{"database": "press", "table": "releases", "rows": [["https://www.crapo.senate.gov/media/newsreleases/crapo-requests-information-on-social-security-data-protections", "Crapo Requests Information on Social Security Data Protections", "2025-09-10", "2025", "2025-09", "Republican", "Senate", "ID", "Mike Crapo", "C000880", "www.crapo.senate.gov", "crapo", "https://www.crapo.senate.gov/media/newsreleases", "scraper", "Washington, D.C.\u2014Following recent allegations of data mishandling within the Social Security Administration (SSA), U.S. Senate Finance Committee Chairman Mike Crapo (R-Idaho) requested information from the agency to better understand the SSA\u2019s data storage and security practices, and to immediately confirm whether sensitive personally identifiable information was accessed, leaked, hacked or disseminated in any unauthorized fashion.\n\n\"All credible whistleblower allegations must be taken seriously and claims should be thoroughly investigated if warranted,\u201d said Crapo. \u201cIt is critical that federal agencies work to implement the strongest protections for Americans\u2019 most sensitive personal information and ensure any data mismanagement is addressed through congressional oversight.\u201d\n\nIn the letter to SSA Commissioner Frank Bisignano, Crapo requests information on:\n\nWhat actions SSA took upon receipt of the whistleblower\u2019s concerns about the agency\u2019s data security practices;\n\nWhat security measures are in place to ensure sensitive information is handled in accordance with applicable laws and regulations;\n\nWhen SSA first stored personally identifiable information in a cloud environment; and\n\nHow the SSA assesses the risk of providing certain agency employees with the ability to transfer data from the Numident database to a private cloud environment, and if the process diverged from the agency\u2019s usual risk assessment process.\n\nRead the full letter here or below:\n\nDear Commissioner Bisignano:\n\nI write to inform you that my staff and I reviewed information recently made public through disclosures and supplemental documents provided to Congress and the U.S. Office of Special Counsel, by Mr. Chuck Borges, a protected whistleblower and former Chief Data Officer of the Social Security Administration (SSA or \u201cagency\u201d) on August 26, 2025.\n\nIn his complaint against the agency, Mr. Borges described alleged shortfalls in how SSA safeguards personally identifiable information (PII), in a test cloud environment, including how the agency governs access, management, and storage of such sensitive information. Mr. Borges further alleged that his attempts to report his security concerns to his superiors were ignored, which in turn created a hostile work environment and culminated in his resignation from the SSA on August 29.\n\nAs Chairman of the Senate Committee on Finance (\u201cCommittee\u201d), I must take very seriously every allegation made by a protected whistleblower. Further, given the large amount of sensitive data under SSA\u2019s control, I consider the protection and security of PII held by the agency to be a matter of first importance.\n\nAs an immediate first step, considering the seriousness of Mr. Borges\u2019 allegations concerning SSA\u2019s ability to safeguard data collected and maintained by the agency, please inform the Committee on Finance immediately upon receipt of this letter whether the Numident database itself or any data contained in the Numident was accessed, leaked, hacked, or disseminated in any unauthorized fashion.\n\nTo better understand the SSA\u2019s data security practices more broadly and the agency\u2019s response, if any, to Mr. Borges\u2019 allegations, I am providing you with the opportunity to respond to the following questions by September 23, 2025.\n\nWhat actions did SSA take upon receipt of Mr. Borges\u2019 concerns about the agency\u2019s data security practices, including its handling of the Numident database and the data it contains?\n\nWhat security measures and/or oversight mechanisms are in place at SSA to ensure sensitive data and PII are handled in accordance with applicable laws and regulations?\n\nWhen did SSA first store PII in a cloud environment? Why and when did SSA select Amazon Web Services (AWS) to be the agency\u2019s cloud service provider?\n\nHow did the SSA assess the risk of providing certain agency employees with the ability to transfer data from the Numident database to a private cloud within SSA\u2019s AWS cloud environment? Did this process diverge from the agency\u2019s usual risk assessment process? If so, how?\n\nIf there are any other matters relevant to the Committee better understanding the agency\u2019s data security practices generally or Mr. Borges\u2019 concerns specifically, please provide additional details for the Committee\u2019s awareness.\n\nThank you for your attention to this important matter. I look forward to your immediate response to the first question regarding the status and security of Americans\u2019 personal information in the agency\u2019s possession, and to the other questions within two weeks.\n\nSincerely,\n\n###", 1, "2026-03-30T01:40:41Z", "2026-04-06T19:10:29Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.crapo.senate.gov/media/newsreleases/crapo-requests-information-on-social-security-data-protections"], "units": {}, "query_ms": 1.032107975333929, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}