Two doors, and most firms only knock on the wrong one
The Department of Health and Human Services buys data and software work through two channels that behave nothing alike. The first is the familiar federal channel: contracting offices at CMS, NIH, CDC and FDA issuing solicitations on SAM.gov against large indefinite-delivery vehicles. The second is indirect. CMS writes the rules and pays most of the bill, but the buyer of record is a state Medicaid agency or a state health department, procuring under state law with federal match money. Firms that only watch SAM.gov see maybe a third of the work they could be bidding.
The second channel is also the more open one. A state Medicaid enterprise procurement is competed under a state's own rules, evaluated by a state panel, and frequently broken into modules small enough for a firm with a sharp bench to prime. The federal channel, by contrast, funnels most large IT dollars through a handful of vehicles whose on-ramps open rarely. Both are worth working. Only one of them is reachable in the next six months by a firm that is not already on a governmentwide contract.
Reachability of each door for a small data and AI firm
Editorial weighting from public procurement records and practitioner reading; illustrative, not a measured statistic.
Who inside HHS is actually buying
HHS is a holding company for operating divisions that contract semi-independently under the HHS Acquisition Regulation at 48 CFR Chapter 3. CMS is the largest by dollars and the most interesting for data work, because it runs Medicare claims processing, the Medicaid data pipeline, the federal marketplace, and the quality-reporting programs. NIH buys research computing, data commons work, and clinical informatics, and runs the NITAAC governmentwide acquisition contracts on behalf of everyone else. CDC buys surveillance systems, analytics platforms, and the state-facing modernization work described below. FDA buys regulatory data systems and real-world-evidence tooling. HRSA, SAMHSA, ACF and IHS each buy program-specific data systems that get far less vendor attention than they deserve.
HHS announced a department-wide restructuring in 2025 that consolidates several operating divisions under a new Administration for a Healthy America and reduces regional offices from ten to five. Parts of it have been contested in court. For a firm selling, the practical effect is that org charts and named contacts move while the contracts, the appropriations, and the underlying program obligations stay put. Verify the current office before an outreach email; do not assume last year's directory.
Medicare's claims work sits with the Medicare Administrative Contractors, awarded under section 1874A of the Social Security Act across twelve A/B MAC jurisdictions and four DME jurisdictions. Those are large recompetes with entrenched incumbents, but the analytics work attached to them moves through subcontracts, and MAC teams buy specialized capability the way any integrator does.

The vehicles that carry the work
Little HHS IT money is spent on standalone contracts. It flows through vehicles, and knowing which vehicle owns which work tells you whether to bid, team, or wait for an on-ramp.
| Vehicle or route | Owner | What it carries | Realistic entry |
|---|---|---|---|
| SPARC | CMS | Multiple-award IDIQ for CMS IT services, ceiling around $25 billion; most CMS software and data task orders route here | Subcontract to a holder now; watch for the follow-on competition |
| CIO-SP4 and CIO-CS | NIH NITAAC | Governmentwide IT services and commodity solutions, used across HHS and beyond | Team with a holder; on-ramps open infrequently and are heavily protested |
| GSA Multiple Award Schedule | GSA | SIN 54151S and 518210C; the workhorse for HHS BPAs and small task orders | Get your own schedule contract; the most controllable route |
| 8(a) sole source | SBA and HHS | Services awards up to $4.5 million without competition | SBA 8(a) certification, plus a program office that wants you specifically |
| Other transaction agreements | ASPR and BARDA | Prototypes under PHS Act section 319L (42 U.S.C. 247d-7e), including health data and modeling work | Consortium membership, or a partner already inside one |
| State Medicaid procurement | State agency, CMS-funded | Medicaid enterprise modules: claims, provider, pharmacy, care management, analytics, EVV | Register on the state portal and answer the RFI; no federal vehicle required |
Two rows matter more than the rest. The bottom row requires no federal vehicle at all, which is where a capable firm without a GWAC starts. And the simplified acquisition threshold of $250,000 in FAR 2.101 sets a floor worth knowing: under FAR 19.502-2(a), acquisitions above the micro-purchase threshold and at or below that threshold are reserved for small business. A well-scoped $180,000 pilot at an HHS program office is a small-business-only action, and it can be awarded far faster than anything on a GWAC.
