incident-responsetrade-pressNewsThe Broadside2 min read

Whitehouse, Wyden Press Bisignano After DOJ Filings Undercut SSA Pledges

Bisignano assured Congress SSA data was secure and managed under "strict security protocols." The agency's own DOJ court filings keep proving otherwise.


TL;DR

Sens. Whitehouse and Wyden fired off a letter to SSA Commissioner Frank Bisignano last week, calling fourteen months of responses to congressional DOGE inquiries "inadequate" and "later disproved by SSA's own admissions." The senators catalogued the pattern: Bisignano's January 2026 assurance that "SSA's systems and data are secure" was contradicted days later by a DOJ court filing revealing unauthorized PII transmission through an unapproved Cloudflare server. SSA still hasn't determined what data was shared. The letter also flags DOGE communications with an election-results advocacy group and a whistleblower's account of a plan to move 2.7 million living people into the Death Master File. Written answers are due Friday.

Senators Sheldon Whitehouse and Ron Wyden have now publicly catalogued what amounts to a fourteen-month compliance failure at the Social Security Administration: not by DOGE, whose access to SSA systems is the underlying problem, but by Commissioner Frank Bisignano, whose assurances to Congress have been repeatedly contradicted by the agency's own admissions in federal court.

The timeline is the diagnosis. At his March 2025 confirmation hearing, Bisignano pledged a "total review" of SSA databases after Whitehouse raised concerns about damage DOGE might have done. A November 2025 follow-up from the senators produced a January 2026 reply stating that "SSA's systems and data are secure and managed under strict security protocols, consistent with Federal and industry standards." Days later, a DOJ court filing in the AFL-CIO lawsuit revealed that DOGE personnel had transmitted PII through a third-party Cloudflare server "not approved for staffing SSA data," and that SSA officials didn't know about it until the records review. The filing also disclosed that a DOGE staffer transmitted an encrypted file containing roughly 1,000 names and addresses drawn from SSA systems to DOGE affiliates outside the agency. SSA hasn't determined with certainty what data was shared in either instance.

The senators' letter also surfaces two additional disclosures SSA has refused to address substantively: DOGE communications with an advocacy group seeking to "overturn election results," for which SSA "refused to provide unredacted information," and a June 2025 whistleblower complaint detailing a DOGE plan to mark 2.7 million living individuals as deceased in the Numident system to trigger immigration enforcement. Bisignano "failed to respond" to inquiries on the whistleblower's allegations.

For compliance directors and CISOs at organizations that rely on SSA's data integrity, the letter documents something structural: an agency whose commissioner can't give Congress a straight answer about what DOGE did with the most sensitive PII database in the federal government. Written responses are due Friday. The "total review" promised in March 2025 is now in its fifteenth month.


Published ·Updated ·Deep Fathom