Kafkaesque Dangers: IPERIA, Do Not Pay, and the Government’s New Fight Against Improper Payments

I.     Introduction

     “The only thing that saves us from the bureaucracy is its inefficiency.”1

          —Eugene McCarthy

Throughout the last decade, the government has waged war on federally funded improper payments,2 which have recently ballooned to over $100 billion annually.3 In 2011, the government rolled out a powerful weapon to help agencies combat their improper payments: the “Do Not Pay” Initiative (“Do Not Pay”).4 Do Not Pay “allows agencies to check various data sources for pre-award, pre-payment eligibility verification, at the time of payment and any time in the payment lifecycle.”5 In essence, Do Not Pay serves as a one-stop shop for government and private sector payee data, allowing government agencies to automate their payee eligibility investigations through computer matching and data analytics.6

While Do Not Pay has been an effective tool in combating improper payments,7 automated investigation through computer matching raises individual privacy concerns.8 In The Digital Person, Professor Daniel Solove9 conceptualizes such concerns as a “Kafkaesque danger” after Franz Kafka’s dystopian novel, The Trial.10 Kafkaesque dangers involve data aggregation and automated investigation in a detached, bureaucratic governmental setting.11 Computer matching has raised the specter of Kafkaesque dangers at least since the 1980s when Congress amended the Privacy Act of 1974 (“Privacy Act”) to curtail government computer matching programs involving personal information.12

Fast-forward to 2012 and the Privacy Act amendment largely prevented government agencies from using the personal information contained in Do Not Pay’s databases to conduct computer matching activities.13 This was problematic because computer matching with personal information derives the very best, most conclusive improper payment results.14 The only way an agency could utilize Do Not Pay’s personal information was to acquire “permission” from the government agency that supplied the personal information to Do Not Pay in the first place. Under the Privacy Act, such permission comes in the form of a computer matching agreement (“CMA”),15 a difficult, administratively burdensome process for an agency to complete.16 Do Not Pay consists of several databases subject to Privacy Act protection—agencies therefore needed to complete at least one, if not more, CMAs before matching on Do Not Pay’s restricted databases.17 This administrative burden was simply too much for many agencies to bear.18 To alleviate this problem, legislators changed how the Privacy Act applies to Do Not Pay by passing the Improper Payments Elimination and Recovery Improvement Act of 2012 (“IPERIA”).19

IPERIA contains a key language change to the Privacy Act relating to the CMA requirements for Do Not Pay.20 The Office of Management and Budget (“OMB”) issued guidance M-13-20 interpreting this change to allow qualifying agencies to collectively satisfy the requirements of a CMA with Do Not Pay through one “multilateral CMA.”21 With a multilateral CMA, qualifying agencies may gain access to the personal information in Do Not Pay—and thus utilize its full computer matching capabilities—at only a fraction of the work it took prior to IPERIA.22 Together, Do Not Pay and IPERIA ushered in a new era of administrative efficiency in the CMA process.

This Note argues that IPERIA’s change to the Privacy Act raises important policy concerns for individual privacy and that the OMB should implement changes to address these concerns. Part II of this Note traces the recent history of the government’s fight against improper payments, leading up to the necessity and passing of IPERIA. Part III determines that IPERIA’s change to the Privacy Act raises Kafkaesque dangers from Do Not Pay, and then concludes that on balance, OMB’s M-13-20 guidance fails to mitigate the risks these dangers pose to individual privacy. Finally, Part IV proposes four key changes OMB can make to bolster individual privacy protections with the advent of the multilateral CMA. These changes call for greater oversight and effectiveness from the agency data integrity boards and new clarity in the qualifying test for the multilateral CMA option.

II.     Improper Payments and the Do Not Pay Initiative

A.     What are Improper Payments?

In 2002, Congress passed the Improper Payments Information Act (“IPIA”).23 This Act requires government agencies to identify, estimate, and report on the scale of their annual improper payments.24 It defined an improper payment as “any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements.”25 Just two pages in length, this Act would serve as the foundation for the government’s 21st-century fight against fraud, waste, and abuse in federally funded payments.26

With new reporting in place, the scale of improper payments came into focus. By fiscal year 2009, reporting found the government was making at least $100 billion in improper payments annually27—roughly the combined 2016 net worth of Mark Zuckerberg and Warren Buffett.28 But this number deserves some unpacking, as not all improper payments represent a loss to the government.29 A payment may be improper because it is: (1) an incorrect amount paid to eligible recipients; (2) a payment made to ineligible recipients; (3) a payment for goods or services not received; (4) a duplicate payment; or (5) a payment for which insufficient or no documentation was found.30 Thus, an improper payment may be due to some unintentional error, such as a lack of supporting documentation or a data entry mistake, rather than an intentional misuse of funds.31

On the other hand, an improper payment may be the result of fraud, waste, or abuse. In 2009, the Government Accountability Office found that improper payments may result from such illicit activities as: improper unemployment payments, bribery, kickbacks, bid rigging, over-billing of labor and materials, improperly paid tax refunds, unemployment payments, tax return filing fraud, overpayments to vendors or contractors, tax credits, Medicare/Medicaid spending, and more.32 Regardless of the cause, “improper payments degrade the integrity of government programs and compromise citizens’ trust in government.”33

