Story perspectives
CMS Leak Exposes 100+ Provider SSNs, Sparks Senator Warning
5/3/2026
1 of 1
Story summary
- CMS unintentionally released Social Security numbers for at least 100 providers and removed the National Provider Directory.
- The breach happened because providers entered SSNs in the wrong form field.
- Senators Jeff Merkley and Ron Wyden wrote to CMS Administrator Mehmet Oz warning that the rushed rollout could mislead seniors.
- A whistleblower said the Department of Government Efficiency stored SSN data on an unsecured cloud server, raising identity-theft concerns.
