Skip to main content
Business Development

Selling data and AI services to HHS and CMS

HHS is one of the largest civilian buyers of data and software work in the country, and most of the money that funds it never appears on a federal solicitation. It shows up as a state Medicaid RFP paid for at ninety cents on the dollar. Here is how the buying actually works, and where a data firm gets in.

Two doors, and most firms only knock on the wrong one

The Department of Health and Human Services buys data and software work through two channels that behave nothing alike. The first is the familiar federal channel: contracting offices at CMS, NIH, CDC and FDA issuing solicitations on SAM.gov against large indefinite-delivery vehicles. The second is indirect. CMS writes the rules and pays most of the bill, but the buyer of record is a state Medicaid agency or a state health department, procuring under state law with federal match money. Firms that only watch SAM.gov see maybe a third of the work they could be bidding.

The second channel is also the more open one. A state Medicaid enterprise procurement is competed under a state's own rules, evaluated by a state panel, and frequently broken into modules small enough for a firm with a sharp bench to prime. The federal channel, by contrast, funnels most large IT dollars through a handful of vehicles whose on-ramps open rarely. Both are worth working. Only one of them is reachable in the next six months by a firm that is not already on a governmentwide contract.

Reachability of each door for a small data and AI firm

State Medicaid module RFP funded at 90/10
91%
HHS SBIR and STTR (NIH, CDC, ACL, FDA)
86%
State health department data modernization work
80%
Subcontract on an existing CMS or NIH task order
77%
GSA Schedule task order or BPA at an HHS division
71%
Prime award on a CMS enterprise IT vehicle
62%

Editorial weighting from public procurement records and practitioner reading; illustrative, not a measured statistic.

Who inside HHS is actually buying

HHS is a holding company for operating divisions that contract semi-independently under the HHS Acquisition Regulation at 48 CFR Chapter 3. CMS is the largest by dollars and the most interesting for data work, because it runs Medicare claims processing, the Medicaid data pipeline, the federal marketplace, and the quality-reporting programs. NIH buys research computing, data commons work, and clinical informatics, and runs the NITAAC governmentwide acquisition contracts on behalf of everyone else. CDC buys surveillance systems, analytics platforms, and the state-facing modernization work described below. FDA buys regulatory data systems and real-world-evidence tooling. HRSA, SAMHSA, ACF and IHS each buy program-specific data systems that get far less vendor attention than they deserve.

HHS announced a department-wide restructuring in 2025 that consolidates several operating divisions under a new Administration for a Healthy America and reduces regional offices from ten to five. Parts of it have been contested in court. For a firm selling, the practical effect is that org charts and named contacts move while the contracts, the appropriations, and the underlying program obligations stay put. Verify the current office before an outreach email; do not assume last year's directory.

Medicare's claims work sits with the Medicare Administrative Contractors, awarded under section 1874A of the Social Security Act across twelve A/B MAC jurisdictions and four DME jurisdictions. Those are large recompetes with entrenched incumbents, but the analytics work attached to them moves through subcontracts, and MAC teams buy specialized capability the way any integrator does.

The vehicles that carry the work

Little HHS IT money is spent on standalone contracts. It flows through vehicles, and knowing which vehicle owns which work tells you whether to bid, team, or wait for an on-ramp.

Vehicle or routeOwnerWhat it carriesRealistic entry
SPARCCMSMultiple-award IDIQ for CMS IT services, ceiling around $25 billion; most CMS software and data task orders route hereSubcontract to a holder now; watch for the follow-on competition
CIO-SP4 and CIO-CSNIH NITAACGovernmentwide IT services and commodity solutions, used across HHS and beyondTeam with a holder; on-ramps open infrequently and are heavily protested
GSA Multiple Award ScheduleGSASIN 54151S and 518210C; the workhorse for HHS BPAs and small task ordersGet your own schedule contract; the most controllable route
8(a) sole sourceSBA and HHSServices awards up to $4.5 million without competitionSBA 8(a) certification, plus a program office that wants you specifically
Other transaction agreementsASPR and BARDAPrototypes under PHS Act section 319L (42 U.S.C. 247d-7e), including health data and modeling workConsortium membership, or a partner already inside one
State Medicaid procurementState agency, CMS-fundedMedicaid enterprise modules: claims, provider, pharmacy, care management, analytics, EVVRegister on the state portal and answer the RFI; no federal vehicle required

Two rows matter more than the rest. The bottom row requires no federal vehicle at all, which is where a capable firm without a GWAC starts. And the simplified acquisition threshold of $250,000 in FAR 2.101 sets a floor worth knowing: under FAR 19.502-2(a), acquisitions above the micro-purchase threshold and at or below that threshold are reserved for small business. A well-scoped $180,000 pilot at an HHS program office is a small-business-only action, and it can be awarded far faster than anything on a GWAC.

