Skip to content
KEDBYTE
How Identity Works
Chapter
11

What Goes Wrong When Identity Is Wrong

Part I · What Identity Is|12,185 words|about 53 min read|Volume 1

11.0 What this chapter gives you#

  1. You will be able to name the four shapes an identity error takes — a record matched to the wrong person, a record that fails to match the right one, one record holding two people, and one person holding two records — and say which harm each shape produces.
  2. You will be able to explain how another person’s debts get into your credit file, name the matching decision that lets it happen, and quote a real case with the sums awarded and the years it took.
  3. You will be able to describe what happens inside a hospital when two patients share one folder or one patient has two, quote the measured rates for both, and name the field that goes wrong most often.
  4. You will be able to say how a living person ends up recorded as dead, how often that happens in one national system, how the record is corrected, and why the correction is slower than the mistake.
  5. You will be able to work out, with arithmetic you can do on paper, why almost everybody a watchlist flags is innocent even when the matching is very accurate.
  6. You will be able to explain why the burden of proof quietly reverses when a record is wrong, name a public inquiry that found exactly that, and quote its finding in one sentence.
  7. You will be able to list the eight properties of a correction process that works, and score any real one — a credit bureau, a police record, a travel watchlist, a benefits office — against them.
  8. You will be able to measure a redress process with four numbers: time to first answer, time to correction, how completely the correction reaches everyone who got the wrong data, and how often the error comes back.
  9. You will be able to say, with dates and figures, why the cost of an identity error is paid by the person, and what design changes move that cost back where it belongs.

An identity system makes two kinds of mistake. It can decide that two records are one person when they are two, and that two records are two people when they are one. Everything in this chapter grows from those two sentences. Both mistakes are cheap for the system and expensive for the person, and that asymmetry is why identity errors last for years rather than minutes.

We are going to be concrete throughout. A credit file with somebody else’s judgments in it. A hospital folder containing two people’s allergies. A benefits office that believes you died in March. In each case we follow the same three questions: how did the wrong thing get written, who found out, and how long did it take to unwrite. The third is the one this book cares about most, because it is the one almost never designed for.

These are not rare events. They are the expected output of ordinary systems running normally. When the United States Social Security Administration posted roughly 5.6 million death records in calendar year 2025, it later determined that 12,504 of them — 0.22 per cent — were wrong, according to the audit report Beneficiaries Incorrectly Recorded as Deceased, report 032311, dated 24 June 2026. Nothing broke. Two errors in a thousand is a good rate for a national database. It is also, in one system in one year, more than twelve thousand living people who had to prove they were alive.

That is the shape of the whole subject. A system that is 99.78 per cent right is excellent, and a catastrophe for the other 0.22 per cent, and no volume of engineering makes that figure zero. The real design question is not how to avoid the error. It is what happens next.

The plain version#

A shelf of folders#

Imagine a doctors’ surgery in a town of about forty thousand people. In the back office there is a wall of shelves, and on the shelves are paper folders, one for each patient. A folder holds everything the surgery knows about you: your date of birth, your address, what you are allergic to, what medicines you take, what you have been treated for and when.

The folders are filed by surname, then first name, then date of birth. When you arrive, the receptionist asks your name and your date of birth, walks to the shelf, and pulls your folder. The doctor reads it and decides what to do about you. If the folder is right, everything downstream is right. If the folder is wrong, everything downstream is wrong, and the doctor has no way to know, because the folder is the only thing she has.

That is worth sitting with. The doctor is not treating you. She is treating the folder, carefully and in good faith, and if the folder says you are not allergic to penicillin she will prescribe penicillin, and given what she was told she will be right to. The whole system’s competence rests on one act nobody thinks of as medicine: a receptionist picking a folder off a shelf.

Now let us break it in the four ways it breaks.

Two people, one folder#

There are two women in this town called Anita Rao. One was born on 4 March 1979. The other was born on 3 April 1979. In the surgery’s paper system, someone once wrote the second one’s date of birth in the day-month order used on one form and the month-day order used on another, and the two dates looked the same. So on one busy afternoon a receptionist decided the two folders were the same woman, and clipped them together.

From that day there is one folder holding two lives. It says the woman is allergic to penicillin, which is true of one of them. It says she takes a blood-thinning medicine, which is true of the other. It records a pregnancy, a broken wrist, a thyroid condition, and a course of antibiotics, and each of those things happened to one of two different people.

Nothing looks wrong. That is the horrible part. There is no gap, no blank line, no warning. The folder is full and tidy and internally plausible, and it describes a person who does not exist. When one Anita Rao comes in with chest pain, the doctor reads a history that is half somebody else’s, and makes a decision that is correct for a patient who is not in the room.

