Doctor holding smartphone with data breach icon overlayed

Medicare Portal Exposed Healthcare Provider Social Security Numbers

A public database intended to help patients find doctors inadvertently leaked the sensitive personal information of thousands of providers.

A publicly accessible Medicare database exposed Social Security numbers of health care providers for several weeks before federal officials took it offline, as reported by Newsweek and The Washington Post.

The database powered a national provider directory run by the Centers for Medicare & Medicaid Services, or CMS. It contained sensitive provider information, including Social Security numbers entered into public fields by providers or their representatives. The news outlets report that CMS attributed the issue to data entry errors, not a cyberattack. A CMS spokesperson told The Post the agency addressed the problem after being alerted.

The directory helps Medicare beneficiaries find doctors and other providers. CMS has not disclosed how many providers were affected or whether they have been notified. However, Newsweek reports this exposure raises questions about data validation in federal health systems, with lawmakers previously having criticized the directory project for accuracy issues.

Providers whose data may have been exposed face identity theft risks, as their Social Security numbers were linked to names, addresses and National Provider Identifiers. Experts recommend monitoring credit reports, setting fraud alerts with Equifax, Experian and TransUnion and checking Social Security earnings records at ssa.gov.

The Washington Post has clarified that only health care providers are affected, with no evidence of patient or beneficiary information or Social Security numbers being exposed.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.