Uploaded image for project: 'BONNIE MAT MADiE Issue Tracker'
  1. BONNIE MAT MADiE Issue Tracker
  2. BONNIEMAT-640

MAT Security Policy does not align with published guidance

XMLWordPrintable

    • Icon: Question Question
    • Resolution: Resolved
    • Icon: Moderate Moderate
    • User Account / Login
    • None
    • MAT
    • AnPhilli1257
    • ALL
    • ALL
    • N/A
    • Hide
      Current security policy for log outs and password resets does not align with documented process
      https://www.emeasuretool.cms.gov/sites/default/files/2020-03/MAT%20User%20Guide.pdf

      MAT 5.6 user guide states " MAT passwords expire every 60 days. The new password must meet the same requirements," on page 14.

      MAT 5.6 user guide states " Users will automatically be logged out of the MAT after 30 minutes of inactivity. After 25 minutes of inactivity, a warning message will display, notifying the user that the session will expire" on page 9.

      I am getting password resets TWICE a month. No documentation supports this.

      MAT logs out automatically after 5 minutes. No documentation supports this and it basically makes the MAT unusable

       
      Show
      Current security policy for log outs and password resets does not align with documented process https://www.emeasuretool.cms.gov/sites/default/files/2020-03/MAT%20User%20Guide.pdf MAT 5.6 user guide states " MAT passwords expire every 60 days. The new password must meet the same requirements," on page 14. MAT 5.6 user guide states " Users will automatically be logged out of the MAT after 30 minutes of inactivity. After 25 minutes of inactivity, a warning message will display, notifying the user that the session will expire" on page 9. I am getting password resets TWICE a month. No documentation supports this. MAT logs out automatically after 5 minutes. No documentation supports this and it basically makes the MAT unusable  

      There are two issues to address here -

      Automatic log out timing:

      I've attached a screenshot of my MAT expiration message.

      I logged into the MAT at at 10:23 AM. I received this message after 10 minutes of inactivity at 10:33 AM.   

      You are correct in that the total time is 15 minutes. as the message states I will be logged out at 10:37 AM.  However, this is not practical for users of the application.  There is a mismatch between workflow and policy.  

      We need more information on the CMS "guideline" for application inactivity as there is no PHI in the MAT.  We question if the correct security policy is being applied for this application.

       

      Required password reset:

      As for the emails - I am happy to forward them along, but please refer to the screenshots and the text here.

      Sunday 3/15/20  - email states it is time to change my password.  

      Wednesday 3/25/20 - email states password will expire in 5 days.

      This is confusing for users as they feel they must change their password upon the receipt of BOTH emails.  There are no instructions in the second email that indicate that the user should disregard the second email if they responded to the first email.

      Of greater concern is that the second email is generated even if the user has already changed their password in response to the first email.  This means the second email is generated without checking the password reset.  

      Please change the language, or change the process!

      Lastly the MAT is on version 5.8.  Documentation provided as current does not reflect this - as the only documentation provided for users is version 5.6.  

       

       

       

       

       

       

       

       

       

       

       

       

       

       

       

        1. _Your MAT Account _
          7 kB
          Ann Phillips
        2. _Your MAT Account _
          8 kB
          Ann Phillips
        3. image003.png
          0.7 kB
          Ann Phillips
        4. March15email.JPG
          111 kB
          Ann Phillips
        5. March25email.JPG
          123 kB
          Ann Phillips
        6. MATlogoutScreenshot..JPG
          51 kB
          Ann Phillips
        7. MATlogoutScreenshot..JPG
          51 kB
          Ann Phillips

            adongare Ashok Dongare
            phillips@ncqa.org Ann Phillips (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: