Several federal laws protect the privacy of your Social Security number, but no single statute covers every situation. The Privacy Act limits how government agencies can demand the number; the Gramm-Leach-Bliley Act and Fair Credit Reporting Act govern banks and credit bureaus; HIPAA covers healthcare providers; the Driver’s Privacy Protection Act restricts state DMVs; and a set of criminal statutes punishes anyone who steals or misuses your number. Each law fills a different gap, and the private-sector gaps that remain are usually filled by state law rather than federal rules.
When a Government Agency Asks for Your SSN
The Privacy Act of 1974 is the closest thing to a general federal SSN protection law. Section 7 of the Act applies to every federal, state, and local government agency that requests your Social Security number. When an agency asks, it must tell you three things: whether disclosure is mandatory or voluntary, what law authorizes the request, and how the number will be used.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
The core protection is the anti-denial rule. An agency generally cannot deny you a right, benefit, or service just because you refuse to hand over your SSN.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals Two exceptions apply. The first is where a separate federal statute specifically requires disclosure. The second is where the agency’s record system was already in operation before January 1, 1975, and required the number under a pre-existing statute or regulation. Grandfathered systems like the IRS can still demand it.
Once a federal agency has your number, it can share it with other entities for purposes “compatible with” the reason it was originally collected. Each agency publishes its approved routine uses in the Federal Register, and disclosures are supposed to be limited to the minimum information needed.2Social Security Administration. Disclosure Without Consent to Federal Agencies and Officials Courts have generally read “compatible purpose” broadly.
If an agency intentionally or willfully violates the Privacy Act’s rules and the violation causes you harm, you can sue in federal court. A successful plaintiff recovers actual damages with a floor of $1,000, plus reasonable attorney fees.3U.S. Department of Justice. Overview of the Privacy Act of 1974 – Remedies Negligent mistakes do not trigger the $1,000 minimum. Courts have dismissed cases where the violation was careless rather than deliberate.
Banks, Credit Reports, and Consumer Data
The Gramm-Leach-Bliley Act (GLBA), at 15 U.S.C. §§ 6801–6809, requires financial institutions to protect “nonpublic personal information,” which includes your Social Security number.4Office of the Law Revision Counsel. 15 USC 6801 – Protection of Nonpublic Personal Information Banks, insurers, and investment firms have to give you a privacy notice when you first become a customer and at least once a year after that.5Office of the Law Revision Counsel. 15 USC Chapter 94 – Disclosure of Nonpublic Personal Information
Before sharing your information with a company outside its corporate family, the institution has to tell you the sharing may happen, explain how to opt out, and give you time to do so before any disclosure occurs.6Office of the Law Revision Counsel. 15 USC 6802 – Obligations With Respect to Disclosures of Personal Information The opt-out does not apply when the institution shares data with a service provider under a confidentiality contract, or in situations like processing a transaction you initiated.
The Fair Credit Reporting Act (FCRA), at 15 U.S.C. § 1681, adds a layer around credit reports. Only entities with a “permissible purpose” — lenders, landlords, employers with your consent, insurers — can pull your report. When you request your own credit file, you can ask the bureau to truncate the first five digits of your SSN so the report shows only the last four.7Office of the Law Revision Counsel. 15 USC 1681g – Disclosures to Consumers
A business that willfully ignores FCRA owes you either actual damages or statutory damages between $100 and $1,000 per violation, whichever is higher, plus potential punitive damages and attorney fees.8Office of the Law Revision Counsel. 15 USC 1681n – Civil Liability for Willful Noncompliance Negligent violations do not carry statutory damages, but you can still recover actual damages and attorney fees.9Office of the Law Revision Counsel. 15 USC 1681o – Civil Liability for Negligent Noncompliance
Getting Rid of the Paperwork
When a business no longer needs your consumer information, it cannot just throw it away. The FTC’s Disposal Rule at 16 CFR Part 682 requires any business that holds consumer report data — including SSNs pulled from credit reports — to take “reasonable measures” to prevent unauthorized access when disposing of it.10eCFR. Disposal of Consumer Report Information and Records (16 CFR Part 682) Paper records must be shredded, burned, or pulverized. Electronic files must be destroyed or wiped so the data cannot be reconstructed. Companies that hire outside shredding services have to vet the vendor.
