About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline

HRD-78-116 1 (1978-06-05)

handle is hein.gao/gaobaaxkf0001 and id is 1 raw text is: 



                          DCCU BENT SESUME

 06218 - jB586O5J4

 Procedures to Safequard Social Security Beneficiary Records Can
 and Should Be Improved. HRD-78-116; B-164031 (4). June 5, 1978.
 28 pi,. + 4 apps~dicis i13 p., .

 Report to Rep. Charles Rose; Rep. John E. Pass; by Elmer B.
 Stdats, Comptrcl'ler General.

 Issue Area: Income Security Programs: Fruqzam aonitoring and
     Administration (1303).
Contact: Human Resources Div.
Budqet Function: Income Security: Public Assistance and Cthe,:
    Income Supplements (604); Income Security: General
    Betirement and bisebility Insurance (601).
Orqanization Concerned: Department ai Health, Education, end
     Uelfare; Social Security Administratios.
Conqressiknal Relevance: Rep. Cbatlee Hose; Rep. Johm IE. oss.
Authority: Freedom of Information Act.

         The Social Security Administration (SSA) is r.es.osible
fcr making correct and timely payme.zts to iadiv!'iual6 entitled
to benefits under social insurance and welfare FLog-ams and for
providing support functions for the medicare pxo/sA. These
proqrams qenerate millions of ricords cn wcrkexs and
beneficiaries that are .aintainee in aute :ated data banks and
fileo. Fiadinlqs/Conclusions: Persontl f lus within the data
system contain valuable private iufczma4icn that is necessary to
support present and future Social Security tenefits. SSA usea a
vast computerized telecommunications network tc process its
workload and to handle inquiries ficm the public. The
telecommuications system contained certain security weaknesses:
the ability to create as well as query beneficiary files from
most terminals, failure to use audit trail features within the
system, failure to always lock terminals dvring nonworking
hours, and unlimited unrestricted access tc terminals. Piles
containinq personal data on beneficiaries such as earnings
rscords, financial status, and medical evaluations were not
beinq properly safeguarded from potential lc.s, destruction,
abuse, or misuse. SSA had not issued gidelines or criteria for
establishincg physical cecurity measures at field offices and had
not determined if adequate security was Frcvided in the kandling
of information by states in administering welfare programs and
by insurance companies in administering medicare.
Recommendations: The Secretary of Health, Education, and Welfare
should direct the Commissioner of SSA to ccirect weaknesses in
the telecommunications network and ccnt.nue tc pursue an active
security Oroqram t, assure the Congres, the Eublic, and
beneficiaries that records are properly safeguarded. In this
effort, the Secretary should conduct a risk analysis to
determine how best to correct physical sec,rity weaknesses,
ir.cludinq measures which will achieve a baUance between good
service to beneticiaries and good security. (HTM)

What Is HeinOnline?

HeinOnline is a subscription-based resource containing thousands of academic and legal journals from inception; complete coverage of government documents such as U.S. Statutes at Large, U.S. Code, Federal Register, Code of Federal Regulations, U.S. Reports, and much more. Documents are image-based, fully searchable PDFs with the authority of print combined with the accessibility of a user-friendly and powerful database. For more information, request a quote or trial for your organization below.



Contact us for annual subscription options:

Already a HeinOnline Subscriber?

profiles profiles most