The 90/10 and 75/25 match is the whole story on state Medicaid IT

Section 1903(a)(3) of the Social Security Act, implemented at 42 CFR 433.112 and 433.116, pays 90 percent federal financial participation for the design, development and installation of Medicaid mechanized claims processing and information retrieval systems, and 75 percent for their ongoing operation. CMS made the enhanced rates permanent for eligibility and enrollment systems in a 2015 final rule effective January 1, 2016. Everything else in Medicaid administration matches at 50 percent under 42 CFR 433.15.

Read that as a pricing fact. A $12 million modernization that qualifies for enhanced match costs the state $1.2 million of its own appropriation. The same $12 million of work, characterized as ordinary administration, costs the state $6 million. The gap between those two numbers is why the characterization of your scope is a technical question with a seven-figure answer, and why state CIOs care intensely about how a vendor's statement of work maps to the regulation.

A $12 million modernization that qualifies for enhanced match costs the state $1.2 million of its own appropriation. The same work characterized as ordinary administration costs the state $6 million.

Enhanced match is conditional. The Standards and Conditions at 42 CFR 433.112(b) require modularity, alignment with the Medicaid Information Technology Architecture, use of industry standards, reuse of existing components, documented business results, reporting, and interoperability. A proposal that cannot show a state how it satisfies those conditions is not merely weaker on technical merit. It threatens the funding rate, and a state financial officer will kill it on that basis alone.

The Advance Planning Document is the real procurement calendar

Before a state can spend matched federal dollars on a system, it submits an Advance Planning Document to CMS under 45 CFR Part 95, Subpart F. A Planning APD funds the analysis. An Implementation APD funds the build. Updates cover changes in scope or cost. Under 45 CFR 95.611, CMS also reviews and approves the state's acquisition documents, meaning the RFP itself and the resulting contract, above stated thresholds.

For a vendor, this is a gift, because it makes the pipeline visible eighteen months before an RFP posts. Approved APDs are public records in most states. Legislative budget documents name the systems being replaced. The state's own IT strategic plan names the year. A firm reading those documents knows which module is coming and can be in the room for the RFI rather than meeting the requirement for the first time at solicitation release.

From self-assessment to a signed module contract

1
State refreshes its MITA self-assessment and roadmap; gaps become candidate projects
3–6 months
2
Planning APD submitted to the CMS regional office and approved
2–4 months
3
Requirements written, market research and RFI issued, acquisition documents cleared by CMS
3–6 months
4
RFP released, proposals evaluated, protest window closes, award
4–9 months
5
Implementation APD approved; design, development and installation at 90 percent match
12–36 months
6
Outcomes-based certification, then operations at 75 percent match
Ongoing

MITA self-assessment: the procurement generator nobody markets to

The Medicaid Information Technology Architecture is CMS's reference model for what a Medicaid enterprise does. Its framework covers business, information and technical architecture across ten business areas and roughly eighty business processes, each rated on a five-level maturity scale. States document their position in a State Self-Assessment: where they are today, where they intend to be, and the roadmap between the two. CMS expects the assessment to be current and to accompany APD submissions, which means it gets refreshed on a rolling cycle rather than once a decade.

That document is the single best sales artifact in the state health market, and it is usually public or obtainable. It states, in the state's own words, which processes are stuck at maturity level one, which are targeted for level three, and by when. Every gap in it is a future procurement with a named owner and a stated business outcome. A capability brief that quotes the state's own self-assessment back to it, with a specific plan for two named processes, lands differently from a generic health-IT one-pager.

The self-assessment work itself is also billable. States are chronically short of the analyst time it takes to run process workshops across eighty business processes, score them defensibly, and produce a roadmap CMS will accept. Our team has done exactly this kind of structured assessment work in other federal domains, and the pattern transfers cleanly: interview the process owners, score against a published maturity rubric, write the evidence trail, and hand back something a funder can act on.

Certification changed, and it changed what states need from a vendor

CMS replaced the older Medicaid Enterprise Certification Toolkit with Streamlined Modular Certification. The center of gravity moved from checklists of system features to outcomes and metrics: a module is certified when the state can demonstrate, with data, that the module produces the business results it promised. Certification matters to the state's cash flow, because operations at 75 percent match depend on it.