Medical Records
The Health Insurance Portability and Accountability Act (HIPAA) protects your Social Security number when it appears alongside health information. The HIPAA Privacy Rule treats identifiers like your SSN as protected health information when linked to data about your condition, treatment, or payment.11Centers for Medicare & Medicaid Services. HIPAA Basics for Providers: Privacy, Security, and Breach Notification Rules Hospitals, doctors, insurers, and their business associates cannot disclose that information without your written authorization, with limited exceptions for treatment, billing, and certain healthcare operations.
When a breach exposes your SSN or other unsecured health data, HIPAA’s Breach Notification Rule requires the organization to notify you in writing within 60 days of discovering the breach. The notice has to describe what happened, what information was involved, what you should do to protect yourself, and what the organization is doing about it.12U.S. Department of Health and Human Services. Breach Notification Rule If the breach affects 500 or more people in a state, the organization also has to alert major media outlets in that area. All breaches must be reported to the Secretary of HHS, with larger ones reported within 60 days and smaller ones in an annual summary.
HIPAA civil penalties range from a few hundred dollars for unknowing mistakes to over $2 million per year for willful neglect that goes uncorrected. Criminal penalties enforced by the Department of Justice can reach 10 years in prison for violations committed with intent to sell or misuse the data.
State DMV Records
State motor vehicle departments hold a lot of your personal data. The Driver’s Privacy Protection Act (DPPA), at 18 U.S.C. § 2721, prohibits DMV employees and contractors from knowingly disclosing personal information from motor vehicle records, including SSNs, unless the disclosure fits one of 14 specific exceptions.13Office of the Law Revision Counsel. 18 USC 2721 – Prohibition on Release and Use of Certain Personal Information From State Motor Vehicle Records
The permitted disclosures lean toward government functions, law enforcement, court proceedings, motor vehicle safety investigations, and insurance claims. Businesses can access records to verify information you submitted or to pursue fraud prevention and debt recovery, but bulk data requests for marketing or surveys require your express consent.
If someone knowingly obtains or discloses your motor vehicle records for a prohibited purpose, you can sue in federal court. The statute guarantees a minimum of $2,500 in liquidated damages, so you collect at least that amount without proving a specific dollar loss. Willful or reckless violations open the door to punitive damages and attorney fees.14Office of the Law Revision Counsel. 18 USC 2724 – Civil Action
SSNs on Government Mail and ID Cards
Two federal laws target a low-tech risk: your Social Security number sitting on a piece of mail anyone could intercept. The Social Security Number Fraud Prevention Act of 2017 prohibits federal agencies from putting your full SSN on any document sent through the mail unless the agency head determines it is necessary for a specific purpose, and each agency has to adopt regulations spelling out that necessity.15eCFR. 43 CFR Part 2 Subpart M – Social Security Number Fraud Prevention Act Requirements The earlier Social Security Number Protection Act of 2010 bars federal and state agencies from printing your SSN on payment checks, and prohibits displaying the number on the outside of a mailing, including through a window envelope.
Medicare cards used to carry a Health Insurance Claim Number built directly from your Social Security number, which meant every doctor’s office, pharmacy, and billing clerk saw it. The Medicare Access and CHIP Reauthorization Act of 2015 required CMS to strip SSNs from all Medicare cards and replace them with randomly generated Medicare Beneficiary Identifiers.16Social Security Administration. HI 00901.040 – New Medicare Numbers and Number Change Requests CMS began mailing the new cards in April 2018. The MBI is an 11-character mix of numbers and uppercase letters designed to carry no hidden meaning, so it cannot be reverse-engineered to reveal your SSN or date of birth.17Centers for Medicare & Medicaid Services. Medicare Beneficiary Identifiers (MBIs) If you suspect your MBI has been stolen, request a replacement by calling 1-800-MEDICARE.
