SSDISocial Security Death Index Search

Why we do not publish Social Security numbers

The file this site is built from contains 90,382,560 full Social Security numbers. We stripped every one of them before the data went anywhere near a web server. The numbers are not in the database this site queries, not in the API, and not in any file on the machine that serves these pages.

This is legal to publish. We are choosing not to.

To be clear about the law: republishing this data is lawful. The Death Master File was fully public when this copy was made. Section 203 of the Bipartisan Budget Act of 2013 restricted access to records of people who died within the previous three years — every death in this file was reported by August 2011, so none of them fall under that restriction. Ancestry, FamilySearch and others publish these numbers today.

We still think it is a bad idea, for a specific reason.

The specific reason

A full name, a date of birth, and a Social Security number are, together, everything somebody needs to file a tax return in a dead person's name and collect the refund. They are most of what is needed to open credit in that name, and they are the raw material for synthetic identity fraud, where a real number is combined with an invented person and used for years.

This is not a hypothetical harm. It is the exact harm Congress was legislating about in 2013, and the reason the file is closed today. The people it hurts most are the survivors — a parent who finds out their dead child's number has been used, a widow untangling a fraudulent return.

The usual answer is that the data is already public, so publishing it changes nothing. We do not find that convincing here. The existing copies are paywalled, login-gated, rate-limited, or awkward to bulk-download. A free, complete, fast, no-login, fully-indexed, API-having copy would not be one more source among many — it would immediately be the most convenient source of 90,382,560 Social Security numbers in existence. That convenience is the whole product. Pointing it at this particular field seemed like the wrong use of it.

Why not just the last four digits?

Because the first five are not random. The first three digits — the area number — were assigned by state, and the middle two were issued in a documented order over time. If you know someone's last four digits, the state that issued the number, and roughly when they got it, the remaining space is small enough to be worth guessing at. Publishing the last four of a number whose front half is inferable is not much of a redaction.

The last four digits are also the single most common field used to verify identity over the phone.

What we publish instead

The state or territory that issued the number. That is the part with genealogical value — it often tells you where a person was living when they first worked — and on its own it narrows nothing: the six digits behind the area number are still a million possibilities, and we publish none of them.

Records of living people

This is a file of deaths, but government records contain errors, and a small number of living people have historically been listed in it by mistake. If you are one of them, or you have another reason to want a record taken down, we will remove it — no explanation required, no fee, and it takes effect immediately.

What we collect about you

Nothing. No accounts, no cookies, no advertising trackers, no session identifiers. The server keeps ordinary web logs. Searches are not associated with anyone.