In 2009, Barack Obama, a president far more publicly committed to government transparency than recent administrations, took office.34 The Obama Administration made significant strides in providing transparency into government payment information. For example, the Obama Administration established several government websites dedicated to providing robust, timely, and accurate information on government payment systems, processes, and success rates.35 The Obama Administration also noticed the high improper payment error rate and directed additional government resources to begin addressing the problem.36

B.     The Government Establishes the Do Not Pay Initiative

A Presidential Memorandum calling for “Enhanced Payment Accuracy Through a Do Not Pay List” established the Do Not Pay Initiative on June 18, 2010.37 Facially, the Memorandum presented a cognizable idea: make a list and check it twice before issuing a federally funded payment.38 However, the substance of the Memorandum made clear that President Obama intended something far more dynamic than a simple “list” of whom the government should or should not pay.

In his Memorandum, President Obama directed government agencies to adjust their pre-payment and pre-award procedures by reviewing payee eligibility against five government databases, designated as the “Do Not Pay List.”39 The “Do Not Pay List” databases include: Social Security Administration’s Death Master File,40 General Service Administration’s (“GSA”) Excluded Parties List System (“Excluded Parties”),41 the Department of the Treasury’s Debt Check Database,42 the Department of Housing and Urban Development’s Credit Alert System,43 and the Department of Health and Human Services’ (“HHS”) List of Excluded Individuals/Entities (“Excluded Individuals”).44 The Memorandum then called for the Director of the OMB to develop a plan to integrate these five databases into a “single entry point” for government agencies.45

Thus, the true design of President Obama’s “Do Not Pay List” was a government system that combines various government data sources into one repository of payee eligibility information, which is then made available to agencies to help identify and prevent improper payments.46 A government system that identifies improper payments before it issues them easily garnered bipartisan support47 as Congress shortly followed President Obama’s Memorandum by passing the Improper Payments Elimination and Recovery Act of 2010, which “incorporated most of the requirements of the June 18, 2010 Presidential Memorandum into law.”48

While the idea of a “Do Not Pay List” was appealing, developing and implementing such a program presented a daunting technological task.49 To effectuate the program, OMB directed the Bureau of the Fiscal Service to begin developing the “Do Not Pay List.”50 The Fiscal Service, in turn, leveraged its fiscal agent relationship with the Federal Reserve51 to provide for the various needs of the program such as technology development, user support, and customer service.52 Fiscal Service’s decision to use the Federal Reserve to develop the “Do Not Pay List” resulted in a dual benefit: Fiscal Service could leverage individual Reserve Bank strategic competencies while eliminating private sector profit margins.53

This partnership recast the “Do Not Pay List” as the “Do Not Pay Business Center,” a multi-functional analytics tool and one-stop data shop for government agencies to verify payee eligibility.54 By April 2012, the Do Not Pay Business Center was available for government agencies to use at no cost.55 Elizabeth Owens, Sikich LLP, and Carol M. Jessup, Associate Professor of Accounting with the University of Illinois Springfield, summarize some of the benefits of Do Not Pay as follows:

[Do Not Pay] helps prevent situations such as paying pension payments to a deceased person, paying a federal inmate or paying a contractor who has defrauded or attempted to defraud the government in the past. The user is able to look up a vendor to determine if he or she is excluded from receiving federal payments, ensure an individual receiving unemployment is still alive, determine if the vendor requires additional oversight due to past performance, and verify the accuracy of income.56

Reminiscent of President Obama’s Memorandum, Do Not Pay’s mission is to “[p]rotect the integrity of the government’s payment process by assisting agencies in mitigating and eliminating improper payments in a cost-effective manner while safeguarding the privacy of individuals.”57 Ironically, “safeguarding the privacy of individuals” would soon become one of the most significant administrative challenges to Do Not Pay’s success.

C.     Do Not Pay Initiative Results and Challenges

The year 2015 marked the five-year anniversary of the Do Not Pay Initiative. By several accounts, Do Not Pay has become an important tool in the government’s effort to reduce improper payments.58 During the period between fiscal year 2009 and 2013, the improper payment rate dropped 35%, representing a total improper payment avoidance of $93 billion.59 Moreover, based on the success of the program, OMB issued a Memorandum in 2012 directing all agencies to use the Do Not Pay Business Center.60 In 2014, the Brookings Institute listed Do Not Pay as one of its “Top 10 Tech Innovations That Will Transform Society and Governance.”61 In 2015, Congress passed the Federal Improper Payments Coordination Act, which expanded the reach of Do Not Pay to states and the judiciary, representing unprecedented government coverage for the program.62

But Do Not Pay’s success was not a guarantee. In its first year of operation, the Privacy Act, a law passed at the height of the Watergate scandal, presented a substantial roadblock to agency use of Do Not Pay.63 “The Privacy Act . . . governs the collection, maintenance, use, and dissemination of information about individuals that is maintained in systems of records by federal agencies.”64 A “‘system of records’ . . . [is] a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.”65