Military ID cards followed a similar path. Starting in 2008, the Department of Defense phased Social Security numbers off military identification cards and replaced them with a DoD ID Number. A separate DoD Benefits Number now handles TRICARE medical care in place of the SSN where possible.18Federal Register. Reduction of Use of Social Security Numbers in the Department of Defense
Employers and Tax Reporting
Your employer has to collect your Social Security number for tax reporting. IRS Publication 15 tells employers to record your name and SSN exactly as they appear on your Social Security card and to keep employment tax records for at least four years.19Internal Revenue Service. Publication 15 (2026), (Circular E), Employer’s Tax Guide The IRS warns against sending taxpayer identification numbers by email because email is not secure.
Beyond tax collection, though, no broad federal statute requires private employers to safeguard your SSN the way HIPAA governs healthcare data. The Social Security Administration urges organizations to treat SSNs as secondary identifiers, avoid using them in login systems or on ID badges, encrypt stored numbers, and never transmit them through insecure channels.20Social Security Administration. Protecting Social Security Numbers That guidance is voluntary at the federal level. If your employer is reckless with your SSN, the applicable law is almost certainly a state statute. Employers who participate in E-Verify do face federal requirements to safeguard personally identifiable information processed through the system, restrict access to authorized users, and discuss verification results privately with the affected employee.21E-Verify. Privacy and Security Statement
Criminal Penalties When Someone Steals Your SSN
Federal law criminalizes stealing or misusing a Social Security number. The main identity fraud statute, 18 U.S.C. § 1028, defines your SSN as a “means of identification” and makes it a crime to produce, transfer, or use another person’s identifying information without authorization. Standard identity fraud carries up to five years in federal prison, with sentences rising to 15, 20, or 30 years for fraud involving government documents, drug trafficking or violent crime, or terrorism.22Office of the Law Revision Counsel. 18 USC 1028 – Fraud and Related Activity in Connection With Identification Documents, Authentication Features, and Information
A separate aggravated identity theft statute, 18 U.S.C. § 1028A, adds a mandatory two-year prison sentence for anyone who uses another person’s means of identification during the commission of certain felonies. That two years runs consecutively, so it gets tacked onto the sentence for the underlying crime. Courts cannot reduce it, run it concurrently, or substitute probation.23Office of the Law Revision Counsel. 18 USC 1028A – Aggravated Identity Theft
Under Social Security law itself, 42 U.S.C. § 408 targets misuse tied to Social Security programs. Using a false SSN to obtain benefits, making false statements to the SSA, or buying or selling Social Security cards is a felony carrying up to five years. Professionals who commit fraud connected to benefit determinations — claimant representatives or healthcare providers, for example — face up to ten years.24Office of the Law Revision Counsel. 42 USC 408 – Penalties
How to Report Misuse
If you discover someone is using your Social Security number, the right agency to contact depends on what happened.
For identity theft in general — someone opened accounts, filed taxes, or claimed benefits in your name — start at IdentityTheft.gov. The site walks you through your situation, generates a personal recovery plan, and produces an official FTC Identity Theft Report you can give to creditors and law enforcement.25IdentityTheft.gov. IdentityTheft.gov The FTC does not investigate individual cases, but reports feed into the Consumer Sentinel database that law enforcement uses to identify patterns.
For fraud tied specifically to Social Security benefits — someone collecting your retirement checks, using your number to claim disability — report to the Social Security Administration’s Office of the Inspector General. File online at oig.ssa.gov or call the fraud hotline at 1-800-269-0271 on weekdays during business hours.26Social Security Administration. Fraud Prevention and Reporting The OIG will not tell you what action it takes, but filing the report creates an official record and can trigger an investigation.
Whichever agency you contact, place a fraud alert or credit freeze with the three major credit bureaus as soon as you suspect misuse. A fraud alert is free and forces creditors to take extra verification steps before opening new accounts. A credit freeze blocks access entirely until you lift it. Neither requires proof that fraud has already happened. Suspicion is enough.