This is a direct opportunity for a data firm. Outcomes-based certification requires instrumentation that most legacy modules do not have: defined metrics, a repeatable pipeline that computes them, evidence retained for audit, and a reporting path to CMS. Whoever builds the metric layer becomes structurally important to the program, whether or not they built the module underneath it. We have proposed and built this shape of system repeatedly: define the measure, compute it the same way every time, keep the lineage, and make the number defensible when someone asks where it came from.

What the interoperability rules put on the calendar

Two regulatory clocks are driving health data budgets right now, and both create work.

Compliance dates in play

CMS-0057-F, the Interoperability and Prior Authorization final rule

Impacted payers, which include Medicare Advantage organizations, state Medicaid and CHIP fee-for-service programs, Medicaid and CHIP managed care plans, and qualified health plan issuers on the federally facilitated exchanges, must meet shortened prior authorization decision timeframes beginning in 2026 and stand up HL7 FHIR based Patient Access, Provider Access, Payer-to-Payer and Prior Authorization APIs by January 1, 2027. Most of the remaining engineering is integration and data quality, not API scaffolding.

On the certified health IT side, the HTI-1 rule from the Assistant Secretary for Technology Policy and Office of the National Coordinator moved the certification baseline to United States Core Data for Interoperability version 3 as of January 1, 2026, and requires source-attribute transparency for predictive decision support interventions built into certified systems. If a model influences a clinical or coverage decision inside certified health IT, its inputs, training characteristics and intended use are now disclosable properties, not internal documentation. Firms that already write model cards and keep evaluation records have a running start; firms that do not are looking at retrofit work.

The data formats underneath all of this are stable and worth naming in a proposal, because naming them proves you have touched the domain: HL7 FHIR R4 with US Core profiles, C-CDA documents, HL7 v2 messages for lab and immunization feeds, X12 837, 835, 270/271 and 278 transactions for claims and prior authorization, NCPDP for pharmacy, and LOINC, SNOMED CT, RxNorm and ICD-10 as the terminologies that make any of it comparable across sources.

CDC's Data Modernization Initiative and the public health door

CDC's Data Modernization Initiative is the public health counterpart to the Medicaid enterprise work, and it was funded at scale: $500 million through the CARES Act in 2020 and another $500 million through the American Rescue Plan in 2021, followed by the Public Health Infrastructure Grant, which pushed roughly $3.2 billion to 107 state, local and territorial health departments across a five-year period, with a dedicated data modernization component.

The money is largely at the health departments, not at CDC headquarters, and it buys the unglamorous middle of the pipeline. Electronic case reporting has gone from a few hundred facilities before 2020 to tens of thousands. The National Syndromic Surveillance Program covers a large majority of the country's emergency departments. Electronic lab reporting, vital records modernization, immunization registries and the analytics layers sitting on top of them are all in scope. CDC's own analytics environment and the open-source Data Integration Building Blocks it publishes give a vendor real artifacts to build against instead of guessing.

The recurring technical problem in this domain is entity resolution and message quality. A state receives the same person under four spellings, three identifiers and two address formats, in message streams built to different profiles of the same standard. The work that gets funded is the work that fixes the record, keeps the lineage, and lets an epidemiologist see why two records were merged. That is a data engineering problem with a health vocabulary attached, and it is squarely what we build.

The security gates that decide whether you can execute

Health data procurement has a compliance floor that arrives before the technical evaluation. State eligibility and enrollment systems receive federal tax information from the IRS for income verification, which puts IRS Publication 1075 in scope for the environment, the staff, and the audit trail. Exchange-adjacent systems inherit the Minimum Acceptable Risk Standards for Exchanges. CMS systems apply the CMS Acceptable Risk Safeguards overlay on top of NIST SP 800-53. Cloud services supporting federal data generally need FedRAMP authorization at Moderate or above, and HIPAA business associate obligations attach wherever protected health information moves.

None of this is optional and all of it is schedulable. Firms that treat security as a post-award activity lose here. Firms that show the control mapping in the proposal, name the boundary, and say which authorization they inherit and which they must earn, win.

Data rights on federally matched software

One clause deserves attention before signing anything with a state health agency: 45 CFR 95.617. Custom software developed with federal financial participation carries a royalty-free, non-exclusive and irrevocable license for the federal government to reproduce, publish and use it, and CMS expects components funded this way to be available for reuse by other states. Commercially available proprietary software you bring to the engagement retains its own terms, and the state acquires a license to use it.