A 1988 amendment to the Privacy Act requires that “no record which is contained in a system of records may be disclosed to a recipient agency or non-[f]ederal agency for use in a computer matching program except pursuant to a written agreement between the source agency and the recipient agency or non-[f]ederal agency.”66 This means that, if an agency wants to share its system of record data for any computerized matching activities, it must establish a Computer Matching Agreement67 with the recipient agency or non-federal agency, unless it is exempted from Privacy Act requirements.68 Additionally, the respective agency’s data integrity board—a board comprised of senior agency personnel charged with overseeing and coordinating Privacy Act requirements for computer matching programs—must review and approve any new computer matching program.69

The Privacy Act significantly affected Do Not Pay, given that four out of the five databases in the “Do Not Pay List” were designated as a system of record.70 In practice, before any recipient agency could match its payee data against personal information—considered “restricted content”—within one of the system of record-designated databases in the “Do Not Pay List,” it needed to establish a CMA with the agency (or agencies) that supply the “Do Not Pay List” databases to Do Not Pay.71 For example, if Agency X wanted to match its payee data against restricted content in the Excluded Parties List and the Excluded Individuals List, Agency X needed to establish a CMA with, and receive data integrity board approval from, GSA and HHS respectively (Figure 1).72


Figure 1: Do Not Pay CMA Requirements Before IPERIA



Establishing a CMA is a difficult process; the Privacy Act enumerates 11 complex specifications that an agency must meet before a CMA is approved.73 Moreover, the Privacy Act’s CMA requirements have a broad reach, as there are hundreds of systems of records spanning numerous agencies.74 The policy rationale for these extensive requirements is principally to protect personal information from capricious government computer matching. Yet for a program like Do Not Pay, the Privacy Act created a substantial administrative burden for agencies wishing to match their payee data against the personal information contained in Do Not Pay.75

New administrative burdens are rarely met with excitement, and agencies began looking for alternative ways to satisfy OMB’s requirement to use Do Not Pay.76 It was not long before agencies discovered the Privacy Act’s CMA requirements could be circumvented through matching on the “public” versions of the “Do Not Pay List” databases.77 Several of the “Do Not Pay List” databases are available in both “public” and “restricted” versions, with the public version containing no personal information.78 Since the public versions contain no personal information, they do not trigger the Privacy Act requirements for a CMA.79 The end result? Agencies could quickly “satisfy” their requirement to use Do Not Pay without having to go through the rigmarole of establishing CMAs.

While this approach ostensibly relieved agencies of the need to complete CMAs, it also created a problem: matching without the aid of personal information produced less conclusive results and more false positives (a false positive is a match that is later found to involve an eligible payee and a proper payment).80 When an agency chooses to match against publicly available versions of a database, Do Not Pay must use only data that is available to the public (such as first and last names), rather than more conclusive data available only in the restricted version of a database, like social security or taxpayer identification numbers.81 By taking this lightweight approach to matching (i.e. matching on less conclusive data), the value of Do Not Pay is eroded and more manual work is created for agency users.82 Recognizing this as a threat to the long-term success of the program, Congress stepped in to change how the Privacy Act applies to Do Not Pay.83

III.     Improper Payment Elimination and Recovery Improvement Act

A.     The Purpose of IPERIA

U.S. Senator Tom Carper (D-DE) introduced the Improper Payment Elimination and Recovery Improvement Act in 2012 (“IPERIA”).84 A champion against improper payments, Senator Carper also introduced the Improper Payment Elimination and Recovery Act in 2010, and IPERIA represented the next crucial step in fighting improper payments.85 The stated purpose of IPERIA is “[t]o intensify efforts to identify, prevent, and recover payment error, waste, fraud, and abuse within Federal spending.”86 While IPERIA contained several important changes to how the government fights improper payments, section 5 directly addresses the Do Not Pay Initiative.87

Section 5 of IPERIA granted Do Not Pay the authority to establish itself as a system of record, which it promptly did.88 As a system of record, agencies wishing to match against restricted content in Do Not Pay now only need to establish one CMA with Do Not Pay, rather than multiple CMAs with source agencies.89 Thus, where Agency X previously had to establish two CMAs (one with GSA and one with HHS) to match against restricted content in the Excluded Parties List and Excluded Individuals List (Figure 1), after IPERIA, Agency X need only establish one CMA with Do Not Pay (Figure 2).90 Furthermore, if Agency X theoretically needed to match on all restricted databases in the “Do Not Pay List,” Agency X would still only need to establish one CMA with Do Not Pay.91 This change to the CMA process affords significant administrative efficiency for agencies and reduced the incentive to only use the public versions of the “Do Not Pay List” databases.


Figure 2: Do Not Pay CMA Requirements After IPERIA



But IPERIA does not stop there. Section 5 of IPERIA makes a key language change to how the Privacy Act applies to Do Not Pay.92 Section 5 of IPERIA inserts additional language into section 552a(o)(1) to read: “between the source agency and the recipient agency or non-Federal agency or an agreement governing multiple agencies.”93 In August 2013, OMB issued guidance M-13-20 explaining that this language change allows agencies to establish a “multilateral computer matching agreement” (“multilateral CMA”) with Do Not Pay.94 A multilateral CMA is a computer matching agreement that involves the Treasury (i.e., Do Not Pay) and two or more agencies for the purpose of establishing a Do Not Pay matching program.95 This change means that Agencies X, Y, and Z may collectively enter one multilateral CMA with Do Not Pay to gain access to Do Not Pay’s restricted content (Figure 3).


