Cross-Agency Data Sharing Barriers and Solutions
Federal agencies lose $186 billion annually due to disconnected data systems.

Fifty-plus years after the Privacy Act, and roughly twenty-five after the 9/11 Commission told the federal government to fix its information sharing, agencies still can't reliably swap basic facts about the people and payments they're responsible for. In FY 2025, fifteen federal agencies reported roughly $186 billion in improper payments across 64 programs, up $24 billion from the year before. Since FY 2003, the running total sits near $3 trillion, and GAO will tell you flat out that the real number is probably higher than what's on the books. I've spent enough time around this problem to have a favorite way of describing it: a technical layer on the bottom, a legal layer stacked on that, a cultural layer on top of both, and security running through all three like rebar in concrete. Mess with one layer without fixing the one underneath it, and the whole thing buckles, which is more or less what's been happening since roughly 1974.
How data verification failures connect improper payments to broken information pipelines
One number inside that $186 billion does more work than the rest combined. An estimated $46.8 billion in FY 2024 traced back specifically to marital status, identity, and death data issues, records that simply refuse to talk to each other. Not glamorous stuff. Still, it's the kind of number that turns an abstraction into something closer to a paperwork error with real consequences attached.
Take Treasury. The Bureau of the Fiscal Service handles something like 90 percent of all federal payments, and it didn't get access to the Social Security Administration's Death Master File, the list of who has, in fact, died, until December 2023. Even now, that access is described as temporary. Cost, privacy rules, and security concerns each explain part of the delay on their own; stacked together, they turned a basic cross-check into a prolonged negotiation.
HHS has its own version of the story, and it's a quieter kind of broken. The agency can't require states to report the data it needs to estimate improper payments under TANF. That's a statutory gap: the law that created the program never handed HHS that lever, so the problem stays partly invisible at the federal level because nobody has the authority to go looking for it.
Zoom out and things get blurrier instead of clearer. Fraud losses, a subset of the broader improper payments problem, land somewhere between $233 billion and $521 billion a year. A range that wide isn't really an estimate; it's an admission that nobody has a clean view into what's actually happening. The death file, the TANF gap, the fraud range, each one maps onto a different barrier. Infrastructure, law, and culture, in that order, and that's the order the next three sections follow too.
The infrastructure problem: legacy systems that were never built to share
Nothing upstream matters if the pipes don't connect. More than 80 percent of government departments deal with data silos that generate real inefficiencies in service delivery, and a 2025 analysis found 78 percent of federal agencies run at least five disconnected major data systems, with 42 percent operating more than fifteen separate repositories. Nobody built a bridge between those repositories, and nobody budgeted for one either.
GAO's 2024 report found 13 of 15 major agencies still run legacy components the report itself calls "difficult to update or secure." That's not neglect exactly; these systems were built this way on purpose, because interoperability wasn't a design goal when they went online. These systems were built for the problems of their era, not for the interoperability demands that came decades later.
The downstream effects are almost comically mundane once you notice them. Citizens fill out the same form for three different agencies because none of them can read what the other already has on file. Departments reconcile reports by hand instead of exchanging structured data, which in practice means someone retyping numbers off one screen into another. Even when two agencies genuinely want to share, incompatible formats mean the data that shows up often turns to mush the moment it lands.
The money side is stranger still. About 80 percent of the federal IT budget goes toward keeping legacy systems alive rather than replacing them, and the ten most urgently outdated ones cost roughly $337 million a year just to keep running. Not to fix. Just to keep operating. The pace of change is slow by any honest measure: in 2010, GAO identified 1,881 IT recommendations needed to modernize and secure government systems. As of 2025, fewer than 25 percent have been carried out. Fifteen years to carry out fewer than a quarter of the recommendations suggests the pace of implementation has been slow by any honest measure.
Legal reform and cultural change both assume there's a pipe for the data to flow through once permission and willingness finally show up. Build those fixes on top of broken infrastructure and the fixes won't hold; nothing's actually moving through the system they're meant to improve.
The legal layer: statutes written before modern data systems actively prevent sharing
Even with better pipes, the law decides what's allowed to flow through them. Statutes including the Privacy Act, the Computer Matching Act, and the Paperwork Reduction Act predate the infrastructure they now govern, written for a world of paper files and filing clerks rather than APIs and federated queries. The rules technically still apply to today's systems, they just weren't built for the technology now moving through them.
