Skip to main content
U.S. flag

An official website of the United States government

Return to Search

Distributed Data Collection (DDC) for RA Including HCRP/EDGE Server FAQ

Guidance for FAQ regarding Edge Server Operations and Technical - Security and Integrity

Issued by: Centers for Medicare & Medicaid Services (CMS)

Issue Date: November 14, 2014

Program Area: Distributed Data Collection (DDC) for RA Including HCRP/EDGE Server

Question: To what extent can issuers modify the Amazon Web Services (AWS) firewall?

Answer: Each Amazon instance will be provisioned with firewall rules. Users will be able to filter all access to only allow certain traffic that is explicitly allowed to that software. Issuers will define the port and protocols which will be allowed to their instances. Additionally, issuers can put their own host-based firewall or Internet Protocol (IP) tables in Red Hat to the security groups at the infrastructure level. It will be up to the issuer to determine the level of security that the issuer wants to implement on their virtual machine. More information on the Amazon firewall can be found in the Amazon Security webinar slide deck and Amazon set-up videos posted in the REGTAP Library (www.regtap.info) and on Amazon's security website www.aws.amazon.com/security.

HHS is committed to making its websites and documents accessible to the widest possible audience, including individuals with disabilities. We are in the process of retroactively making some documents accessible. If you need assistance accessing an accessible version of this document, please reach out to the guidance@hhs.gov.

DISCLAIMER: The contents of this database lack the force and effect of law, except as authorized by law (including Medicare Advantage Rate Announcements and Advance Notices) or as specifically incorporated into a contract. The Department may not cite, use, or rely on any guidance that is not posted on the guidance repository, except to establish historical facts.