One person, two folders#

The other break is the mirror image. One Anita Rao married and changed her surname. She told the surgery. The clerk who took the call made a new folder under the new name, because that was quicker than finding and re-filing the old one, and meant to merge them later, and did not.

Now there is one woman with two folders. One holds fifteen years of history. The other holds three months. Whichever one the receptionist happens to pull is the one the doctor believes.

This break is quieter than the first, and in some ways worse. Nothing in the new folder is false. Every line in it is true. The damage is done entirely by what is missing: the allergy that was recorded eleven years ago and is not in this folder; the scan that showed the shadow on the lung; the fact that this patient has already tried this drug and reacted badly to it. A folder that is merely incomplete looks exactly like a folder for a healthy person with an uneventful past.

The general rule underneath both breaks: wrongly joining two people creates false facts, wrongly splitting one person creates missing facts, and missing facts are harder to notice, because absence has no shape.

The drawer marked “no longer with us”#

At the back of the office there is a second set of shelves, for people who have died. Once a fortnight a clerk moves folders across. It is a small, dull job.

Suppose the clerk moves the wrong folder. Suppose the death notice said “A. Rao” and there were two.

Very little happens at first. Then the pharmacy stops filling the prescription, because the surgery’s list says there is no such patient. Then a hospital letter is returned. Then, because the surgery also tells the town council and the pension office, a payment stops. Then the bank, which is told by the pension office, freezes the account, because the bank’s rule for a dead customer is to freeze first and ask afterwards. Then the card in her purse stops working in the shop.

And here is the thing that makes this different from every other kind of error. To get any of it undone, she has to persuade each of those offices in turn that she is alive, and she has to do it without a bank card, without a prescription, and with the surgery’s list — which is the thing everybody else trusts — still saying she is dead. The evidence she needs is downstream of the error. Her ability to fix the record has been taken away by the record.

Correcting a mistake is normally a small errand. This one is not a small errand, because the mistake removed her means of running errands.

The red sticker, and why nearly everyone who has one is innocent#

Now a different sort of folder problem, and the one people reason about worst.

Suppose the town’s police send the surgery a list of forty people they want to speak to, and ask the receptionist to put a red sticker on those folders. The receptionist checks each arriving patient’s name against the list. She is careful and she is right ninety-nine times out of a hundred.

The surgery sees about four thousand patients a month. Of those four thousand, let us say four are genuinely on the list.

Watch what happens. Of the four real ones, she spots roughly four. Of the three thousand nine hundred and ninety-six who are not on the list, she is wrong about one in a hundred, which is about forty people. So at the end of the month she has put stickers on about forty-four folders, and only four of them belong to anybody the police wanted.

Ninety per cent of the red stickers are on innocent people. Not because the receptionist is careless — she was right ninety-nine per cent of the time, which is very good — but because there are a thousand innocent people for every guilty one, and one per cent of a very large number beats one hundred per cent of a very small one.

This is not a clever paradox. It is arithmetic, and it is the most important number in the whole subject of checking people against lists: when the thing you are looking for is rare, most of what you find will be the wrong thing, even with a very good test.

And notice what it costs. Each sticker takes a second to apply. Each innocent person carrying one has to go somewhere, wait, explain, and be believed by somebody who has a stickered folder in front of them.

Who pays#

Put the four breaks side by side and one thing is common to all of them. The surgery does not suffer. Its shelves still work, its throughput is unchanged, its error rate across all patients is excellent, and if anyone audits it, it will pass.

The person suffers, alone, and in a way the surgery has no field for. There is no box on any form for “eleven weeks without medication”, no counter that increments when somebody is turned away from a bank. The cost is real, large and completely invisible to the system that caused it, which is why systems keep producing it.

That is the thesis of this chapter, said once before we make it technical: an identity system’s error rate is a small number to the system and a whole year to the person, and until the correction process is designed as carefully as the matching process, that will not change.

Anita Rao, carried through#

We will follow one of the two Anita Raos for the rest of the chapter, the one born on 4 March 1979. In January her hospital records were merged with the other Anita Rao’s. In February a lender pulled her credit file, found a county court judgment belonging to the other one, and refused her a loan. In March a clerk processing a death notification for a third person with a similar name suspended her benefit. By the end of the year she had fixed one of the three.

Where the plain version stops being true#

There is no folder, and there is no shelf#

The single folder is a comforting lie. Your identity is not in one place that can be corrected; it is in dozens of places that were each given a copy at a different moment and have each since changed it independently.