The 90/10 and 75/25 match is the whole story on state Medicaid IT
Section 1903(a)(3) of the Social Security Act, implemented at 42 CFR 433.112 and 433.116, pays 90 percent federal financial participation for the design, development and installation of Medicaid mechanized claims processing and information retrieval systems, and 75 percent for their ongoing operation. CMS made the enhanced rates permanent for eligibility and enrollment systems in a 2015 final rule effective January 1, 2016. Everything else in Medicaid administration matches at 50 percent under 42 CFR 433.15.
Read that as a pricing fact. A $12 million modernization that qualifies for enhanced match costs the state $1.2 million of its own appropriation. The same $12 million of work, characterized as ordinary administration, costs the state $6 million. The gap between those two numbers is why the characterization of your scope is a technical question with a seven-figure answer, and why state CIOs care intensely about how a vendor's statement of work maps to the regulation.
Enhanced match is conditional. The Standards and Conditions at 42 CFR 433.112(b) require modularity, alignment with the Medicaid Information Technology Architecture, use of industry standards, reuse of existing components, documented business results, reporting, and interoperability. A proposal that cannot show a state how it satisfies those conditions is not merely weaker on technical merit. It threatens the funding rate, and a state financial officer will kill it on that basis alone.
The Advance Planning Document is the real procurement calendar
Before a state can spend matched federal dollars on a system, it submits an Advance Planning Document to CMS under 45 CFR Part 95, Subpart F. A Planning APD funds the analysis. An Implementation APD funds the build. Updates cover changes in scope or cost. Under 45 CFR 95.611, CMS also reviews and approves the state's acquisition documents, meaning the RFP itself and the resulting contract, above stated thresholds.
For a vendor, this is a gift, because it makes the pipeline visible eighteen months before an RFP posts. Approved APDs are public records in most states. Legislative budget documents name the systems being replaced. The state's own IT strategic plan names the year. A firm reading those documents knows which module is coming and can be in the room for the RFI rather than meeting the requirement for the first time at solicitation release.
From self-assessment to a signed module contract
MITA self-assessment: the procurement generator nobody markets to
The Medicaid Information Technology Architecture is CMS's reference model for what a Medicaid enterprise does. Its framework covers business, information and technical architecture across ten business areas and roughly eighty business processes, each rated on a five-level maturity scale. States document their position in a State Self-Assessment: where they are today, where they intend to be, and the roadmap between the two. CMS expects the assessment to be current and to accompany APD submissions, which means it gets refreshed on a rolling cycle rather than once a decade.
That document is the single best sales artifact in the state health market, and it is usually public or obtainable. It states, in the state's own words, which processes are stuck at maturity level one, which are targeted for level three, and by when. Every gap in it is a future procurement with a named owner and a stated business outcome. A capability brief that quotes the state's own self-assessment back to it, with a specific plan for two named processes, lands differently from a generic health-IT one-pager.
The self-assessment work itself is also billable. States are chronically short of the analyst time it takes to run process workshops across eighty business processes, score them defensibly, and produce a roadmap CMS will accept. Our team has done exactly this kind of structured assessment work in other federal domains, and the pattern transfers cleanly: interview the process owners, score against a published maturity rubric, write the evidence trail, and hand back something a funder can act on.
Certification changed, and it changed what states need from a vendor
CMS replaced the older Medicaid Enterprise Certification Toolkit with Streamlined Modular Certification. The center of gravity moved from checklists of system features to outcomes and metrics: a module is certified when the state can demonstrate, with data, that the module produces the business results it promised. Certification matters to the state's cash flow, because operations at 75 percent match depend on it.
