Skip to Highlights
Highlights

The Department of Health and Human Services (HHS) is one of the largest federal agencies, the nation's largest health insurer, and the largest grant- making agency in the federal government. The department manages over 300 programs that serve to improve the health and well-being of the American public and is comprised of several component agencies covering a wide range of activities including conducting and sponsoring medical and social science research, guarding against the outbreak of infectious diseases, assuring the safety of food and drugs, and providing health care services and insurance. It also manages and funds a variety of information technology (IT) initiatives ranging from those facilitating the payment of claims for Medicare and Medicaid services to those supporting health surveillance and communications. In fiscal year 2006, the department plans to spend over $5 billion on information technology--the third largest IT expenditure in the federal budget. As we agreed with Congress, our objectives were to (1) assess the department's capabilities for managing its IT investments and (2)determine any plans the department might have for improving those capabilities. To address these objectives, we analyzed documents and interviewed agency officials to (1)validate and update HHS's self-assessments of key practices in the framework and (2)evaluate HHS's plans for improving its capabilities.

Skip to Recommendations

Recommendations

Recommendations for Executive Action

Agency Affected Recommendation Status
Department of Health and Human Services 1. The HHS Secretary should direct the CIO to ensure that the plan draws together ongoing efforts and additional efforts that are needed to address the weaknesses identified in this report. The plan should also (1) specify measurable goals, objectives, and milestones; (2) specify needed resources; (3) assign clear responsibility and accountability for accomplishing tasks; and (4) be approved by senior management.
Closed - Implemented
While HHS did not complete an improvement plan to address the weaknesses identified in our report that (1) identifies measurable goals, objectives, and milestones; (2) specifies needed resources; and (3) assigns clear responsibility and accountability for accomplishing tasks, the department has over the years taken action to implement and close each of the recommendations from our report.
Department of Health and Human Services 2. To improve the department oversight of its component agency investment management process, the HHS Secretary should direct the HHS CIO to establish a mechanism for ensuring component agencies define and implement investment management processes that are aligned with those of the department.
Closed - Implemented
In December 2005, HHS adopted capital planning and investment control (CPIC) policy and procedures that provided for a departmental IT governance organization and required that each HHS component agency (i.e., operating division) establish and maintain IT governance structures consistent with those established at the department level. In addition, in October 2008 HHS adopted an Enterprise Performance Life Cycle (EPLC) framework to further align and enhance IT governance and management processes throughout the department. The EPLC framework applies to all levels of HHS and is compatible with current Department CPIC policy, and under it the component agencies are required to establish IT Governance processes that are consistent with HHS CPIC policy and procedures, including the EPLC framework. Under the EPLC, the department reserves the right to conduct project reviews of component agency projects when necessary to review process compliance or to otherwise fulfill its HHS IT project, investment, and portfolio management responsibilities. In November 2009, HHS officials briefed us and provided documentation illustrating how the EPLC is used for aligning the planning, management and oversight of HHS IT projects throughout a 10-stage life cycle.
Department of Health and Human Services 3. To strengthen HHS's investment management capability and address the weaknesses discussed in this report, the Secretary of the Department of Health and Human Services should direct the Chief Information Officer (CIO) to develop and implement a plan for improving the department's IT investment management processes. The plan should address the weaknesses described in this report, beginning with those we identified in our Stage 2 analysis and continuing with those we identified in our Stage 3 analysis. The plan should, at a minimum, develop comprehensive guidance and additional supporting guidance that defines and describes the complete investment management process, unifies existing processes enterprise-wide, reflects changes in processes as they occur; define the operations and decision-making processes of the HHS investment review board and other management entities, such as the component agencies, involved in managing IT investments.
Closed - Implemented
HHS has developed comprehensive Capital Planning and Investment Control (CPIC) policy and procedures that define and describe the CPIC processes at the agency and also direct all operating divisions to issue implementing guidance. Additionally, HHS issued its Portfolio Management Tool Desktop Guide that relates the HHS CPIC process to the tool that supports that process. Finally, a number of charters have been revised including: a CIO Council charter that clarifies scope, responsibilities, and membership; Service and Supply Fund charter that includes specific language regarding review of IT proposals by the HHS CIO Council and IT Investment Review Board (ITIRB); and ITIRB charter that addresses the board's responsibilities regarding the Service and Supply Fund.