Figure 3: The Multilateral CMA



However, the M-13-20 guidance requires each recipient agency to qualify for the multilateral CMA. To qualify, agencies must show that “the matching purpose and the specific data elements that will be matched are sufficiently similar across each of the agencies to allow all parties to satisfy the requirements in a single CMA that is clear to all relevant agencies and to the public.”96 Before Agencies X, Y, and Z can enter a multilateral CMA, they must qualify through the above test. If all three qualify, they can now enter one multilateral CMA together with Do Not Pay. On the surface, this test sounds reasonable yet it is not clear what “sufficiently similar” means in the context of specific agency data elements. This leaves the door open for interpretation and, possibly, abuse.97

Arguably, allowing Do Not Pay to become a system of record, and thus a single CMA point of contact for agencies, still protects individual privacy interests from capricious computer matching.98 The multilateral CMA, however, is a groundbreaking development. The multilateral CMA significantly expedites OMB’s directive for all agencies to use Do Not Pay99 by allowing more agencies to onboard100 in a shorter time and with greater ease.101 It is unclear how many agencies may qualify for a multilateral CMA, but Congress’s change to the Privacy Act indicates there is definite interest in such an option. This development raises some troubling policy concerns.

B.     Balancing Administrative Efficiency and Individual Privacy Interests

IPERIA’s change to the Privacy Act and OMB’s guidance establishing the multilateral CMA, collectively, beg the question as to whether IPERIA’s new administrative efficiencies sacrifice too much privacy protection. On the one hand, IPERIA updates the Privacy Act by helping to reduce redundancies in the CMA process and aiding the government’s fight against improper payments.102 On the other hand, IPERIA erodes the Privacy Act’s CMA requirements—individual privacy protection—to allow more agencies to engage in advanced automated investigation activities through Do Not Pay’s computer matching capabilities.103 Further underscoring concerns over invasion of individual privacy, since Congress passed IPERIA, congressional and Treasury budget reports indicate Do Not Pay has spent tens of millions of dollars on improving its investigation technologies and acquiring more data.104

How one views IPERIA depends on the balance of interests between the new administrative efficiency of the multilateral CMA and individual privacy interests affected under the Privacy Act. In Understanding Privacy, Professor Solove writes: “To properly weigh privacy against conflicting interests, it is imperative that we have a complete understanding of the particular privacy problems involved in any given context. We must identify the privacy problems, examine the activities compromised by each, and recognize the nature of harms to these activities.”105 To achieve this complete understanding, this Note seeks to identify and weigh the privacy problems IPERIA raises to determine the appropriate balance between administrative efficiency and individual privacy as it relates to the multilateral CMA.

To conduct this analysis, Solove provides a helpful framework in The Digital Person.106 Solove defines two paradigms of privacy based on twentieth century dystopian novels: an Orwellian paradigm and a Kafkaesque paradigm.107 The characteristics of the Orwellian paradigm of privacy are government surveillance, secrecy, and attempts at societal control.108 The Kafkaesque paradigm captures concerns of data aggregation and automated investigation in a detached and bureaucratic governmental setting.109 In a government context, Solove recognizes that there are dangers from both paradigms.110 The Orwellian dangers include: (1) a slow creep towards totalitarianism; (2) a detrimental impact to democracy and self-determination; (3) interference with freedom of association; and (4) loss of anonymity.111 The Kafkaesque dangers include: (1) leaks, lapses, and vulnerability; (2) automated investigations and profiling; and (3) changing purposes and uses.112

By analyzing IPERIA’s changes to the CMA process for Do Not Pay through these two paradigms, the balance between administrative efficiency and individual privacy interests comes into focus. If Do Not Pay poses Orwellian dangers after IPERIA, it almost certainly represents an erosion of individual privacy interests.113 On the other hand, if Do Not Pay falls within the Kafkaesque paradigm, the impact to individual privacy interests may be more attenuated.114 In that case, this Note proposes that a risk analysis of the Kafkaesque dangers is necessary to better understand whether IPERIA actually creates valuable administrative efficiencies or facilitates a system that invades individual privacy through automated investigation activities.115

1.     IPERIA Falls Squarely Within the Kafkaesque Paradigm

It seems fairly clear that IPERIA’s effect on Do Not Pay does not pose the sort of Orwellian dangers contemplated by Solove.116 The defining theme amongst these dangers is some direct governmental interference with an individual’s privacy.117 Whether that interference is in the form of social control, freedom of speech, privacy in one’s associations, or the ability to send and receive information freely, the Orwellian paradigm signifies the establishment and expansion of a surveillance state.118 IPERIA’s change to how agencies engage Do Not Pay through the CMA process does not readily invite these types of dangers.119 For example, unlike government surveillance programs, IPERIA does not facilitate direct data aggregation from an unaware public.120 Instead, IPERIA reduces the administrative burden for agencies seeking to engage Do Not Pay for restricted computer matching on data already collected through normal government agency processes.121

