BlackLeafwatch the watchmen
Federal grant disbursement and payment-system oversight (HHS Program Support Center)

HHS's $860B grant-payment system took 9 months to flag $7.8M fraud

Summary

HHS's Program Support Center moves $860 billion a year in federal grant money through its Payment Management System. When bad actors began diverting funds by impersonating grant recipients in March 2023, the PSC officials who knew -- first the Payment Management Services Director, then the system's security officer -- didn't tell PSC leadership. Leadership wasn't informed until nine months later, and even then the tip came from a different federal agency, not PSC itself. By the time the scheme was contained, bad actors had diverted over $10 million and cost HHS a net $7.8 million. Over a year after the fraud was first reported, HHS's inspector general found 31 of 54 flagged security weaknesses in the same payment system still weren't fixed within their required deadlines.

By Marcus Aurelius · July 17, 2026

's own inspector general titled its audit around the fact that the agency "has begun taking corrective actions." The audit's own numbers make that framing worth doubting: a $7.8 million fraud went unreported to leadership for nine months, and over a year after it was first reported, most of the security weaknesses it exposed still weren't fixed on schedule.

How the fraud worked

The Payment System is the fiscal intermediary between grant-awarding agencies and grant recipients across the federal government: in 2023 it processed over 499,000 transactions totaling more than $860 billion, and roughly 28% of its transactions serve non- agencies. Starting in March 2023, bad actors gained access by using fake grant-recipient email addresses to request system access, then masqueraded as recipients -- deleting valid users, changing bank account details, and redirecting payments to their own accounts. The scheme touched 10 grants across 7 recipients before it was contained.

Nine months of silence

An affected grant recipient reported an initial series of fraudulent withdrawals to the Payment Management Services Director on March 28, 2023; by then, bad actors had taken a cumulative $643,733. The Director referred it to the system's security officer, who ruled it a non-cyber issue and out of scope, then reported it to 's Office of Inspector General -- but never told PSC leadership. PSC leadership wasn't informed until January 3, 2024, over nine months later, and even then the notification came from the Health Resources and Services Administration's chief operating officer, a grant-awarding agency, not from Payment Management Services. The Director who sat on the initial report resigned in June 2024.

Net loss to HHS
$7.8M
from over $10M diverted gross; banks blocked over $2M before it reached the bad actors
Before PSC leadership knew
9+ months
first fraud reported Mar. 28, 2023; PSC leadership informed Jan. 3, 2024 -- and that tip came from another federal agency, not Payment Management Services
Security fixes still overdue
31 of 54
as of July 25, 2024, over a year after the fraud began; none of the 54 corrective-action plans included a required funding determination
How $10 million in diverted grants became a $7.8 million loss
Grant funds diverted from HHS's Payment Management System, March 2023-January 2024
Diverted to bad actors' accounts (gross)
10
Rejected by banks before deposit
2
Net loss booked by HHS
7.8
Source: HHS-OIG audit A-18-24-03700 (June 2025)
View data as table
OIG's own figures are stated as "over" round numbers, not exact totals -- gross diverted and bank-rejected amounts are floors, not precise sums.
Diverted to bad actors' accounts (gross)10OIG states "over $10 million"
Rejected by banks before deposit2OIG states "over $2 million"
Net loss booked by HHS7.8the final, actual loss figure

Over a year later, most fixes were still late

traced the breakdown partly to staffing: PSC relied on manual controls that required trained personnel, but high vacancy and turnover rates left it short of the people needed to run them. The gaps outlasted the fraud itself -- as of July 25, 2024, PSC had logged 54 documented security weaknesses in the Payment System, and 31 of them, including the one rated most severe, had blown past their required fix deadlines. None of the 54 corrective-action plans included the funding determination federal rules require.

Flagged security weaknesses ran years past their deadlines
Days a Payment System weakness exceeded its required fix deadline, by risk severity (as of July 25, 2024)
Critical (1 weakness, 15-day requirement)
100
High (2 weaknesses, 30-day requirement)
175
Moderate (4 weaknesses, 90-day requirement)
1,430
Low (24 weaknesses, 365-day requirement)
567
Source: HHS-OIG audit A-18-24-03700 (June 2025)
View data as table
31 of 54 documented weaknesses in the Payment System were not fixed within their required timeframes -- including the one rated most severe.
Critical severity -- 1 weakness, required within 15 days100 days over deadline
High severity -- 2 weaknesses, required within 30 days175 days over deadline
Moderate severity -- 4 weaknesses, required within 90 days1,430 days over deadline
Low severity -- 24 weaknesses, required within 365 days567 days over deadline

The takeaway

  • "Has begun taking corrective actions" is doing a lot of work in that title. Over a year after the fraud was first reported, 31 of 54 documented weaknesses -- including the one rated most severe -- still weren't fixed within their required deadlines, and none of the 54 corrective-action plans even recorded whether funding existed to fix them.
  • The report never reached leadership -- for nine months. The Payment Management Services Director learned on March 28, 2023 of an initial series of fraudulent withdrawals -- $643,733 by that point -- and looped in the system's security officer, who ruled it out of his scope in April. Neither told PSC leadership. Leadership didn't hear about it until a different federal agency told them -- over nine months after that first report, with the loss nearly $7 million higher.
  • A $7.8 million loss is small next to $860 billion -- which is itself worth noting. The Payment System moves that much a year for and several other federal agencies. The scale that makes the loss look minor is the same scale that should have made basic account-verification controls non-negotiable, not optional.

's own dollar figures for the gross diverted amount ("over $10 million") and bank-rejected amount ("over $2 million") are stated as floors, not exact totals; the $7.8 million net-loss figure is the report's precise, final number. All figures come from - audit A-18-24-03700 (June 2025), which reviewed Payment System controls in place from March 1, 2023 through March 31, 2024 and was conducted through in-person fieldwork at PSC's Rockville, Maryland office. PSC concurred with all six of 's recommendations and told it has begun implementing fixes, including automated bank-account verification and new escalation procedures, though as of the audit's fieldwork most of the systemic weaknesses identified remained open.

Sources(1) ▾
  • U.S. Department of Health and Human Services, Office of Inspector General, HHS's Grant Payment System Lacked Effective Internal Controls To Prevent $7.8 Million in Fraud, and HHS Has Begun Taking Corrective Actions To Reduce Fraud Risk (A-18-24-03700) (2025-06-18)-'s audit of internal controls, risk management, and cybersecurity over the Payment Management System operated by 's Program Support Center -- the fiscal intermediary that processes grant payments for all agencies and several non- federal agencies. Covers controls in place March 1, 2023 through March 31, 2024, the period during which bad actors diverted grant funds by impersonating recipients. Fetched directly and converted with pdftotext -layout. oig.hhs.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account