REGULATORY WATCH BRIEF Moderate 49 🧭 Regulatory Guidance published

CMS re-establishes matching program with Treasury's Do Not Pay Working System under Privacy Act

The program expands data sharing for fraud prevention, raising privacy and security considerations for covered entities.

ImpactModerate 49
Type🧭 Regulatory Guidance
Statuspublished enacted, check the effective date
JurisdictionUS

What happened

The Centers for Medicare & Medicaid Services announced the re-establishment of a data matching program with the Do Not Pay Working System, administered by the Treasury's Bureau of Fiscal Service. The notice cites subsection (e)(12) of the Privacy Act of 1974 as authority for the program.

Why it matters for trust and compliance

  • Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
  • The program expands data sharing for fraud prevention, raising privacy and security considerations for covered entities.

Who is affected

healthcare controller processor Centers for Medicare & Medicaid Services U.S. Department of the Treasury, Bureau of Fiscal Service

Recommended actions

  1. Check that privacy notices describe the practices this addresses.
  2. Map the security requirements to existing controls and close gaps.