Under the Kafkaesque paradigm, on the other hand, Do Not Pay poses dangers that are immediately more apparent after IPERIA. By reducing the administrative burden of the CMA process, IPERIA facilitates agencies’ access to restricted content in Do Not Pay, leading to more payee investigation activities.122 More investigation means more payee personal information in the Do Not Pay system, making the Kafkaesque danger of leaks, lapses, and vulnerabilities (i.e., data breaches123) more perilous.124 Data breaches can be incredibly costly and can cause irreparable harm for all parties involved.125 If Do Not Pay experienced a data breach, that breach not only could expose personal information but could also cause the government to suffer significant reputational damage.126 A string of high profile data breaches since 2000 demonstrate this danger all too well.127

Automated investigation is the principal Kafkaesque danger that results from computer matching under IPERIA.128 With the use of computer matching, the government can automate the investigation of millions of people.129 IPERIA makes the process significantly easier for qualifying agencies to enter a CMA with Do Not Pay because of IPERIA’s multilateral CMA process.130 That ease of process, in turn, will lead to more automated investigation of individual payees.131 More automated investigation will likely result in the discovery of additional instances of fraud and improper payments—which is a good thing.132 At the same time however, automated investigation is a fundamentally different way to investigate individuals.133

Typically, the government must have some factual basis to conduct individualized investigative activities.134 With Do Not Pay however, an agency has the option of conducting one giant investigation of numerous payees through “batch matching.”135 Or, an agency may choose to constantly investigate its payees through a “continuous monitoring” service.136 These computer matching services give agencies the ability to constantly investigate their payees. The Kafkaesque danger is that these automated investigations allow the government to deeply and continuously intrude into the lives and affairs of its people.137 Automated investigation through computer matching does not discriminate, and unfortunately most people the system investigates are innocent.138

IPERIA also raises the Kafkaesque danger that Do Not Pay will engage in profiling139 through its Data Analytics Services.140 As Do Not Pay investigates more agency payee data, Do Not Pay will have more opportunities to develop comprehensive profiles as part of a larger effort to forecast fraudulent behaviors.141 Borrowing from a private sector example of knowledge-based marketing, profiling presents one of three “major areas of application of data mining,”142 with the other two being trend and deviation analysis.143 The Do Not Pay Analytics Services already advertises that it “analyzes data and trends” and engages in “conduct reporting,”144 both of which parallel the aims of trend and deviation analysis.145 Developing profiles and “discovering”146 new information about fraudsters surely presents an attractive, albeit dubious,147 data mining application to further Do Not Pay’s fight against improper payments.148

The problem with profiles is that they can be wrong, inaccurate, or mistaken.149 Profiling supports decision-making based on past data, which can be stale or incomplete.150 While speculative, it is possible that Do Not Pay’s Analytics Services could inaccurately profile an individual as a fraudster.151 That profile, in turn, could lead to an adverse information investigation, a process by which the payment-issuing agency verifies the adverse information that Do Not Pay discovers about the payee.152 This investigation would require the individual to contest the adverse information, creating unnecessary headache and hassle.153 Another issue with profiling is that more data does not always lead to better insights.154 Even as agencies more extensively use Do Not Pay after IPERIA, Do Not Pay’s profiling capabilities may not experience a corresponding improvement. Rather, Do Not Pay’s profiling capabilities may plateau, and the plateau may not be particularly effective or accurate.

Finally, changing purposes and uses of the Do Not Pay program present a cognizable Kafkaesque danger.155 As Solove points out, data obtained by the government for one purpose may readily be used for a different purpose as motives change.156 For Do Not Pay, as IPERIA facilitates agency use of Do Not Pay’s automated investigation capabilities, the possibility increases that another governmental agency will find other purposes for the Do Not Pay program, such as financial crime investigation.157 This possibility is bolstered by Do Not Pay’s ability to combine government and commercial data sources, creating new and unique datasets to investigate.158 Changing purposes and uses of Do Not Pay could engender more government data aggregation and computer matching, further implicating individual privacy interests.

2.     IPERIA Mitigates Kafkaesque Dangers, but Concerns Remain

Recognizing that IPERIA likely raises Kafkaesque dangers, this Note argues that a risk analysis is necessary to understand the threat of these dangers to individual privacy interests.159 If there is a high risk that these dangers will occur, IPERIA poses a threat to individual privacy interests. A low risk, by contrast, means IPERIA does not significantly threaten individual privacy. To determine the risk level, this Note weighs IPERIA’s Kafkaesque dangers against its mitigating factors.160 Mitigating factors would tend to reduce the risk level posed from IPERIA’s Kafkaesque dangers, thereby reducing the threat to individual privacy.161 IPERIA has two primary mitigating factors: its scope and privacy safeguards.162

First, IPERIA’s purpose illustrates its narrow scope—IPERIA’s specific purpose is to address improper payments and the complex issues surrounding improper payments.163 The scope of this purpose further narrows when looking at IPERIA’s Privacy Act changes related to the multilateral CMA and Do Not Pay.164 Since IPERIA allows the multilateral CMA process for Do Not Pay matching programs only, IPERIA retains the Privacy Act’s default posture on CMAs for all other agencies.165 IPERIA could have exempted Do Not Pay from CMA requirements altogether, thereby eliminating all Privacy Act protection.166 Instead, it arguably creates a program-level approach to the CMA process.167

