Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
Networking Communications
Security Directives and Compliance
Data Center Virtualization
Air Force ELSG Contract Guide
Security Management
DOD and Security Guide
Networx Contract Guide
SEWP IV Contract Guide
Priority Report: Virtualization
Priority Report: Networking Services

More >>



Latest News
ADVERTISEMENT





 

SSA lists thousands of live persons as dead

By Michael Hardy
Published on June 26, 2008

Comment

Click here to comment on this article


Related story links

SSA expands access to Death Master File

Time to update the Privacy Act?

IG Report: Personally Identifiable Information Made Available to the General Public Via the Death Master File


Newsletters

You might also be interested in these FCW newsletters:

Daily
Management

To learn more, click here.


The Social Security Administration inadvertently compromised the personal information of more than 20,000 people by listing them in the Death Master File (DMF) while they were still alive, the agency's inspector general has determined.

The IG's analysis dates to January 2004. Since then, SSA has made the live people's Social Security number, full name, date of birth, and state and ZIP code of last known residence available to users of the database, the IG found.

After learning that those people were not deceased, SSA deleted the information, which limited its spread. However, that had no effect on the information previously made available to DMF subscribers.

The IG's investigators found some instances where the personal information was available for free viewing on the Internet, according to a June 4 IG report.

SSA provides the data to the Commerce Department's National Technical Information Service (NTIS), which in turn sells it to customers. Customers include the government, investigative businesses, financial and credit reporting firms, and geneaology researchers. Some, including prominent geneaology Web sites, post some or all of the information online for their users.

To prevent a repeat of the situation, the IG's  recommendations include:

  • Implementing a risk-based approach for distribution of DMF information. One suggestion: Have NTIS delay release of updates to public customers for one year to give SSA ample time to correct erroneous entires.
  • Limiting information included in the data sold to public customers.
  • Starting required breach notification evaluation procedures.
  • Providing appropriate notification to living individuals whose information was released in error.

In response to the IG's report, SSA said limiting the personal information might be difficult, but it would consider doing so. The agency agreed with the other recommendations.


upcoming event

Occupational Health & Safety Executive Summit - Arlington, VA
October 6 - October 7, 2008

Top 100 Executive Briefings: Focus on Enterprise Network Security, Fairview Park Marriott in Falls Church, VA 2008
October 9, 2008

Transition 2009, Four Points Sheraton, Washington, DC
October 15, 2008

GCN Awards Gala, Hilton Washington in Washington, D.C.
October 22, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email