HHS's $860B grant-payment system took 9 months to flag $7.8M fraud
Summary
HHS's Program Support Center moves $860 billion a year in federal grant money through its Payment Management System. When bad actors began diverting funds by impersonating grant recipients in March 2023, the PSC officials who knew -- first the Payment Management Services Director, then the system's security officer -- didn't tell PSC leadership. Leadership wasn't informed until nine months later, and even then the tip came from a different federal agency, not PSC itself. By the time the scheme was contained, bad actors had diverted over $10 million and cost HHS a net $7.8 million. Over a year after the fraud was first reported, HHS's inspector general found 31 of 54 flagged security weaknesses in the same payment system still weren't fixed within their required deadlines.
How the fraud worked
The Payment System is the fiscal intermediary between grant-awarding agencies and grant recipients across the federal government: in 2023 it processed over 499,000 transactions totaling more than $860 billion⧉, and roughly 28% of its transactions serve non- agencies. Starting in March 2023, bad actors gained access by using fake grant-recipient email addresses⧉ to request system access, then masqueraded as recipients -- deleting valid users, changing bank account details, and redirecting payments to their own accounts. The scheme touched 10 grants across 7 recipients before it was contained.
Nine months of silence
An affected grant recipient reported an initial series of fraudulent withdrawals to the Payment Management Services Director on March 28, 2023; by then, bad actors had taken a cumulative $643,733⧉. The Director referred it to the system's security officer, who ruled it a non-cyber issue and out of scope, then reported it to 's Office of Inspector General -- but never told PSC leadership. PSC leadership wasn't informed until January 3, 2024⧉, over nine months later, and even then the notification came from the Health Resources and Services Administration's chief operating officer, a grant-awarding agency, not from Payment Management Services. The Director who sat on the initial report resigned in June 2024.
View data as table
| Diverted to bad actors' accounts (gross) | 10 | OIG states "over $10 million" |
|---|---|---|
| Rejected by banks before deposit | 2 | OIG states "over $2 million" |
| Net loss booked by HHS | 7.8 | the final, actual loss figure |
Over a year later, most fixes were still late
traced the breakdown partly to staffing: PSC relied on manual controls that required trained personnel⧉, but high vacancy and turnover rates left it short of the people needed to run them. The gaps outlasted the fraud itself -- as of July 25, 2024, PSC had logged 54 documented security weaknesses⧉ in the Payment System, and 31 of them, including the one rated most severe, had blown past their required fix deadlines. None of the 54 corrective-action plans included the funding determination federal rules require.
View data as table
| Critical severity -- 1 weakness, required within 15 days | 100 days over deadline |
|---|---|
| High severity -- 2 weaknesses, required within 30 days | 175 days over deadline |
| Moderate severity -- 4 weaknesses, required within 90 days | 1,430 days over deadline |
| Low severity -- 24 weaknesses, required within 365 days | 567 days over deadline |
The takeaway
- "Has begun taking corrective actions" is doing a lot of work in that title. Over a year after the fraud was first reported, 31 of 54 documented weaknesses -- including the one rated most severe -- still weren't fixed within their required deadlines, and none of the 54 corrective-action plans even recorded whether funding existed to fix them.
- The report never reached leadership -- for nine months. The Payment Management Services Director learned on March 28, 2023 of an initial series of fraudulent withdrawals -- $643,733 by that point -- and looped in the system's security officer, who ruled it out of his scope in April. Neither told PSC leadership. Leadership didn't hear about it until a different federal agency told them -- over nine months after that first report, with the loss nearly $7 million higher.
- A $7.8 million loss is small next to $860 billion -- which is itself worth noting. The Payment System moves that much a year for and several other federal agencies. The scale that makes the loss look minor is the same scale that should have made basic account-verification controls non-negotiable, not optional.
's own dollar figures for the gross diverted amount ("over $10 million") and bank-rejected amount ("over $2 million") are stated as floors, not exact totals; the $7.8 million net-loss figure is the report's precise, final number. All figures come from - audit A-18-24-03700 (June 2025), which reviewed Payment System controls in place from March 1, 2023 through March 31, 2024 and was conducted through in-person fieldwork at PSC's Rockville, Maryland office. PSC concurred with all six of 's recommendations and told it has begun implementing fixes, including automated bank-account verification and new escalation procedures, though as of the audit's fieldwork most of the systemic weaknesses identified remained open.
Sources(1) ▾
- U.S. Department of Health and Human Services, Office of Inspector General, HHS's Grant Payment System Lacked Effective Internal Controls To Prevent $7.8 Million in Fraud, and HHS Has Begun Taking Corrective Actions To Reduce Fraud Risk (A-18-24-03700) (2025-06-18) — -'s audit of internal controls, risk management, and cybersecurity over the Payment Management System operated by 's Program Support Center -- the fiscal intermediary that processes grant payments for all agencies and several non- federal agencies. Covers controls in place March 1, 2023 through March 31, 2024, the period during which bad actors diverted grant funds by impersonating recipients. Fetched directly and converted with pdftotext -layout. oig.hhs.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
's own inspector general titled its audit⧉ around the fact that the agency "has begun taking corrective actions." The audit's own numbers make that framing worth doubting: a $7.8 million fraud went unreported to leadership for nine months, and over a year after it was first reported, most of the security weaknesses it exposed still weren't fixed on schedule.