In accordance with subsection (e)(12) of the Privacy Act of 1974, as amended, the U.S. Department of Health and Human Services, Centers for Medicare & Medicaid Services (CMS), i...
Centers for Medicare and Medicaid Services, Department of Health and Human Services.
ACTION:
Notice of a new matching program.
SUMMARY:
In accordance with subsection (e)(12) of the Privacy Act of 1974, as amended, the U.S. Department of Health and Human Services, Centers for Medicare & Medicaid Services (CMS), is providing notice of the re-establishment of a matching program between CMS and the Do Not Pay Working System, which is administered by the U.S. Department of the Treasury, Bureau of Fiscal Service (Fiscal Service).
DATES:
The deadline for comments on this notice is October 26, 2026. The re-established matching program will commence not sooner than 30 days after publication of this notice, provided no comments are received that warrant a change to this notice. The matching program will be conducted for an initial term of 36 months (approximately October 19, 2026 to October 18, 2029) and within 3 months of expiration may be renewed for three additional years if the parties make no change to the matching program and certify that the program has been conducted in compliance with the matching agreement.
ADDRESSES:
Interested parties may submit written comments on this notice to the CMS Privacy Act Officer by mail at: Division of Security, Privacy Policy & Oversight, Information Security & Privacy Group, Office of Information Technology, Centers for Medicare & Medicaid Services, Location: N1-14-56, 7500 Security Blvd., Baltimore, MD 21244-1850, or email
walter.stone@cms.hhs.gov.
FOR FURTHER INFORMATION CONTACT:
If you have questions about the matching program, you may contact John Sofokles, Government Technical Lead, Center for Program Integrity, Centers for Medicare & Medicaid Services, at 410-786-6373, by email at
john.sofokles@cms.hhs.gov,
or by mail at 7500 Security Blvd., Baltimore, MD 21244.
SUPPLEMENTARY INFORMATION:
The Privacy Act of 1974, as amended (5 U.S.C. 552a), provides certain protections for individuals applying for and receiving federal benefits. The law governs the use of computer matching by federal agencies when records in a system of records (meaning, federal agency records about individuals retrieved by name or other personal identifier) are matched with records of other federal or non-federal agencies. The Privacy Act requires agencies involved in a matching program to:
1. Enter into a written agreement, which must be prepared in accordance with the Privacy Act, approved by the Data Integrity Board of each source and recipient federal agency, provided to Congress and the Office of Management and Budget (OMB), and made available to the public, as required by 5 U.S.C. 552a(o), (u)(3)(A), and (u)(4).
2. Notify the individuals whose information will be used in the matching program that the information they provide is subject to verification through matching, as required by 5 U.S.C. 552a(o)(1)(D).
( printed page 60959)
3. Verify match findings before suspending, terminating, reducing, or making a final denial of an individual's benefits or payments or taking other adverse action against the individual, as required by 5 U.S.C. 552a(p).
4. Report the matching program to Congress and the OMB, in advance and annually, as required by 5 U.S.C. 552a(o) (2)(A)(i), (r), and (u)(3)(D).
5. Publish advance notice of the matching program in the
Federal Register
as required by 5 U.S.C. 552a(e)(12).
This matching program meets these requirements. It re-establishes matching begun in 2020 to address improper payments using the Do Not Pay Working System, as described in 85 FR 58062.
Barbara Demopulos,
CMS Privacy Act Officer, Division of Security, Privacy Policy & Oversight, Information Security and Privacy Group, Office of Information Technology, Centers for Medicare & Medicaid.
Participating Agencies
The U.S. Department of Health and Human Services, Centers for Medicare & Medicaid Services, and the U.S. Department of the Treasury, Bureau of Fiscal Service (Fiscal Service).
Authority for Conducting the Matching Program
The Payment Integrity Information Act of 2019 (31 U.S.C. 3351et seq.) establishes the DNP Initiative and requires, for the purposes of identifying and preventing improper payments, each executive agency to have access to, and use of, the relevant databases in DNP to verify payment or award eligibility. Additional authorities for this matching program include Executive Order 13520,
Reducing Improper Payments
(74 FR 62201); Executive Order 14249,
Protecting America's Bank Account Against Fraud, Waste, and Abuse
(90 FR 14011); and OMB Memorandum M-25-32,
Preventing Improper Payments and Protecting Privacy Through Do Not Pay.
Additional information regarding the authorities for the collection and maintenance of information is contained within the system of records notices listed below.
Purpose(s)
The purpose of the matching program is to provide CMS with information from the Treasury's Do Not Pay Working System, which CMS will use to identify providers and suppliers who are ineligible for Medicare enrollment; to promptly suspend or revoke the Medicare billing privileges of the identified disqualified providers and suppliers; to enable recoupment of past payments made to those providers and suppliers; to assist CMS in detecting and preventing fraud, waste, abuse and avoid making future improper payments to disqualified providers and suppliers; and to enhance patient safety for beneficiaries in CMS programs.
Categories of Individuals
The categories of individuals involved in the matching program are individual providers and suppliers who bill Medicare for payment.
Categories of Records
The categories of records used in the matching program are identifying data and payment eligibility status data. To request information from Treasury's Do Not Pay Working System, CMS will provide Fiscal Service with the following information about a Medicare provider or supplier: Tax Identification Number (TIN), Business Name, Person First Name, Person Middle Name, Person Last Name, Address, City Name, State Code, Person Date of Birth, Person Sex, Vendor/Payee Phone Number, Vendor/Payee Email Address.
When Fiscal Service is able to match the TIN and other identifying data provided by CMS, Fiscal Service will disclose to CMS the following information with respect to that provider or supplier:
Record Code
Payee Identifier
Agency Location Code
Tax Identification Type
Tax Identification Number
Whether a Record Belongs to a Business or Individual or Government
Data Universal Numbering System (DUNS) Number
Payee Business Name
Payee Business DBA Name
Person Full Name
Person First Name
Person Middle Name
Person Last Name
Address
Person Date of Birth
Person Sex
Vendor/Payee Status
Phone Type
Vendor/Payee Phone Number
Vendor/Payee Fax Number
Vendor/Payee Email Address
Vendor/Payee Active Date
Vendor/Payee Expiration Date
Agency Record Grouping
Match Type
Match Source
Match Level
Match Date/Time
Matched Party Type
Matched Tax ID Number
Matched Tax ID Type Code (alternate)
Matched Tax ID Number (alternate)
Match DUNS Number
Matched Full Name
Matched First Name
Matched Middle Name
Matched Last Name
Matched Business Name
Matched DBA Business Name
Matched Birth Date
Matched Death Date
Matched List Status Code
Matched List Status Code Description
Matched List Effective Date
Matched Address
Matched City
Matched State Code
Matched Zip Code
Matched Country Code
System(s) of Records
The records used in this matching program will be disclosed from the following systems of records, as authorized by routine uses published in the System of Records Notices (SORNs) cited below:
A. System of Records Maintained by CMS
The Provider Enrollment, Chain, and Ownership System (PECOS), System No. 09-70-0532,71 FR 60536 (Oct. 13, 2006), 78 FR 32257 (May 29, 2013) and 83 FR 6591 (Feb. 14, 2018).
B. System of Records Maintained by Fiscal Service
The Department of the Treasury, Bureau of the Fiscal Service .017—Do Not Pay Payment Verification Records,85 FR 11776 at 11803 (Feb. 27, 2020)