The honest version: what you think of as “your record” is a family of partial, stale, contradictory copies held by organizations with no obligation to talk to each other and frequently no way to. Correcting the original does not correct the copies. It only stops the next copy from being wrong. If a hospital group, three insurers, a screening register and a research data set all copied the merged record during the eleven months it existed, fixing the hospital’s copy fixes one of six, and nobody is paid to go and find the other five.

The correction is not one event#

In the plain version the clerk un-clips the folders and it is over. In reality a correction is a sequence with different owners and very different clocks, and every step is a place the process stops: the person notices; works out who to tell; proves who they are to an organization that currently believes something false about who they are; somebody decides the change is warranted; the master record is changed; the change is pushed downstream; downstream systems apply it; anybody who acted on the wrong data is told; and the consequences of those actions are unwound.

Almost every real redress process stops at step five or six. The gap between “the record was corrected” and “the harm was undone” is where most of the suffering in this chapter lives.

Most identity errors are not bugs#

The plain version invites you to think somebody was careless. Sometimes somebody was. Much more often the error is the correct output of a deliberately chosen rule, where choosing the other way would have produced a different error somebody decided was worse. A credit bureau requiring an exact match on name, date of birth and full identity number before joining records produces almost no mixed files and enormous numbers of split ones, and a split file makes a person look as though they have no credit history, which denies them credit too. There is no setting with neither. Chapter 8 works through the mathematics of that trade-off; the point here is that the dial exists, somebody turned it, and the person harmed was not consulted.

The honest version: an identity error is usually a policy decision arriving at a particular person. The question to ask about any identity failure is not “what went wrong” but “which error was this system built to prefer, and who did it decide should absorb it”.

Nobody owns your identity end to end#

Real identity has no receptionist. No office anywhere can see all the places that hold a record about you, so none can correct them all, and none can tell you when you are finished. That is not an oversight but a deliberate property of a free society, argued for in chapter 10 on anonymity and linkability. It has a cost, and this chapter is that cost: the same absence of a central index that protects you from surveillance means that when you are wrongly recorded there is nobody to appeal to who can fix everything at once.

The false positive is not the machine’s mistake#

When a face matching or name screening system raises a wrong alert it is tempting to say the system got it wrong. Usually it did exactly what it was configured to do. Every such system has a threshold: a similarity score above which it declares a match. Raise it and you get fewer false alerts and miss more real ones; lower it and you catch more real ones and flood the operator with wrong ones. The number of innocent people stopped is not an accident of the technology. It is a dial, set by a person, usually without publishing where or why.

The honest version: “the algorithm made a mistake” almost always means “an organization chose an operating point that produces this many mistakes, and did not tell you what it was”.

The base rate argument does not make screening useless#

It would be dishonest to leave the red sticker arithmetic where we left it, because it is routinely over-claimed. That most alerts are false does not make a screening system worthless. It makes it a filter, not a verdict. A system that turns four thousand people into forty-four to look at has done real work, provided that looking at somebody is cheap, quick, respectful and reversible. The harm comes not from the flag but from what is attached to it: detention, refusal, a permanent note on a file, or a second officer who treats the flag as evidence rather than as a reason to check.

Experts genuinely disagree about where the line falls. Police forces argue that a low rate of wrong alerts per person scanned, combined with a rule that no arrest may rest on the match alone, makes the practice proportionate. Civil liberties organizations argue that scanning millions of uninvolved people to find a few hundred changes the relationship between citizen and state in a way no accuracy figure can settle. They are arguing about different things — one about error rates, one about consent — and the argument does not resolve while they are.

Your cost and the system’s cost are different numbers#

The last place the plain version breaks is the most important. In reality there are two cost ledgers and they do not balance. The system’s ledger records the error as a fraction: 0.22 per cent, one in 250, 92 per cent of alerts. Small, manageable, improving. Your ledger records it in months of your life, in a job you did not get, in a mortgage rate you paid for six years, in treatment that started late. Those units do not convert, and no amount of improvement in the first ledger appears in the second, because the second is not measured by anybody with the power to change the system.

Almost every good idea in the rest of this chapter is an attempt to force those two ledgers onto one page.

The technical version#

The four shapes, named precisely#

The vocabulary matters, because the same words are used differently in different industries and the confusion is expensive.

