Pre-Payment Fraud Prevention and Treasury Data Access Act
What changed between versions
Entire Section 5 (U.S. Treasury data access for purposes of program integrity) was removed, eliminating the statutory authority for Treasury to access IRS tax return information under IRC 6103(i)(9), Social Security Act section 235 data, and the National Directory of New Hires under section 453(j). These were the specific legal hooks that would have allowed Treasury to pull sensitive personal financial data into the Do Not Pay system.
State and local government obligations were changed from a requirement to 'establish and maintain appropriate preaward and prepayment procedures' to having 'access to the Do Not Pay system to review preaward and prepayment data' if procedures are established. This shifts from a mandatory procedural obligation to an access-based model.
The Do Not Pay system data access language was changed from 'Notwithstanding any other provision of law, including the Internal Revenue Code of 1986, the Social Security Act, and the Personal Responsibility and Work Opportunity Reconciliation Act' to 'Consistent with the routine use authority under section 552a of title 5, and subject to the requirements of paragraphs (3) and (6).' This removes the blanket override of privacy statutes and requires compliance with Privacy Act routine use procedures instead.
A new requirement mandates that the Secretary publish and maintain a System of Records Notice for the Do Not Pay system identifying each data asset, the routine uses under which it is disclosed, specific permitted purposes, and access controls. No data asset may be disclosed before publication of applicable routine uses.
New implementation requirements mandate that the Do Not Pay system strictly provide match-based queries returning only limited responses (confirmation or denial of a match, confidence level, data sources, and minimum additional data elements). Individuals are prohibited from retrieving, browsing, or making repeated tailored inquiries to reconstitute underlying records.
New provision prohibits taking adverse action against any individual based solely on Do Not Pay system information. Agencies must take additional independent verification steps before adverse action and make an independent judgment regarding payment certification or recovery decisions.
A new confidentiality maintenance provision requires the Secretary to maintain the same level of confidentiality for each data asset as required by the source law, with documentation in the System of Records Notice of specific confidentiality obligations and compliance mechanisms.
A new section requires the Evaluation Officer of each agency to provide Congress an annual evaluation of the Do Not Pay system including the best available estimate of effectiveness in reducing fraud and improper payments on a monthly and regional basis, with analysis of which data sources are attributed to identifying or reducing instances by count and total dollar savings.
A new voluntary expedited process for computer matching agreements was added under the Privacy Act. OMB must establish a standard template within 180 days that, upon execution, is deemed to satisfy Privacy Act requirements without Data Integrity Board review. Agreements have termination dates of less than 5 years (up from 3) and can be renewed for up to 5 years.
Data matching under the Do Not Pay system is now limited to inquiries that return a binary verification response, retain resulting data for no more than 30 days, and contain no more than 20 discrete record requests at a time for a particular agency program.
The penalty for knowing and willful unlawful disclosure of Do Not Pay system information was increased from a fine of not more than $5,000 to not more than $250,000 (imprisonment remains at 5 years).
The payment suspension penalty for recipients who fail to submit the required first-time use report was narrowed from preventing payment vouchers 'for any program funds' to only 'funds related to the particular program for which the report was required.'
Congressional reporting on the Do Not Pay system was changed from an annual report to quarterly reports, with the content shifted from 'an evaluation of effectiveness' to 'performance measures for monitoring effectiveness.'
The public notice and comment period for designating categories of data assets containing personally identifiable information was reduced from 30 days to 15 days (the 30-day period for adding specific data assets within a designated category remains unchanged).
The exemption process for agencies was strengthened: the reference changed from 'guidance' to 'regulations,' and a new requirement was added that requesting agencies must provide a plan and reasonable timeframe to remediate the need for the exemption.