Second, IPERIA contains individual safeguards to protect privacy interests. For example, section 5 requires program transparency through annual reporting requirements on Do Not Pay’s operations, including an evaluation of whether Do Not Pay reduces improper payments.168 Section 5 also requires OMB to establish guidance on data quality issues involving the retention, timely destruction, and correction of Do Not Pay’s data in accordance with the Privacy Act.169 This guidance is a critical safeguard, as maintaining high data quality is important in any computer program, but particularly where automated investigations are occurring.170 Finally, Section 5 gives OMB authority to develop new guidance for the data integrity boards to: (1) “improve the effectiveness and responsiveness”; (2) “ensure privacy protections in accordance with the Privacy Act”; and (3) “establish standard matching agreements for use when appropriate.”171

As previously discussed, the data integrity boards are the approving bodies for new matching programs.172 Among other responsibilities, the Privacy Act charges the data integrity boards with annual reporting on certain key topics, such as: (1) proposed matching agreements that the board disapproved; (2) changes in board membership or structure; and (3) alleged or identified violations of matching agreements and any corrective action taken.173 Data integrity boards must also provide guidance to their agency constituents on matching program requirements.174

Following IPERIA, OMB’s M-13-20 guidance further clarifies that each payment-issuing agency’s data integrity board must review any CMA that an agency enters into with Do Not Pay.175 Moreover, whenever agencies enter into a multilateral CMA, the data integrity boards are responsible for ensuring that, if a single agency is designated to perform the CMA reporting requirements, the designation of that agency is appropriate.176 This means that instead of all agencies performing the required CMA reporting, one agency may be designated to report for all agencies involved in the multilateral CMA.177 Finally, M-13-20 tasks the data integrity boards with ensuring CMAs fully comply with the Privacy Act before they approve any new proposed matching program.178

IPERIA’s message about the data integrity boards is clear: these boards are the frontline for enforcing Privacy Act protections, particularly with respect to Do Not Pay.179 Successful board performance is therefore critical to ensuring a proper balance between administrative efficiency and individual privacy interests.180 With this goal in mind, the M-13-20 guidance outlines new data integrity board requirements to ensure each board performs its duties effectively and responsively.181 This guidance includes new requirements for annual meetings, board member training on the Privacy Act, and oversight responsibilities for the Senior Agency Official for Privacy (“privacy officer”),182 who is responsible for an agency’s “compliance with federal laws, regulations, and policies relating to information privacy, such as the Privacy Act.”183

IPERIA significantly mitigates the risk level of Do Not Pay’s Kafkaesque dangers.184 IPERIA’s narrow scope and individual privacy safeguards clearly demonstrate Congress’ concern for individual privacy interests.185 To that end, IPERIA lays a solid foundation for privacy protection measures even as it opens the door to new administrative efficiencies.186 However, OMB’s M-13-20 guidance is neither clear enough nor goes far enough in building upon that foundation. This shortcoming is particularly true when it comes to the data integrity boards and the qualifying test for a multilateral CMA. This Note now calls on OMB to take additional measures to ensure against the risk of Kafkaesque dangers as Do Not Pay engages in more automated investigation activities post-IPERIA.

IV.     OMB Should Issue Additional Guidance

As previously discussed, the multilateral CMA is a groundbreaking development and raises concerns that the government is eschewing Privacy Act requirements for administrative efficiency. OMB’s M-13-20 guidance was an important first step in alleviating this concern, but more guidance is necessary to ensure that agencies do not abuse the multilateral CMA. The lack of specificity in the M-13-20 guidance creates ambiguities in how the data integrity boards effectively approach their role and how agencies engage in the multilateral CMA process.

To ensure these ambiguities do not elevate to Kafkaesque dangers, OMB should achieve the following three objectives with the data integrity boards through new guidance: (1) increase board effectiveness by implementing new, or updating current, operational requirements; (2) establish annual recertification requirements for Privacy Act training; and (3) require effectiveness assessments in conjunction with the privacy officer. Finally, OMB should define what “sufficiently similar” means in the multilateral CMA qualifying test.187

A.     Increase Data Integrity Board Effectiveness on Three Fronts

Data integrity boards decide whether to establish a proposed matching program—a critical role in privacy protection.188 This role is particularly important after IPERIA, which calls for new OMB guidance on board effectiveness in ensuring matching programs comply with the Privacy Act.189 Effectiveness is defined as “the degree to which something is successful in producing a desired result,”190 and a desired result of IPERIA is for the boards to protect individual privacy while overseeing new administrative efficiency in the multilateral CMA process.191 To achieve both ends effectively, the boards must do more than what the M-13-20 guidance contemplates.192 The following three requirements will increase board effectiveness:
(1) semiannual board meetings; (2) interagency knowledge sharing; and
(3) regular strategic planning.