A false match is a decision that two records refer to the same entity when they do not. In biometrics this is a false positive, or in the language of ISO/IEC 19795 a false match; in record linkage a false link; in a consumer credit file it produces a mixed file; in a hospital master patient index an overlay. A false non-match is the reverse decision, that two records refer to different entities when they are the same: a false negative in biometrics, a missed link in record linkage, a duplicate in a hospital index, a split or fragmented file at a credit bureau.

Note that the plain-English phrasing and the health informatics phrasing are inverted, which trips up almost everyone who moves between the two fields. “Two people in one record” sounds like a duplicate and is called an overlay. “One person in two records” sounds like a split and is called a duplicate. A third term, overlap, means one person holding records in two indexes that ought to be linked and are not.

Shape Health index term Effect
Two people, one record Overlay False facts
One person, two records Duplicate Missing facts
One person, two indexes Overlap Missing facts
Wrong status on record (none) Loss of service

The fourth row has no standard name and deserves one. A record can be correctly resolved to exactly one person and still carry a status that is false: deceased, sanctioned, barred, ineligible, deported. This is the class that produces the most severe outcomes in this chapter, because status flags are usually designed to be acted on immediately and questioned later.

The mixed file: how another person’s debts reach you#

A consumer credit file is assembled, not stored. The agency receives millions of tradeline records a month from lenders, courts and collection agencies, each carrying some identifying data, and must decide which existing file each one belongs to. The matching runs on partial and inconsistent identifiers: a free-text name, current and former addresses, date of birth where supplied, and in the United States some or all of the Social Security number. Because furnishers supply incomplete data, the agencies match partially — historically on fewer than all nine digits of a Social Security number, and on similar rather than identical names. When two consumers share a common name and similar addresses, a partial match rule joins them, and one person’s file acquires the other’s judgments, defaults and collections. That is a mixed file.

The scale is measurable. The United States Federal Trade Commission carried out the study mandated by section 319 of the Fair and Accurate Credit Transactions Act of 2003, and reported on 11 February 2013 that of 1,001 participants who reviewed 2,968 credit reports, one in five had a verified error on at least one of their three reports, and five per cent had errors serious enough that correcting them would move them to a better credit tier. About one in 250 saw a score change of more than 100 points once the error was fixed.

Complaint volumes tell the same story from the other end. The Consumer Financial Protection Bureau’s Consumer Response Annual Report of 31 March 2026 records about 6.6 million complaints in calendar year 2025, more than double the roughly 3.2 million of 2024; its December 2025 report on credit and consumer reporting complaints records that of more than 5.6 million complaints received between 1 January 2024 and 30 June 2025, almost 4.8 million concerned credit or consumer reporting. Credit reporting is not one complaint category among many. It is most of the complaint volume of a national financial regulator.

Two cases fix the mechanism in place.

The first is Miller v. Equifax Information Services LLC, case number 3:11-cv-01231 in the United States District Court for the District of Oregon. Julie Miller was refused credit in 2009 on the strength of an Equifax report containing another person’s derogatory accounts, along with a wrong Social Security number and a wrong date of birth. She disputed eight times between 2010 and 2011. Experian removed the information; Equifax did not. She sued in October 2011. On 29 July 2013 a jury awarded her 180,000 dollars in compensatory damages and 18.4 million dollars in punitive damages. On 20 May 2014 the court reduced the punitive award to 1.62 million dollars, holding that a nine-to-one ratio to compensatory damages was the constitutional maximum on that record. From first harm to final judgment: about five years, for a consumer who did everything the statute asks of her before going to court.

The second is TransUnion LLC v. Ramirez, 594 U.S. 413, decided 25 June 2021 by five votes to four, Justice Kavanaugh writing. TransUnion sold an add-on product, OFAC Name Screen Alert, comparing a consumer’s first and last name against the United States Treasury Office of Foreign Assets Control list of specially designated nationals — names only, no date of birth, no middle name, no other identifier. On 27 February 2011 Sergio Ramirez was refused a car at a dealership in Dublin, California, because the report said he was a potential terrorist; his wife bought the car instead. The class contained 8,185 people whose files carried the alert, of whom only 1,853 had a report actually sent to a third party in the relevant period. The Court held that only those 1,853 had the concrete harm needed for standing; the other 6,332 had a false statement sitting in a file about them and no federal case.

That holding is the cleanest statement in law of the asymmetry this chapter is about. A wrong record that has not yet been read is, to the system, nothing at all.