Department of Health and Human Services 4. To strengthen HHS's investment management capability and address the weaknesses discussed in this report, the Secretary of the Department of Health and Human Services should direct the Chief Information Officer (CIO) to develop and implement a plan for improving the department's IT investment management processes. The plan should address the weaknesses described in this report, beginning with those we identified in our Stage 2 analysis and continuing with those we identified in our Stage 3 analysis. The plan should, at a minimum, ensure that HHS's investment review board's membership includes business representation of its component agencies as it begins to execute its full range of responsibilities.
Closed - Implemented
In August 2007, HHS developed an Information Technology Investment Review Board (ITIRB) charter that, among other things, specifies that the board's membership is to include business representation. Specifically, the charter notes that the ITIRB is to include one representative from each of the operating divisions and that each of these representatives is to have voting privileges.
Department of Health and Human Services 5. To strengthen HHS's investment management capability and address the weaknesses discussed in this report, the Secretary of the Department of Health and Human Services should direct the Chief Information Officer (CIO) to develop and implement a plan for improving the department's IT investment management processes. The plan should address the weaknesses described in this report, beginning with those we identified in our Stage 2 analysis and continuing with those we identified in our Stage 3 analysis. The plan should, at a minimum, develop well-defined and disciplined written procedures that outline the process for selecting new IT proposals, reselecting ongoing IT investments, and integrating funding with the process of selecting an investment.
Closed - Implemented
HHS has developed comprehensive Capital Planning and Investment Control (CPIC) policy and procedures that define and describe the CPIC processes at the agency, including the processes for selecting new IT proposals, reselecting ongoing IT investments, and integrating funding with the process of selecting an investment. Additionally, in 2007 the HHS Office of the Chief Information Officer reviewed and ranked approximately 100 IT investments to assist the HHS Information Technology Investment Review Board select and recommend fiscal year 2009 funding for the Department's IT portfolio that was submitted to the Office of Management and Budget.
Department of Health and Human Services 6. To strengthen HHS's investment management capability and address the weaknesses discussed in this report, the Secretary of the Department of Health and Human Services should direct the Chief Information Officer (CIO) to develop and implement a plan for improving the department's IT investment management processes. The plan should address the weaknesses described in this report, beginning with those we identified in our Stage 2 analysis and continuing with those we identified in our Stage 3 analysis. The plan should, at a minimum, establish a process for the investment board to regularly review and track the performance of a defined set of component agency IT systems against expectations, and take corrective actions when these expectations are not being met; and establish a mechanism for maintaining visibility into other investments.
Closed - Implemented
In response to GAO's recommendation, in 2007 HHS issued guidance calling for the establishment of a High Variance List process to provide departmental oversight of the portfolio of all major or tactical IT investments for capital assets. Under this process, performance data (i.e., earned value management data) for each investment in the portfolio are reviewed by the Office of the Chief Information Officer (CIO) and investments are placed on the High Variance List if they fail to meet specific criteria. The process also involves a progressive escalation process, up to the investment board, if necessary, to ensure that any performance issues are resolved and needed corrective actions are implemented. HHS provided information showing that during 2009, the Office of CIO prepared an HHS High Variance List Analysis Summary each month that describes the current status of each investment on the list, and that the investment board was provided an Investment Oversight briefing on the HHS High Variance List each quarter.
Department of Health and Human Services 7. To strengthen HHS's investment management capability and address the weaknesses discussed in this report, the Secretary of the Department of Health and Human Services should direct the Chief Information Officer (CIO) to develop and implement a plan for improving the department's IT investment management processes. The plan should address the weaknesses described in this report, beginning with those we identified in our Stage 2 analysis and continuing with those we identified in our Stage 3 analysis. The plan should, at a minimum, develop and implement policies and procedures for modifying IT portfolio selection criteria.
Closed - Implemented
