SSA needs to enhance its data verification systems, watchdog finds

Marcin Golba/NurPhoto via Getty Images

Improving matches between agency and external data could reduce improper payments, inaccurate records and manual work for federal employees the agency’s inspector general found.

The Social Security Administration could improve the administration of its programs and increase verified matches between external data and internal records by updating its verification systems for Numident, “a database that stores personally identifiable information for all individuals assigned a Social Security number,” the agency’s watchdog recently found

The Office of the Inspector General offered SSA two recommendations for improving the data-matching systems: create processes for agency components to work on improving the Numident verifications systems’ matching criteria and conduct periodic risk assessments. The agency accepted the recommendations.

“Enhancing these systems will not only improve accuracy — it will reduce manual workloads, strengthen program administration and help prevent improper payments, said Michelle Anderson, an SSA assistant inspector general, in a Thursday press release. 

The agency also plans to consolidate several Numident verification systems into a centralized platform, but system owners have yet to develop plans to improve current matching criteria, the release said.

Through over 3,400 data sharing agreements, SSA receives data from third-party organizations such as prisons, the Internal Revenue Service and state agencies, according to the agency. SSA verifies some — but not all — of that outside information by comparing it with SSA records through various Numident verification systems. For example, the agency verifies reported dates of death, employer wages and IRS self-employment wages.

The verification process is designed to ensure the SSA correctly connects data with the appropriate persons’ records. But the OIG found that four Numident verification systems could not verify 1.3 billion system transactions or about 9% of all transactions between fiscal years 2021 and 2025. 

The OIG analyzed 30 transactions that Numident verification systems could not verify and found that all of those missed matches could have been avoided if SSA “had incorporated other criteria from SSA’s manual verification policy or other systems, or used advanced analytics similar to those used by other Federal agencies.”

The watchdog specifically found that 26 out of 30 system transactions could have been matched if SSA used the same criteria employees use to manually verify data matches. 

In one example, a Numident verification system rejected a death report because the system had the name “Ginnie” on file but the death report listed the name “Jinnie,” according to the OIG. SSA employees are allowed to tolerate similar first names with minor spelling differences. Had the agency allowed the verification system to use that same criteria, it would have automatically added the death report data to the beneficiary’s Numident and payment record, according to OIG.

It also found that 22 out of 30 system transactions could have been matched if SSA verification systems used similar criteria to each other. None of the Numident systems the OIG reviewed used the same data matching criteria. 

In one example, a Numident verification system known as EVS rejected a prisoner report because the system had the last name “Smith Johnson” on file, but the prisoner report listed “Johnson.” Had the EVS system used the same matching criteria as another Numident verification system, known as the SSN Name Validation System, it would have matched the prisoner report.

The OIG found that SSA employees responsible for different Numident verification systems did not collaborate on matching criteria their systems used.

It also found that Numident verification systems would have verified matches for 25 out of 30 reports with at least 90% confidence if SSA used advanced analytics similar to those used by other agencies.

In one example, a Numident verification system rejected a death report because the first and last names it received did not match what SSA had on file. The Numident name was “Jane Doe” but the death report name was “Doe Jane,” according to the OIG. Had SSA used a token-based matching program similar to what other agencies use, it would have matched the death report with agency data at a 100% confidence level, the office added. 

The agency has since added the date of death to the beneficiary’s Numident data and payment record, which has kicked off a recovery of overpayments worth about $83,018.

“If SSA increased matches by even 1 percent of the transactions it reported its systems could not verify during our audit timeframe, it would see millions of additional matches each year. These additional matches could potentially prevent improper payments, inaccurate records, and additional manual work for SSA employees,” according to the OIG report.