The Federal Data Strategy formally directs agencies to identify and address legal and regulatory barriers to sharing. Sensible instruction, awkward catch: often the law itself is the barrier the strategy is asking agencies to work around. You can't strategize your way past a statute. You have to change it, or find the narrow legal path that satisfies it without breaking it, which is a lot harder than it sounds when the statute in question is fifty years old.
On top of the statutes sits a second bureaucratic layer, Data Use Agreements and system-of-record notices, each needing its own negotiation, its own sign-off, its own timeline. Before recent executive action, many agencies kept strict internal rules limiting access to their own data even for other federal agencies, let alone state programs that receive federal funding but answer to entirely different reporting requirements.
Run the TANF example back through this legal lens and it sharpens considerably. HHS's inability to compel state reporting is a statutory silence, nobody wrote the authority into the law, so no amount of goodwill or clever software fixes it. Access to the Death Master File follows the same shape: restricted by privacy statute, gated by formal agreements, and tagged with fees, which means legal constraints impose real costs even when every party at the table genuinely wants to cooperate.
The Evidence Act of 2018 tried to chip away at this. It created Chief Data Officers, Evaluation Officers, and an "open by default" standard for how agencies treat their own data. Useful additions, all three. Yet they didn't touch the statutory conflicts sitting underneath them, and appointing a Chief Data Officer doesn't help much if the Privacy Act still says no. The org chart doesn't outrank the U.S. Code, however senior the title sounds.
That leaves the harder question underneath all of it. How do you reform laws that exist for good reasons without gutting the protections that justify them in the first place? Nobody's arguing the Privacy Act should disappear. The real work is sorting which restrictions are load-bearing and which ones are scaffolding nobody's gotten around to taking down.
The cultural layer: why agencies protect data even when sharing it is legal and technically possible
Fix the pipes, fix the statutes, and you'd expect the data to start moving. It often doesn't, and the holdup here is cultural, not mechanical. Former U.S. Chief Statistician Nancy Potok put it about as precisely as anyone has: agencies have historically treated data as binary, either fully open or fully locked down, and the shift toward graduated, contextual sharing is genuinely foreign territory for most civil servants. "It's not like an on/off switch," she's said, and yet nearly every approval chain, every risk process, every internal culture inside these agencies was built around exactly that switch.
The friction shows up in familiar ways. Internal access processes are often so cumbersome that even routine, low-stakes data requests get stuck for weeks. Every department runs its own standards, its own security protocols, its own political read on what's safe to release. There's no shared cross-agency framework, so every sharing arrangement gets negotiated from zero, every single time.
Underneath all of that sits a genuinely lopsided incentive structure, and this is the part that I think explains more than any statute does. A civil servant faces accountability for a privacy violation, while the costs of failing to share data that might have stopped fraud elsewhere in government are far less visible and rarely land on any individual. Nobody designed this maliciously. It was designed for a narrower goal than the one everyone now claims to care about. The agency holding the data eats the risk of sharing it, while the benefit lands somewhere else, in another agency's fraud numbers, another program's improper payment rate. There's little reason for anyone to rush toward risk for a payoff they'll never get credit for.
No technology fix changes that math, and no statute rewrite changes it either. What it takes is leadership norms, shared accountability, and roles with actual cross-agency authority, not just cross-agency titles. Chief Data Officers are a start. A CDO without a real cross-agency mandate hits the same wall, though: a newer title without the authority to match it.
The security tension that cuts across all three barriers
Here's where the whole project turns uncomfortable, because the fix and the risk grow at the same rate. Survey data from 2025 puts the average at 137 cyberattacks against U.S. and UK government agencies every week, up from 127 a week in 2024, a 25 percent year-over-year jump for U.S. agencies specifically. That's an accelerating number sitting directly on top of every plan to wire more systems into more systems.
The tension is structural, not incidental: cutting fraud and improper payments means connecting data across agencies, and connecting data across agencies widens the target those 137-a-week attacks are aimed at. You don't get the fraud-reduction upside of a connected data environment without also handing attackers a bigger surface to work with.
Executive Order 14243, issued in March 2025, puts this tension into policy almost too neatly. It directs agencies to provide what it calls "unfettered access" to comprehensive data, including state program data, framed explicitly as a fraud-reduction measure. Critics argue the order lumps legitimate data protection measures in with unnecessary obstruction, treating real privacy safeguards the same as barriers that serve no purpose. The real question, as others have framed it, is not whether barriers should exist, but which ones are redundant and which ones are load-bearing.
Congress has picked up the thread too. That means this argument has moved out of executive memo territory and into broader policy debate, with legislative proposals seeking to codify the order's directives into statute.