In December 2005, HHS adopted Capital Planning and Investment Control (CPIC) procedures that provide for the HHS CPIC Team, CIO Council, and IT investment review board to work together to develop a set of selection criteria to be used in scoring and ranking the IT investments and to review these criteria on an annual basis, revising them as necessary to reflect changing priorities of the Department. To implement these procedures, each year, prior to final decisions regarding the HHS annual budget submission, the HHS Office of the CIO presents a ranked portfolio to the HHS IT Investment Review Board, and the ranking process is revised, if necessary, to reflect changes in HHS strategic goals. The criteria used require that each major and tactical investment receives a Priority Score and a Quality Score based on information provided by HHS component agencies and Enterprise Initiative investment managers via the Portfolio Management Tool and investment reviews conducted by HHS Critical Partners. To illustrate how it had implemented its procedures for developing and modifying the criteria it used in order score and rank its IT portfolio, in 2009 HHS provided documentation describing the criteria it used in the fiscal year 2009 budget cycle, and how the department had modified its portfolio selection criteria after the fiscal year 2008 cycle, as well as its ranked IT portfolios for the 2009 and 2010 budget cycles.
Department of Health and Human Services 8. To strengthen HHS's investment management capability and address the weaknesses discussed in this report, the Secretary of the Department of Health and Human Services should direct the Chief Information Officer (CIO) to develop and implement a plan for improving the department's IT investment management processes. The plan should address the weaknesses described in this report, beginning with those we identified in our Stage 2 analysis and continuing with those we identified in our Stage 3 analysis. The plan should, at a minimum, develop policies and procedures for using the portfolio selection criteria to create its portfolio.
Closed - Implemented
HHS has developed comprehensive Capital Planning and Investment Control (CPIC) policy and procedures that define and describe the CPIC processes at the agency. They include policy and procedures for using the portfolio selection criteria to create the IT portfolio.
Department of Health and Human Services 9. To strengthen HHS's investment management capability and address the weaknesses discussed in this report, the Secretary of the Department of Health and Human Services should direct the Chief Information Officer (CIO) to develop and implement a plan for improving the department's IT investment management processes. The plan should address the weaknesses described in this report, beginning with those we identified in our Stage 2 analysis and continuing with those we identified in our Stage 3 analysis. The plan should, at a minimum, develop, review, and modify criteria for assessing portfolio performance at regular intervals to reflect current performance expectations.
Closed - Implemented
In response to our recommendation, in April 2007 HHS established a process to provide departmental oversight of the portfolio of all major or tactical IT investments, with a particular focus on investments experiencing performance issues. Under this process, performance data for each investment in the portfolio are reviewed by the Office of the CIO and an investment is placed on the List if it meets any of five specific High Variance List criteria, such as the investment has a development, modernization, or enhancement cost or schedule variance of more than 10 percent or has not tested its security controls or contingency plan within the past year. In addition, in November 2009, the department issued an IT Investment Performance Baseline Management policy for measuring, reporting, and evaluating the portfolio performance of all HHS major and tactical IT Investments, and of all HHS supporting IT investments with annual budget year costs equal to or greater than $1 million. This new policy modified the earlier HHS earned value management policy for assessing IT investment performance, and is intended to employ improved performance measurement mechanisms that assess each IT investment's progress in achieving benefits and continued viability over the IT investment's entire lifecycle.
Department of Health and Human Services 10. To strengthen HHS's investment management capability and address the weaknesses discussed in this report, the Secretary of the Department of Health and Human Services should direct the Chief Information Officer (CIO) to develop and implement a plan for improving the department's IT investment management processes. The plan should address the weaknesses described in this report, beginning with those we identified in our Stage 2 analysis and continuing with those we identified in our Stage 3 analysis. The plan should, at a minimum, define and implement processes for carrying out PIRs for all IT investments.
Closed - Implemented
In 2008, HHS issued guidance calling for the conduct of a post-implementation review (PIR) of each completed IT project after a period of sustained operation into the production environment to assess whether the project has met its objectives, delivered planned levels of benefit, and addressed the specific requirements as originally defined, to examine the efficacy of all elements of the working business solution to see if further improvements can be made to optimize the benefit delivered, and to learn lessons from the project that can be used to improve future project work and solutions. The department provided examples of post-implementation reviews it conducted in 2008 of its Federal Parent Locater System and National Patient Information Reporting System to illustrate implementation of PIR guidance by HHS component agencies.

Full Report