This is a direct opportunity for a data firm. Outcomes-based certification requires instrumentation that most legacy modules do not have: defined metrics, a repeatable pipeline that computes them, evidence retained for audit, and a reporting path to CMS. Whoever builds the metric layer becomes structurally important to the program, whether or not they built the module underneath it. We have proposed and built this shape of system repeatedly: define the measure, compute it the same way every time, keep the lineage, and make the number defensible when someone asks where it came from.
What the interoperability rules put on the calendar
Two regulatory clocks are driving health data budgets right now, and both create work.
CMS-0057-F, the Interoperability and Prior Authorization final rule
Impacted payers, which include Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid and CHIP managed care plans, and qualified health plan issuers on the federally facilitated exchanges, must meet shortened prior authorization decision timeframes beginning in 2026 and stand up HL7 FHIR based Patient Access, Provider Access, Payer-to-Payer and Prior Authorization APIs by January 1, 2027. Most of the remaining engineering is integration and data quality, not API scaffolding.
On the certified health IT side, the HTI-1 rule from the Assistant Secretary for Technology Policy and Office of the National Coordinator moved the certification baseline to United States Core Data for Interoperability version 3 as of January 1, 2026, and requires source-attribute transparency for predictive decision support interventions built into certified systems. If a model influences a clinical or coverage decision inside certified health IT, its inputs, training characteristics and intended use are now disclosable properties, not internal documentation. Firms that already write model cards and keep evaluation records have a running start; firms that do not are looking at retrofit work.
The data formats underneath all of this are stable and worth naming in a proposal, because naming them proves you have touched the domain: HL7 FHIR R4 with US Core profiles, C-CDA documents, HL7 v2 messages for lab and immunization feeds, X12 837, 835, 270/271 and 278 transactions for claims and prior authorization, NCPDP for pharmacy, and LOINC, SNOMED CT, RxNorm and ICD-10 as the terminologies that make any of it comparable across sources.
CDC's Data Modernization Initiative and the public health door
CDC's Data Modernization Initiative is the public health counterpart to the Medicaid enterprise work, and it was funded at scale: $500 million through the CARES Act in 2020 and another $500 million through the American Rescue Plan in 2021, followed by the Public Health Infrastructure Grant, which pushed roughly $3.2 billion to 107 state, local and territorial health departments across a five-year period, with a dedicated data modernization component.
The money is largely at the health departments, not at CDC headquarters, and it buys the unglamorous middle of the pipeline. Electronic case reporting has gone from a few hundred facilities before 2020 to tens of thousands. The National Syndromic Surveillance Program covers a large majority of the country's emergency departments. Electronic lab reporting, vital records modernization, immunization registries and the analytics layers sitting on top of them are all in scope. CDC's own analytics environment and the open-source Data Integration Building Blocks it publishes give a vendor real artifacts to build against instead of guessing.
The recurring technical problem in this domain is entity resolution and message quality. A state receives the same person under four spellings, three identifiers and two address formats, in message streams built to different profiles of the same standard. The work that gets funded is the work that fixes the record, keeps the lineage, and lets an epidemiologist see why two records were merged. That is a data engineering problem with a health vocabulary attached, and it is squarely what we build.
The security gates that decide whether you can execute
Health data procurement has a compliance floor that arrives before the technical evaluation. State eligibility and enrollment systems receive federal tax information from the IRS for income verification, which puts IRS Publication 1075 in scope for the environment, the staff, and the audit trail. Exchange-adjacent systems inherit the Minimum Acceptable Risk Standards for Exchanges. CMS systems apply the CMS Acceptable Risk Safeguards overlay on top of NIST SP 800-53. Cloud services supporting federal data generally need FedRAMP authorization at Moderate or above, and HIPAA business associate obligations attach wherever protected health information moves.
None of this is optional and all of it is schedulable. Firms that treat security as a post-award activity lose here. Firms that show the control mapping in the proposal, name the boundary, and say which authorization they inherit and which they must earn, win.