The implication for any real solution is blunt. Security has to sit in the room at the first design meeting, not get bolted on afterward as a constraint to route around once the architecture's already poured. Otherwise every gain on the fraud side gets quietly eaten by new exposure on the breach side.
What sequenced solutions actually look like in practice
Given that none of these layers work alone, what does fixing this actually look like? Technical infrastructure sets the floor for what's physically possible. Legal frameworks decide what's allowed to move across that floor. Cultural change decides whether people actually use the permission they've been handed. Security protects all of it while it's in motion. Skip a step and the structure won't hold, however good the blueprint looks on paper.
On the technical side, that means modernizing toward interoperability by design, and not falling into the trap, agencies do this more than anyone wants to admit, of swapping one siloed system for a newer, equally siloed one. It means standardizing data formats and identifiers across agencies, so willingness to share actually produces something usable on the other end. And it means incremental integration: connecting what already exists instead of waiting on a wholesale replacement that, at the pace GAO has documented, might not show up this decade or the next one.
On the legal side, the Data Foundation has already flagged the Privacy Act, the Computer Matching Act, and the Paperwork Reduction Act as reform targets, which hands lawmakers an actual punch list instead of a vague mandate to "do better." Streamlining Data Use Agreements so routine sharing doesn't need months of bespoke negotiation per deal would help a lot. So would extending and codifying time-limited access grants; the Death Master File arrangement shows exactly how fragile an ad hoc grant stays even after you've won it.
On the cultural side, Chief Data Officers need a real cross-agency mandate, not an advisory chair at a table where the actual decisions happen somewhere else. Incentive structures need to flip so agencies benefit from sharing instead of only absorbing its risk. Agencies need to move off the binary open-or-locked mindset Potok described and toward tiered, contextual access, where different data gets different handling depending on who's asking and why. The CDO Council the Evidence Act set up is a workable skeleton, though it needs enforcement authority it doesn't currently have.
On security, the fix runs through privacy-preserving computation: secure enclaves, federated queries, techniques that let agencies pattern-match across datasets without exposing the underlying records to each other. Pair that with audit logging and access controls built straight into the sharing architecture, so every access is traceable and revocable instead of a one-time grant nobody's watching afterward. NAPA's framing is worth closing this section on: sort the redundant barriers from the essential ones, then engineer around the redundant ones without touching the essential ones. Easier said than done, given how long these barriers have been in place.
Where the policy environment stands now and what remains unresolved
The Evidence Act of 2018 is still the most durable piece of this puzzle: an open-by-default standard, a CDO Council, Evaluation Officers, a governance skeleton that survives a change in administration because it's structural rather than political. That durability matters more than it should have to, because anything tied to a single executive order lives and dies with that order.
That's exactly the risk EO 14243 carries. It sped up access in specific domains, which is real progress worth naming plainly and not burying under caveats. But it also created legal uncertainty and civil liberties concerns still being fought out in public, and how long it lasts as a mechanism is genuinely an open question. The Eliminating Information Silos Act of 2025 suggests Congress wants some of this locked into statute rather than left to executive whim, but the bigger legislative lift, actually rewriting the Privacy Act and its statutory cousins, hasn't happened yet. It might not happen this decade, if the modernization pace is anything to go by.
Treasury's access to the Death Master File in December 2023 is worth revisiting one more time here, because it captures both the progress and the fragility in a single case. It took decades to arrange, it costs money to keep running, and the terms of access still aren't locked down. That's what "solved" looks like right now in this corner of government: solved with an asterisk, and a renewal date nobody's fully sure about.
Meanwhile the technical foundation is still being built, slowly. Fewer than 25 percent of GAO's 1,881 recommendations from 2010 have been carried out as of 2025, which means the floor this whole structure needs to stand on is, in large part, still under construction.
For anyone working inside this system day to day, the plain version goes something like this. Legal reform and executive action open windows, but only agencies running modern infrastructure can actually climb through them; cultural change lags behind both because new roles and new norms need years of steady leadership to stick, not one memo and a press release. The attack surface keeps growing as sharing expands, so security spending has to keep pace with policy ambition instead of trailing three steps behind it, which, if the last fifteen years are any guide, is exactly what it's been doing.
A new law, a new platform, or another executive order alone won't close this gap. The agencies making real headway treat it as a sequence of interlocking problems, doing the layers in order instead of skipping the boring ones because the boring ones are, in the end, the ones holding everything else up.


