HR 8463 United States House · 119th Congress

Pre-Payment Fraud Prevention and Treasury Data Access Act

This bill establishes new pre-payment verification requirements for federal agencies to prevent fraud before any money is disbursed. It mandates that agencies confirm a payee's identity, bank account validity, and eligibility using a centralized "Do Not Pay" system that cross-references data from the Treasury, IRS, and Social Security Administration. Additionally, the legislation requires recipients of federal awards over $50,000 to submit a one-time report detailing how they intend to use the funds within 180 days of receiving them. The act also expands the types of sensitive data the Treasury can access to detect improper payments while including specific privacy protections and penalties for unauthorized disclosure.
Bill status passed 3 of 5 stages cleared
Introduction
Apr 2026
Committee Review
Jun 2026
House Passage
Jun 2026
Senate Passage
President
Introduced Apr 23, 2026 Last action Jun 9, 2026
Maddy AI version diff · 1 comparison

What changed between versions

Introduced in House Engrossed in House · 15 edits · Jun 8, 2026
MAJOR
The Engrossed version of HR 8463 makes major revisions to the Do Not Pay system provisions, replacing a broad data-access override with Privacy Act-compliant procedures, adding significant privacy protections and use limitations, increasing penalties for unlawful disclosure from $5,000 to $250,000, and entirely removing the standalone section that granted Treasury direct access to IRS tax return information, Social Security data, and the National Directory of New Hires. The bill also shifts state/local government obligations from mandatory procedures to an access-based model, changes congressional reporting from annual to quarterly, adds a new independent evaluation requirement, and narrows the payment suspension penalty for noncompliant recipients to only funds related to the specific program in question.
SCOPE

Entire Section 5 (U.S. Treasury data access for purposes of program integrity) was removed, eliminating the statutory authority for Treasury to access IRS tax return information under IRC 6103(i)(9), Social Security Act section 235 data, and the National Directory of New Hires under section 453(j). These were the specific legal hooks that would have allowed Treasury to pull sensitive personal financial data into the Do Not Pay system.

State and local government obligations were changed from a requirement to 'establish and maintain appropriate preaward and prepayment procedures' to having 'access to the Do Not Pay system to review preaward and prepayment data' if procedures are established. This shifts from a mandatory procedural obligation to an access-based model.

REQUIREMENT

The Do Not Pay system data access language was changed from 'Notwithstanding any other provision of law, including the Internal Revenue Code of 1986, the Social Security Act, and the Personal Responsibility and Work Opportunity Reconciliation Act' to 'Consistent with the routine use authority under section 552a of title 5, and subject to the requirements of paragraphs (3) and (6).' This removes the blanket override of privacy statutes and requires compliance with Privacy Act routine use procedures instead.

A new requirement mandates that the Secretary publish and maintain a System of Records Notice for the Do Not Pay system identifying each data asset, the routine uses under which it is disclosed, specific permitted purposes, and access controls. No data asset may be disclosed before publication of applicable routine uses.

New implementation requirements mandate that the Do Not Pay system strictly provide match-based queries returning only limited responses (confirmation or denial of a match, confidence level, data sources, and minimum additional data elements). Individuals are prohibited from retrieving, browsing, or making repeated tailored inquiries to reconstitute underlying records.

New provision prohibits taking adverse action against any individual based solely on Do Not Pay system information. Agencies must take additional independent verification steps before adverse action and make an independent judgment regarding payment certification or recovery decisions.

A new confidentiality maintenance provision requires the Secretary to maintain the same level of confidentiality for each data asset as required by the source law, with documentation in the System of Records Notice of specific confidentiality obligations and compliance mechanisms.

A new section requires the Evaluation Officer of each agency to provide Congress an annual evaluation of the Do Not Pay system including the best available estimate of effectiveness in reducing fraud and improper payments on a monthly and regional basis, with analysis of which data sources are attributed to identifying or reducing instances by count and total dollar savings.

A new voluntary expedited process for computer matching agreements was added under the Privacy Act. OMB must establish a standard template within 180 days that, upon execution, is deemed to satisfy Privacy Act requirements without Data Integrity Board review. Agreements have termination dates of less than 5 years (up from 3) and can be renewed for up to 5 years.

Data matching under the Do Not Pay system is now limited to inquiries that return a binary verification response, retain resulting data for no more than 30 days, and contain no more than 20 discrete record requests at a time for a particular agency program.

ENFORCEMENT

The penalty for knowing and willful unlawful disclosure of Do Not Pay system information was increased from a fine of not more than $5,000 to not more than $250,000 (imprisonment remains at 5 years).

The payment suspension penalty for recipients who fail to submit the required first-time use report was narrowed from preventing payment vouchers 'for any program funds' to only 'funds related to the particular program for which the report was required.'

TIMELINE

Congressional reporting on the Do Not Pay system was changed from an annual report to quarterly reports, with the content shifted from 'an evaluation of effectiveness' to 'performance measures for monitoring effectiveness.'

The public notice and comment period for designating categories of data assets containing personally identifiable information was reduced from 30 days to 15 days (the 30-day period for adding specific data assets within a designated category remains unchanged).

ELIGIBILITY

The exemption process for agencies was strengthened: the reference changed from 'guidance' to 'regulations,' and a new requirement was added that requesting agencies must provide a plan and reasonable timeframe to remediate the need for the exemption.

Floor votes

How they voted

This bill passed the House by voice vote (no roll call recorded).
Full legislative history

Actions timeline

Total actions
14
Key actions
4
Committee
4
Amendments
3
Jun 8, 2026
Introduced
On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H3919-3922)
lower
Jun 8, 2026
Lower · Passed
Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H3919-3922)
lower
Jun 8, 2026
Introduced
Mr. Gill (TX) moved to suspend the rules and pass the bill, as amended.
lower
Jun 8, 2026
Lower · Passed
Committee on Ways and Means discharged.
lower
Jun 8, 2026
Lower · Passed
Reported (Amended) by the Committee on Oversight and Government Reform. H. Rept. 119-688, Part I.
lower
Apr 29, 2026
Introduced
Ordered to be Reported (Amended) by the Yeas and Nays: 35 - 1.
lower
Apr 29, 2026
Lower · Passed
Committee Consideration and Mark-up Session Held
lower
Apr 23, 2026
Committee
Referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Ways and Means, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
lower
Apr 23, 2026
Introduced
Introduced in House
lower
1 primary · 3 co-sponsors

Sponsors