The Centers for Medicare & Medicaid Services (CMS) has formally re-established a significant data matching program with the U.S. Department of the Treasury's Bureau of Fiscal Service, which administers the Do Not Pay Working System. This re-establishment, publicly announced through a Federal Register notice, marks a renewed federal commitment to combating improper payments, fraud, waste, and abuse within the Medicare program. The program is set to commence not sooner than 30 days after its September 25, 2026, publication, with an initial term of 36 months, extending the fight against financial irregularities until approximately October 2029.
The Mandate Behind Data Matching
The re-establishment of this matching program is rooted in a broader federal directive to ensure payment integrity. The Payment Integrity Information Act of 2019 (31 U.S.C. 3351 et seq.) is a cornerstone of this effort, explicitly requiring executive agencies to access and utilize the relevant databases within the Do Not Pay system. This legislative mandate aims to verify payment or award eligibility before federal funds are disbursed. Complementing this act are several foundational executive and administrative policies, including Executive Order 13520, "Reducing Improper Payments," issued by President Trump, and Executive Order 14249, "Protecting America's Bank Account Against Fraud, Waste, and Abuse," also issued by President Trump. These presidential directives, alongside OMB Memorandum M-25-32, "Preventing Improper Payments and Protecting Privacy Through Do Not Pay," collectively underscore the government's sustained focus on safeguarding federal dollars from ineligible recipients.
How the Matching Program Operates
The core purpose of this matching program is to provide CMS with actionable intelligence from the Treasury's Do Not Pay Working System. CMS will leverage this information to identify Medicare providers and suppliers who are ineligible to receive payments. The process involves CMS submitting specific identifying data for Medicare providers and suppliers to the Fiscal Service. This data includes Tax Identification Numbers (TINs), business names, individual names, addresses, dates of birth, and contact information.
Upon receiving this information, the Fiscal Service performs a match against its Do Not Pay databases. If a match is found, the Fiscal Service discloses critical information back to CMS. This includes various identifying details, payment eligibility status, and specific codes indicating the reason for ineligibility. With this verified information, CMS is empowered to take immediate and decisive action. This includes promptly suspending or revoking the Medicare billing privileges of identified disqualified entities, enabling the recoupment of any past improper payments, and actively preventing future improper payments. A vital ancillary benefit is the enhancement of patient safety for beneficiaries in CMS programs, as it ensures that care is delivered by legitimate and qualified providers.
Safeguarding Privacy Under Federal Law
Central to any federal data matching initiative involving personal information is adherence to the Privacy Act of 1974, as amended (5 U.S.C. 552a). The Federal Register notice confirms that this matching program meets all statutory requirements of the Privacy Act. These requirements are rigorous and include: entering into a written agreement approved by the Data Integrity Board of each agency involved, notifying individuals whose information will be used that it is subject to verification through matching, verifying match findings before taking any adverse action such as suspending or denying benefits, reporting the program to Congress and the Office of Management and Budget (OMB), and publishing an advance notice in the Federal Register. These provisions are designed to protect individual privacy while allowing the government to efficiently detect and prevent fraud and waste.
Implications for Providers and the Public
For Medicare providers and suppliers, the re-establishment of this program signals continued and heightened scrutiny. It reinforces the necessity for accurate and up-to-date enrollment information and strict adherence to eligibility criteria. Any entity billing Medicare can expect their information to be cross-referenced with federal watchlists and databases designed to flag individuals or organizations deemed ineligible for federal payments. For the public, and particularly Medicare beneficiaries, this program offers an additional layer of protection. By reducing fraud and ensuring that only legitimate providers participate in Medicare, the program aims to preserve the integrity of federal healthcare funds and contribute to better, safer care delivery. The program's effectiveness hinges on the continued, robust collaboration between CMS and the Department of the Treasury.