Data rights on federally matched software
One clause deserves attention before signing anything with a state health agency: 45 CFR 95.617. Custom software developed with federal financial participation carries a royalty-free, non-exclusive and irrevocable license for the federal government to reproduce, publish and use it, and CMS expects components funded this way to be available for reuse by other states. Commercially available proprietary software you bring to the engagement retains its own terms, and the state acquires a license to use it.
Draw the line between those two categories in the contract, before development starts. A firm that brings a real product and configures it stands in a different position from a firm writing bespoke code on the state's dime. Confusing the two after the fact is how vendors lose control of their own intellectual property.
The research door: HHS SBIR and STTR
NIH, CDC, FDA, ACL and BARDA all run SBIR and STTR programs, and HHS is the second-largest SBIR funder in the government. Award sizes follow SBA's annually adjusted guidelines, with Phase I in the low six figures and Phase II above two million dollars, and NIH holds authority to exceed those guidelines for specified subject areas. NIH is largely investigator-initiated through omnibus solicitations, which suits a firm with its own technical idea. CDC and ACL publish narrower contract solicitations tied to program needs.
The strategic value is not only the research money. A Phase II award creates SBIR data rights in the resulting technology and opens the Phase III sole-source path, which lets any federal agency, including a state program funded federally, buy the derived product without further competition. For a data firm building a durable product in health, that sequence is the cleanest route from an idea to a production contract that exists in federal acquisition.
A working checklist before the first health pursuit
- SAM.gov registration current, with NAICS 541511, 541512, 541519, 541715 and 518210 claimed
- Registered as a vendor in the eProcurement portals of the four or five states you intend to pursue
- The current MITA state self-assessment and approved APDs for those states read end to end
- A one-page control mapping covering HIPAA, IRS Publication 1075 and NIST SP 800-53 posture
- Named engineers with health data experience identified for the roles you will propose
- A written position on custom versus proprietary software under 45 CFR 95.617
- Answers filed to every relevant RFI, whether or not you intend to prime the follow-on
Where we fit
Precision Federal builds AI, data and software systems for federal, state and commercial customers. In the health market that means the parts a program office cannot buy off a shelf: entity resolution across sources nobody fully controls, extraction from documents that have to survive an audit, metric pipelines that produce the same number twice, and model behavior a hearing officer or a certification reviewer can follow. Our team is led by a former professor in technology who ranks in the top 0.1 percent of the Kaggle field, holds seven cloud certifications, and brings twenty years of production federal systems work across five consulting firms. We field a standing bench of named engineers, licensed professional engineers and domain specialists, and we staff a pursuit with the people who will actually do the work.
We work as a prime where the scope fits and as a subcontractor where a larger integrator needs a bench that can carry the data and AI portion of a health program. Either way, the first conversation is short and technical: what the data looks like, who has to defend the output, and what the deadline is.
Frequently asked questions
No. State Medicaid enterprise systems are procured by the state under state law, using federal match money. A vendor registers in the state's procurement portal, responds to the RFI, and bids the RFP. CMS approves the funding and the acquisition documents, but the contract is with the state.
Ninety percent federal financial participation applies to design, development and installation of Medicaid claims processing, information retrieval, and eligibility and enrollment systems under 42 CFR 433.112. Ongoing operation of those systems matches at 75 percent under 42 CFR 433.116. Other administrative activity matches at 50 percent. Enhanced rates are conditional on the Standards and Conditions in the regulation.
Often twelve to eighteen months. Approved Advance Planning Documents, MITA self-assessments, state IT strategic plans and legislative budget records all name systems and years before an RFP posts. Reading those documents is the cheapest capture work available in this market.
HIPAA where protected health information is involved, IRS Publication 1075 where federal tax information reaches eligibility systems, MARS-E for exchange-adjacent systems, the CMS Acceptable Risk Safeguards overlay on NIST SP 800-53 for CMS systems, and FedRAMP for cloud services supporting federal data.
NIH, CDC, FDA, ACL and BARDA. NIH is the largest and is mostly investigator-initiated through omnibus solicitations; CDC and ACL publish narrower, program-driven contract solicitations. A Phase II award opens the Phase III sole-source path for later production buys.
