The Centers for Medicare and Medicaid Services (CMS) exposed some healthcare providers’ Social Security numbers through a downloadable database linked to a new Medicare provider directory, according to reporting by The Washington Post and HIPAA Journal. The directory was built to help seniors identify which doctors and medical providers accept specific insurance plans, but the underlying database was reportedly publicly accessible for several weeks. Reporters said they were able to identify dozens of SSNs by reviewing only a sample of the records, raising concerns about the handling of sensitive provider data in a system CMS had promoted as part of a broader healthcare technology modernization effort.
CMS said the exposure stemmed from providers or their representatives entering information into incorrect fields, and the agency said it is working on a fix while adding stronger submission and validation safeguards. The disclosure renewed criticism of the provider directory’s rollout, which had already faced scrutiny over inaccurate insurance network information. The incident also lands amid heightened concern over Social Security number exposure more broadly, following separate reporting on the National Public Data breach, where a threat actor allegedly stole and leaked a massive trove of personal records that included SSNs and other identifying information.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
CMS said it was working on a fix for the exposed provider directory data and strengthening submission and validation safeguards. The incident also renewed criticism of the portal's rollout and data accuracy problems.
The Washington Post reported that CMS had inadvertently exposed healthcare providers' Social Security numbers through a database used by the Medicare portal. Reporters said they were able to identify dozens of SSNs by reviewing only a sample of records.
A downloadable database tied to the CMS provider directory was publicly accessible for several weeks and contained some healthcare providers' Social Security numbers. The exposure was reportedly caused by provider or representative information being entered into incorrect fields.
CMS created a new provider directory the previous year to help Medicare beneficiaries identify which doctors and medical providers accept specific insurance plans. The portal was presented as a modernization effort to improve healthcare technology.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.