CMS re-establishes matching program with Treasury's Do Not Pay Working System under Privacy Act
The program expands data sharing for fraud prevention, raising privacy and security considerations for covered entities.
ADTP Regulatory Watch· September 25, 2026· U.S. Department of Health and Human Services, Centers for Medicare & Medicaid Services
ImpactModerate 49
Type🧭 Regulatory Guidance
Statuspublishedenacted, check the effective date
JurisdictionUS
What happened
The Centers for Medicare & Medicaid Services announced the re-establishment of a data matching program with the Do Not Pay Working System, administered by the Treasury's Bureau of Fiscal Service. The notice cites subsection (e)(12) of the Privacy Act of 1974 as authority for the program.
Why it matters for trust and compliance
Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
The program expands data sharing for fraud prevention, raising privacy and security considerations for covered entities.
Who is affected
healthcarecontrollerprocessorCenters for Medicare & Medicaid ServicesU.S. Department of the Treasury, Bureau of Fiscal Service
Recommended actions
Check that privacy notices describe the practices this addresses.
Map the security requirements to existing controls and close gaps.