Draw the line between those two categories in the contract, before development starts. A firm that brings a real product and configures it stands in a different position from a firm writing bespoke code on the state's dime. Confusing the two after the fact is how vendors lose control of their own intellectual property.

The research door: HHS SBIR and STTR

NIH, CDC, FDA, ACL and BARDA all run SBIR and STTR programs, and HHS is the second-largest SBIR funder in the government. Award sizes follow SBA's annually adjusted guidelines, with Phase I in the low six figures and Phase II above two million dollars, and NIH holds authority to exceed those guidelines for specified subject areas. NIH is largely investigator-initiated through omnibus solicitations, which suits a firm with its own technical idea. CDC and ACL publish narrower contract solicitations tied to program needs.

The strategic value is not only the research money. A Phase II award creates SBIR data rights in the resulting technology and opens the Phase III sole-source path, which lets any federal agency, including a state program funded federally, buy the derived product without further competition. For a data firm building a durable product in health, that sequence is the cleanest route from an idea to a production contract that exists in federal acquisition.

A working checklist before the first health pursuit

  • SAM.gov registration current, with NAICS 541511, 541512, 541519, 541715 and 518210 claimed
  • Registered as a vendor in the eProcurement portals of the four or five states you intend to pursue
  • The current MITA state self-assessment and approved APDs for those states read end to end
  • A one-page control mapping covering HIPAA, IRS Publication 1075 and NIST SP 800-53 posture
  • Named engineers with health data experience identified for the roles you will propose
  • A written position on custom versus proprietary software under 45 CFR 95.617
  • Answers filed to every relevant RFI, whether or not you intend to prime the follow-on

Where we fit

Precision Federal builds AI, data and software systems for federal, state and commercial customers. In the health market that means the parts a program office cannot buy off a shelf: entity resolution across sources nobody fully controls, extraction from documents that have to survive an audit, metric pipelines that produce the same number twice, and model behavior a hearing officer or a certification reviewer can follow. Our team is led by a former professor in technology who ranks in the top 0.1 percent of the Kaggle field, holds seven cloud certifications, and brings twenty years of production federal systems work across five consulting firms. We field a standing bench of named engineers, licensed professional engineers and domain specialists, and we staff a pursuit with the people who will actually do the work.

We work as a prime where the scope fits and as a subcontractor where a larger integrator needs a bench that can carry the data and AI portion of a health program. Either way, the first conversation is short and technical: what the data looks like, who has to defend the output, and what the deadline is.

Frequently asked questions

Is a federal contract vehicle required to sell data services into the Medicaid market?

No. State Medicaid enterprise systems are procured by the state under state law, using federal match money. A vendor registers in the state's procurement portal, responds to the RFI, and bids the RFP. CMS approves the funding and the acquisition documents, but the contract is with the state.

What does the 90/10 Medicaid match actually cover?

Ninety percent federal financial participation applies to design, development and installation of Medicaid claims processing, information retrieval, and eligibility and enrollment systems under 42 CFR 433.112. Ongoing operation of those systems matches at 75 percent under 42 CFR 433.116. Other administrative activity matches at 50 percent. Enhanced rates are conditional on the Standards and Conditions in the regulation.

How far ahead can a vendor see a state Medicaid procurement?

Often twelve to eighteen months. Approved Advance Planning Documents, MITA self-assessments, state IT strategic plans and legislative budget records all name systems and years before an RFP posts. Reading those documents is the cheapest capture work available in this market.

What compliance regimes apply to health data work for state and federal agencies?

HIPAA where protected health information is involved, IRS Publication 1075 where federal tax information reaches eligibility systems, MARS-E for exchange-adjacent systems, the CMS Acceptable Risk Safeguards overlay on NIST SP 800-53 for CMS systems, and FedRAMP for cloud services supporting federal data.

Which HHS operating divisions run SBIR and STTR programs?

NIH, CDC, FDA, ACL and BARDA. NIH is the largest and is mostly investigator-initiated through omnibus solicitations; CDC and ACL publish narrower, program-driven contract solicitations. A Phase II award opens the Phase III sole-source path for later production buys.

1 business day response

Bidding a health data program this cycle?

We build the data and AI portion of Medicaid enterprise modules, public health surveillance pipelines, and payer interoperability work, as prime or as a subcontractor to your team.

CapabilitiesMore insights →Start a conversation
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512SAM.GOV ACTIVE