1.     Semiannual Board Meetings

OMB should require the data integrity boards to meet internally at least semiannually rather than the annual meeting required in the M-13-20 guidance.193 Given the importance of the board, and the gravity of issues the board faces when deciding on new matching programs, meeting once a year is simply not enough.194 While OMB does provide that the boards should “meet with sufficient frequency to ensure that matching programs are carried out efficiently, expeditiously, and in compliance with the law,” this guidance is largely a subjective standard that data integrity boards might neglect or flat-out ignore.195 Requiring semiannual or even quarterly meetings in some cases will ensure the data integrity board takes its role as seriously as IPERIA contemplates.196 More importantly, it will facilitate responsiveness in board determinations on proposed matching programs—a general effectiveness goal of M-13-20.197

2.     Interagency Knowledge Sharing

OMB should require the data integrity boards to engage in interagency knowledge sharing activities. Knowledge sharing is the process of converting knowledge “into a form that can be understood, absorbed, and used by other individuals.”198 Knowledge sharing moves knowledge to the organizational level where it is transformed into organizational value and collectively shared.199 Most importantly, knowledge sharing “provides strategic advantages for government to improve decision-making and enhance the quality of services and programs.”200

Requiring interagency knowledge-sharing activities amongst the data integrity boards would benefit individual privacy protection and administrative efficiency. For example, knowledge sharing allows dissemination of board best practices201 and lessons learned.202 Knowledge sharing also facilitates informal relationship building, something that may prove valuable for the boards as agencies collaboratively engage in the multilateral CMA process.203 Finally, knowledge sharing may help the boards identify issues with proposed matching programs more quickly and more effectively than they might otherwise have by operating in a vacuum.204 How the boards actually engage in knowledge-sharing activities should be left for each to decide;205 however, OMB should broadly require (and facilitate where needed) such activities, as well as routine reporting on knowledge sharing successes and challenges.

3.     Strategic Planning

The goal of strategic planning is to increase board effectiveness generally, thereby increasing assurance that the boards will respect individual privacy protections as they carry out their role. Thus, OMB should require the data integrity boards to engage in regular strategic planning to encourage effective decision-making and operations.206 While some boards may already engage in strategic planning activities, establishing it as a requirement sends the signal that OMB expects all boards to be effective bodies within their respective agencies.207 To support this requirement, OMB should establish a broad topic framework for the boards to utilize. This framework should include, at a minimum, general board operating procedures such as succession planning, matching program review processes, and strategies to effectively meet the various board reporting obligations.

B.     Establish Annual Recertification Requirements for the Data Integrity Boards

OMB’s M-13-20 guidance directs each agency’s privacy officer to develop a training program for board members on Privacy Act-related issues.208 The training must include information on “the requirements in the Privacy Act, other relevant laws, and guidance from OMB, [National Archives and Records Administration], and the Department of Commerce’s National Institute of Standards and Technology.”209 While some agencies’ privacy officers may be able to establish a successful training program, OMB should take a more proactive role in ensuring all of the data integrity boards are properly trained in these areas. Allowing each agency’s privacy officer to develop the program for each agency raises concerns of training variation, subjectivity, and incompleteness.

OMB should therefore develop its own training program through an annual certification.210 By standardizing211 the data integrity board training in this way, OMB will best uphold IPERIA’s intent for the boards to ensure privacy protections are met by helping the boards be as adequately informed as possible on the Privacy Act and other relevant laws.212 The benefit of a certification program is that it ensures board members have met OMB’s specific requirements to perform their role.213 Moreover, requiring annual recertification is an effective way for the boards to remain trained on the government and industry standards critical to their role, such as data handling, retention, destruction, and correction.214 As these standards evolve over time, an annual recertification requirement will ensure that board members remain abreast of key changes.215

A potential downside of this approach is that it may create internal conflict between OMB and the agencies’ privacy officers over their efforts to develop training materials after OMB initially issued its M-13-20 guidance. To alleviate these concerns, OMB should involve interested privacy officers as subject matter experts216 and stakeholders217 wherever possible. A collaborative approach between OMB and the privacy officer will ensure that the process captures lessons learned and best practices,218 while reducing the chances of internal conflicts. Once OMB develops the certification training, OMB should once again leverage these privacy officers to ensure data integrity board members complete annual recertification requirements in a timely manner.

C.     Require Data Integrity Boards to Self-Assess Their Effectiveness with the Privacy Officer

OMB’s M-13-20 guidance grants the privacy officer an important oversight role. M-13-20 requires the privacy officer to “periodically review the effectiveness and responsiveness” of the data integrity board and then determine whether the board needs additional guidance.219 But OMB provides no information on how the privacy officer should determine whether additional guidance is needed.220 OMB also does not address potential conflicts of interest that exist between the data integrity boards and the privacy officer, even though the two roles are within the same agency.221 To alleviate these concerns, OMB should issue new guidance that requires the data integrity boards to self-assess their effectiveness collaboratively with the privacy officer, using an objective framework or checklist.

