WMATA OIG Report Flags Privacy, Payment and Contract Risks
A September 10, 2026 report from the Washington Metropolitan Area Transit Authorityโs Office of Inspector General identifies weaknesses in how Metro protects sensitive information, documents vendor payments and manages federally supported contracts.
The report covers oversight work from January 1 through June 30, 2026. Its findings give Washington, D.C., riders, employees, contractors and taxpayers an accountability snapshot of the regional transit authority, which serves the District, Maryland and Virginia.
Privacy and payment records need stronger controls
The OIG found systemic weaknesses in WMATAโs data privacy and protection practices. The audit said the authority lacked a comprehensive data-privacy framework, had not fully deployed automated security tools, and lacked centralized encryption standards and enforcement.
The report also identified gaps in enterprise-wide coordination and enforcement. According to the OIG, those weaknesses increase the risk of data breaches and noncompliance with applicable privacy and security standards, including standards associated with the National Institute of Standards and Technology and the Health Insurance Portability and Accountability Act.
The finding does not state that rider or employee data was exposed. It identifies weaknesses in the systems, governance and controls WMATA uses to protect sensitive information.
A separate accounts-payable audit found missing documentation for receipt, invoice validation and approval. The OIG said WMATA needs stronger controls to follow its prompt-payment policy, support vendor invoices and improve the transparency and tracking of bundled purchase orders.
For vendors and taxpayers, the accountability issue is whether WMATAโs records clearly show what was purchased, who approved it, whether invoices were adequately supported and whether payments followed authority policy.
Federal-awards audit found a material contract-management weakness
WMATAโs fiscal 2025 Single Audit identified a material weakness in internal control over financial reporting related to contract management. The same audit identified a significant deficiency involving a key federal-compliance requirement and a separate material weakness involving preparation of the Schedule of Expenditures of Federal Awards.
Those findings concern WMATAโs controls for managing and reporting federally supported work. They do not, by themselves, establish that all federal funds were misused or that a specific loss occurred.
The report separately states that the OIG issued seven contract audits during the six-month period and identified $5.09 million in monetary benefits. The report describes the figure as benefits identified through audit work; it does not present it as recovered cash, total losses or savings already received by WMATA.
The listed reviews included proposed rates and price proposals for work involving the Northern Bus Garage replacement, survey services and construction-support services. Several audits showed potential benefits as โTBDโ because the amount could not yet be calculated.
Investigations produced five criminal matters
The OIG also reported five criminal matters during the period, including prosecutions tied to a health-care fraud scheme. The report says insurance claims were created with forged doctorsโ signatures and submitted for injuries, medical treatments and disability periods that did not exist. It says WMATA employees involved in the scheme provided kickback payments to another employee who facilitated it.
Eight WMATA employees have been convicted for their roles in those offenses, according to the report. Two employees sentenced in June 2026 received 24 months of probation and were ordered to pay restitution totaling $96,371. The criminal matters are distinct from the audit findings and do not establish broader fraud across WMATA.
The OIG hotline received 287 complaints during the reporting period. Nineteen led to investigations, while other complaints were referred to management or outside entities, remained under review or were closed without OIG action.
Corrective actions remain open or under review
The OIG tracks corrective-action plans until final action is completed. Its report lists recommendations from earlier audits that had not been completed as of June 30, 2026, including work involving cybersecurity, procurement, accounts payable, data privacy, real-property records and security cameras.
The data-privacy audit listed seven recommendations as incomplete, with a latest target date of September 15, 2029. The accounts-payable audit listed 10 recommendations as incomplete, with the completion date shown as โTBD.โ Those entries are corrective-action targets and status snapshots, not evidence that the work is finished.
The OIG also plans to deliver a five-year review in November 2026 covering WMATAโs Infrastructure Investment and Jobs Act-funded projects. The forthcoming review is intended to examine implementation progress, compliance with reform requirements and whether the authority used the federal investment effectively.
For Washington-area riders and taxpayers, the practical question is whether WMATA converts the findings into documented improvements in privacy governance, payment records, contract oversight and federal-award controls. The September report is an oversight snapshot of the first half of 2026, not a complete assessment of every current Metro operation.
Sources
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.