Trump’s Medicare Portal Exposed Dozens of Doctors’ Social Security Numbers to Public

The Trump administration launched a new Medicare provider directory, designed to help seniors find doctors and insurance plans — framed as a long-overdue healthcare technology modernization effort led by CMS federal officials.

The Washington Post discovered a publicly accessible database powering the directory contained Social Security numbers of health providers — linked to their names and other identifying information — exposed for at least several weeks without any public awareness.

The Post downloaded the database and reviewed a sample of rows, identifying at least dozens of Social Security numbers belonging to real health care providers — confirming the breach’s scope through direct, firsthand data analysis.

On Tuesday, The Post notified health officials, giving CMS time to take down the database. Affected providers, contacted directly, said they were confused and deeply concerned about the serious risk of identity theft.

CMS blamed the exposure on providers entering data in wrong fields, calling them “incorrect entries.” The agency claimed it had taken steps to “promptly address” the issue and reinforce data submission safeguards going forward.

The directory is part of a DOGE-led national initiative by Amy Gleason, already plagued by prior errors. Democratic senators had warned CMS that a rushed rollout risked misleading seniors and leaving them with unexpected, uncovered medical bills.