Assessing effectiveness can be a complex and rigorous process.222 However, a growing body of research has developed regarding governance best practices and organizational effectiveness.223 OMB should take advantage of this research and promulgate an assessment tool based on leading research in this field, or adapt for use an existing self-assessment tool, such as the Governance Self-Assessment Checklist, Board Self-Assessment Questionnaire, or the Benchmarks of Excellence tool.224 In either case, requiring the data integrity boards to assess their effectiveness in partnership with the privacy officer should result in several benefits.

First, a collaborative assessment of effectiveness directly involves the privacy officer in the process of identifying and rating various board strengths, weaknesses, and internal challenges.225 This involvement should naturally result in better insights and greater information sharing amongst the boards and privacy officers regarding board effectiveness. Better insights and greater information sharing will allow the privacy officer to report more knowledgably to OMB about data integrity board effectiveness and responsiveness, pursuant to OMB’s M-13-20 guidance.226 Second, bringing the privacy officer into the board self-assessment process brings in a perspective outside of the board, which can result in a more insightful assessment.227 These benefits should translate into a qualitative improvement in privacy officer oversight.

As the quality of the privacy officer’s oversight improves, so too should the level of confidence that the boards are carrying out their role effectively. As data integrity boards are the frontline for ensuring that the government respects and enforces the Privacy Act, proper privacy officer oversight is critical to ensuring the boards are effective in managing new administrative efficiencies through the multilateral CMA. OMB should empower each agency’s privacy officer, to the greatest extent possible, to carry out his or her oversight mission. Requiring a closer partnership between the data integrity boards and the privacy officers through a collaborative self-assessment of board effectiveness is a powerful measure to ensure that the privacy officer has effective oversight.

D.     Define What “Sufficiently Similar” Means in the Context of Data Elements

As previously discussed, the multilateral CMA allows for more efficient access to restricted personal information content in Do Not Pay, resulting in increased automated investigation of agency payees through computer matching.228 The multilateral CMA, therefore, enhances administrative efficiency, but it does not add anything by way of individual privacy protection.229 Recognizing this deficiency, OMB’s M-13-20 guidance erects a countervailing privacy protection hurdle for the multilateral CMA in the form of a qualifying test requiring “the matching purpose and the specific data elements” to be “sufficiently similar.”230 However, the test misses the mark in a critical way: OMB does not define what it means by “sufficiently similar.”231

A data integrity board could interpret this “sufficiently similar” requirement broadly or narrowly.232 A broad reading could imply that individual data elements contained within one dataset must be similar, but not exact, to individual data elements in another dataset to be sufficiently similar. For example, one data set containing a data element titled LAST_FIRST_NAME and another dataset containing the data element LAST_NAME could be sufficiently similar under this reading, as one dataset contains a subset of the other. A narrow reading, however, could require a specified percentage of data elements within an agency’s dataset to be identical to the data elements contained within another agency’s dataset, determined on a case-by-case basis by the reviewing data integrity boards. For example, a data integrity board may determine that between Agencies X, Y, and Z, 30% of their individual data elements must be identical to be sufficiently similar.

The problem with a broad reading is that it allows a greater number of agencies to satisfy the first prong of M-13-20’s test for a multilateral CMA, perhaps improperly. This opens the door for misuse and controverts IPERIA’s intent to balance administrative efficiency with privacy protections.233 To ensure that agencies appropriately use the multilateral CMA, OMB should clarify its M-13-20 guidance by adopting the narrow reading. In requiring agencies to prove their datasets are sufficiently similar by showing a percentage of identical data elements, OMB ensures agencies utilizing a multilateral CMA have a legitimate need. The multilateral CMA should not be an easy or expedient option; rather, it should be an exception to the Privacy Act rules for a CMA.

A narrow reading also gives data integrity boards the ability to establish the required percentage of data elements that must be identical to prove out that the datasets are sufficiently similar. Since agencies will have varying amounts of data elements within their datasets, data integrity boards should individually evaluate each proposed multilateral CMA to determine the appropriate percentage. The boards could take into account such factors as: (1) how many agencies are entering the multilateral CMA; (2) the size of each agency’s dataset; and (3) the desired level of individual privacy protection.234 As a general rule, requiring a higher percentage of identical data elements will translate to greater individual privacy protection.235 OMB should promulgate new guidance to address this concern and update M-13-20’s test accordingly.    

V.     Conclusion

IPERIA is a groundbreaking development in the course of the Do Not Pay program. The ability for several agencies to utilize one multilateral CMA to access restricted personal information content in Do Not Pay portends a new era in automated investigation through computer matching. OMB should guard against the dangers to individual privacy that this new era presents, and the best way to do so is to build upon IPERIA’s privacy safeguards. The M-13-20 guidance was a start, but OMB should now promulgate new guidance that strengthens and clarifies M-13-20. Doing so will ensure appropriate use of the multilateral CMA and maintain the balance between administrative efficiency and individual privacy interests. The government should fight hard against improper payments, but it must respect individual privacy while doing so.


J.D. Candidate, The University of Iowa College of Law, 2017; M.B.A. Management, Rockhurst University, 2013; B.A. Economics, Political Science, Rockhurst University, 2011.

I would like to thank my wife Katelyn for her love and support, my family for their continued encouragement, and all of the talented individuals on the Iowa Law Review. I dedicate this Note to my late father, Dick Clark, who is greatly missed by friends and family.