A federal agency losing money to fraud is a story as old as the ledger. A federal agency losing money because it declined, for years at a stretch, to open its own mail is something rarer, and considerably more damning. That is the finding buried inside the Social Security Administration Office of the Inspector General’s latest audit, “Supplemental Security Income Earnings Alerts” (Report 022310, September 2026), a document that manages to be both bone dry and quietly incendiary.
The Alert Nobody Answered
SSI recipients are supposed to report their income every month, since the program exists for people with limited means and the payment shrinks as earnings rise. When the IRS or a state agency reports wages that don’t match what SSA has on file, the system throws an earnings alert. An employee is then required to contact the recipient, verify the discrepancy, and adjust the record accordingly. This is not an exotic obligation; it is described in plain terms in SSA’s own Program Operations Manual System (POMS SI 02310.005, SI 02310.062).
OIG pulled a random sample of 100 SSI recipients out of a population of 417,291 who had at least one earnings alert pending as of September 2024. The results were not flattering. Employees fully resolved alerts for 20 of the 100. For 63 recipients, reviews were either never started or never finished, and as of April 2025 those alerts had been sitting for an average of 733 days, roughly two years of an unopened envelope. Nine of them had been pending for more than five years. For another 17 recipients, staff cleared the alert but failed to record all the earnings that should have changed the payment, which is less “resolved” and more “closed and mislabeled.”
The Fine Print That Makes Delay Profitable
Here is where the report stops being merely embarrassing and becomes structurally interesting. SSA operates under an administrative finality rule, and absent a finding of fraud, the agency generally cannot reopen and revise eligibility determinations more than 24 months old. If an employee reviews an alert within six months of its creation, that counts as diligent pursuit, and SSA can reach back a full 24 months from the original alert date to recover an overpayment. If the employee does not meet that standard, the 24 month window instead runs from whenever the review finally happens, however late. Every month of institutional foot dragging is a month of debt quietly aging out of collectability.
OIG’s own example makes the mechanism vivid. A father’s 2017 earnings discrepancy triggered an alert in July 2018. An SSA employee scheduled two appointments in 2019, the father missed both, and the file simply sat there. By 2026, the alert had gone unresolved for over seven years, and the agency estimated it had paid the child recipient roughly $36,000 that hinged on the father’s unreported income. Because nobody picked the file back up until 2026, SSA could only recover approximately $19,000 of it. The other $19,000 became, in the agency’s own language, correct, a status it acquired not through verification but through neglect.
A Billion Dollars, Filed Under Never Mind
Projected across the full population, OIG estimates SSA paid about 333,800 recipients roughly $1 billion they were not eligible to receive, because employees did not complete, or did not correctly complete, the earnings reviews required to catch it. Of that billion, the administrative finality clock has already rendered approximately $664 million permanently uncollectable, absent a fraud determination the agency has shown no particular urge to pursue. The remaining $344 million is, for now, still theoretically recoverable, assuming anyone gets around to it.
It is worth sitting with that arithmetic for a moment. Two thirds of the overpayment total identified in this single sample projection is not merely uncollected; it is uncollectable by design, a feature of the agency’s own finality doctrine rather than a bug in enforcement. SSA did not lose this money to a sophisticated fraud ring. It lost it to a filing cabinet.
Nobody Home
Perhaps the most telling line in the entire report is the one OIG offers almost in passing, that auditors “could not determine why employees did not initiate or complete reviews of earnings alerts in accordance with Agency policies, and Agency subject-matter experts could not provide an explanation.” Not a bad explanation. No explanation. The people whose job it is to know why their own agency’s controls failed had nothing to offer.
This is also not SSA’s first rodeo with this exact problem. A 2012 OIG review found the agency was not timely developing earnings alerts and estimated roughly $110 million in preventable or recoverable SSI overpayments. SSA responded then with the standard bureaucratic liturgy, reminders issued, guidance reissued, a promise to do better. Fourteen years later, the same failure mode reappears at nearly ten times the estimated cost. SSA has once again agreed to implement OIG’s three recommendations, namely clean up the 63 unresolved cases and the 17 incomplete ones, figure out why staff aren’t pursuing alerts, and implement corrective action. The agency’s official comment, from Chief Risk Officer Chad Poist, characterizes some of the flagged cases as simply not yet due for redetermination under existing timelines, and notes that corrective action has already been completed on a portion of the cited cases, a caveat OIG’s own report does not credit.
Whether this round of promises fares any better than the last is not a question this audit answers, and it is not one the agency seems especially eager to answer either. What the report does establish, in the agency’s own numbers, is that the cost of that uncertainty is not abstract. It has a dollar figure, it has a 24 month expiration date, and as of the report’s own projections, most of it will be gone before anyone in Baltimore gets around to reading the file.
Source: SSA Office of the Inspector General, “Supplemental Security Income Earnings Alerts,” Report 022310 (September 2026).
