordable coverage for those with fluctuating incomes. CMCS manages Medicaid.gov and InsureKidsNow.gov to provide critical information about eligibility, benefits, application processes, and policy updates to millions of users

Goal

To modernize CMS’s website infrastructure, enhance security, improve user experience, and ensure compliance with accessibility and federal regulations by upgrading to the latest Drupal versions, implementing Agile and DevSecOps practices, and leveraging cloud technologies for scalability and reliability. This initiative streamlines content deployment, optimize business processes, and maintain the highest standards of security and accessibility for Medicaid, CHIP, and BHP users.

Challenge

Administering benefits through Medicaid, CHIP, and BHP is complex and constantly evolving due to policy changes, budget constraints, health crises, outdated technology, and growing user expectations. Sky Solutions leads this website modernization to address these challenges, including outdated infrastructure, security vulnerabilities, inefficient processes, and accessibility issues. The existing Drupal version had limited capabilities, impacting the delivery of updates and features.

Solutions

To address these challenges, Sky initiated an organized modernization effort. We tackle the outdated technology stack by migrating to the latest Drupal versions and implementing advanced automation testing such as Playwright for comprehensive testing on the code, for performance and security. Additionally, we introduce an Agile and DevSecOps culture that streamlines business processes therefore facilitating faster development cycles and improved collaboration. We optimize content deployment processes, ensuring the rapid dissemination of up-to-date information. With security being of the utmost importance, Sky implements robust measures to ensure compliance with ATO and FISMA requirements, along with significant infrastructure upgrades that leverage cloud-based solutions on AWS to enhance scalability and reliability and a migration to Google’s Vertex AI Search.

Sky has embarked on a comprehensive modernization journey targeting various facets critical to transforming the landscape. At the forefront was the cultivation of an Agile and DevSecOps culture, introducing automation that streamlined processes, significantly reducing the time and effort required for new feature delivery and content posting. To fortify compliance and security measures, robust cloud and platform management strategies were implemented. Governance standards were established to ensure adherence to regulations and security requirements, alongside the execution of a meticulously devised cloud strategy for Acquia cloud Drupal version upgrades.

An equally vital focus was the ability to maintain stringent compliance with accessibility standards and regulations. Sky diligently ensures compliance with a spectrum of stringent standards, including U.S. Web Design/DigitalGov, OMB Federal Web Standards, CMS and HHS policies, and W3C Web Accessibility Initiative (WAI) standards. Upholding Section 508 of the Rehabilitation Act was pivotal, demonstrating a commitment to inclusivity and accessibility for all users.

Sky engineered a robust CI/CD pipeline, ushering in a DevOps culture and embracing test-driven development methodologies. The integration of security and compliance tools into the CI/CD pipeline ensured proactive identification and resolution of vulnerabilities before deployment, enhancing the overall security posture of the platforms. The maintenance of Mini Orange for single sign-on (SSO) to Drupal sites and the utilization of Akamai for CDN configuration significantly improved user experience and site performance, underlining the commitment to enhancing accessibility and usability.

Technologies/Methodologies

  • Drupal
  • Agile & DevSecOps
  • AWS (Amazon Web Services)
  • Google Vertex
  • Acquia Cloud
  • DevSecOps
  • CI/CD Pipeline
  • Accessibility Tools include SiteImprove, ANDI, JAWS, WAVE
  • Security Tools compliance with security standards like ATO and FISMA
  • Section 508 Compliance

Outcome

Ultimately, our efforts enabled CMCS to keep pace with the changing health landscape and continue to provide a fast and reliable web presence via Medicaid.gov and IKN platforms, available to the public 24 hours a day, 7 days a week. We accelerate speed-to-market as it relates to ongoing regulatory and benefit changes that need to be communicated and accessible to beneficiaries in a timely manner. We help drive the best consumer and usability experience possible, making it easier and more intuitive for beneficiaries to find and use the information and resources they need. Lastly, we ensure compliance with all security guidelines and accessibility requirements, aligning to CMCS’s aspiration to be a model employer of people with disabilities and provide equally effective access to its programs and services.
  • Millions of users use Medicaid.gov and IKN.gov to find information about these programs.
  • 93,008,246 individuals enrolled in Medicaid and CHIP in the 51 states and the District of Columbia reported enrollment data for January 2023.