Here is what the matching decision actually looks like, stripped to its bones.

incoming tradeline
  name  : "A RAO"
  dob   : 1979-03-04
  ssn   : ***-**-4417
  addr  : 118 CANAL ST, APT 2

candidate file A            candidate file B
  ANITA RAO                   ANITA M RAO
  1979-03-04                  1979-04-03
  ***-**-4417                 ***-**-4471
  118 CANAL ST                118 CANAL ST APT 2

score A = 0.91   score B = 0.88
threshold to append = 0.85

both exceed the threshold; the rule
"append to highest score" writes the
tradeline to file A, which is wrong.

Nothing in that block is exotic. A transposed pair of digits in the identity number, a day and month that swap under two date formats, and a shared building. The two candidates are separated by a hair, and the rule picks one.

The overlay and the duplicate in a master patient index#

A hospital keeps a master patient index: the register that assigns each patient one enterprise identifier and links every encounter, order and result to it. Its failure modes are measured better than almost any other identity system’s, because when this register is wrong people are injured, and injuries get reported.

The measured duplicate rate is high. Industry estimates place the average rate of duplicate records in a healthcare organization’s electronic health record at 8 to 12 per cent; a RAND Corporation analysis cited in the health information management literature puts the United States average at 8 per cent and at 15 to 16 per cent in large systems. A study at Children’s Medical Center Dallas found that duplicates cost about 96 dollars each, that clinical care was negatively affected in 4 per cent of confirmed duplicate cases, and that repeated tests or treatment delays added about 1,100 dollars to the cost of care.

The best data on why duplicates happen comes from Beth Haenke Just, David Marc, Megan Munns and Ryan Sandefer, “Why Patient Matching Is a Challenge: Research on Master Patient Index (MPI) Data Discrepancies in Key Identifying Fields”, published in Perspectives in Health Information Management, volume 13, Spring 2016. They took a multisite data set of 398,939 confirmed duplicate pairs and asked which fields disagreed.

Field Discrepant in pairs
Middle name 58.1 per cent
Social Security number 53.4 per cent
Last name 23.7 per cent
First name 22.6 per cent
Date of birth 6.2 per cent
Sex 6.0 per cent

Read the detail underneath, because that is where the design lessons are. Of the middle name discrepancies, 62.0 per cent were a blank in one record and 20.3 per cent an initial against a full name. Of the Social Security number discrepancies, 58.2 per cent were a blank and 50.2 per cent a default filler value such as 111-11-1111 or 123-45-6789. Of the date of birth discrepancies, 48.3 per cent had a day that did not match, 40.0 per cent a year, 22.1 per cent a month, and 2.6 per cent had month and day swapped. First and last name were swapped in 7.8 per cent of first-name discrepancies. Only 4.99 per cent of the 398,939 pairs agreed on all six key fields.

That last figure is the one to remember. Ninety-five per cent of duplicate pairs differ somewhere in the identifying data, so exact matching cannot find them, so a probabilistic method is compulsory, so false matches are compulsory too. Chapter 8 covers the linkage mathematics; what belongs here is the consequence.

For the consequence, the primary source is ECRI, whose Patient Safety Organization published a 2016 deep-dive analysis of 7,613 wrong-patient events voluntarily reported by 181 healthcare organizations between January 2013 and mid-2015. Nine per cent led to temporary or permanent harm, and two deaths were recorded. Seventy-two per cent occurred during patient encounters and a further 12 per cent during intake; 36 per cent involved diagnostic procedures such as imaging and laboratory tests, and 22 per cent treatment.

The United Kingdom has an equally sharp measurement in transfusion medicine. The Serious Hazards of Transfusion scheme has collected data since 1996; its 2024 report records 899 “wrong blood in tube” near misses, 63.8 per cent of all near misses that year, down from 986 in 2023 after three years of increases. The leading causes were failure to identify the patient correctly when taking blood, 367 cases or 40.8 per cent, and labelling the sample away from the patient, 280 cases or 31.1 per cent, with both together in 169 cases. Of the 448 cases where the blood group was known, 184 — 41.1 per cent — could have produced an ABO-incompatible transfusion. And 757 of the 899, 84.2 per cent, were caught in the laboratory rather than at the bedside.

That last number is the whole argument for defence in depth. The bedside identity check failed 899 times; an independent downstream check, comparing the sample’s blood group against the patient’s historical group, caught 84 per cent of them. That second check is the only reason those were near misses rather than deaths.

The standard control is the two-identifier rule. Joint Commission National Patient Safety Goal NPSG.01.01.01 requires organizations to “use at least two patient identifiers when providing care, treatment, and services”, and its element of performance specifies their use when administering medications, blood or blood components, collecting samples for testing, and providing treatments or procedures. This is a standard in the strict sense: written down, audited, tied to accreditation. As of January 2026 the Joint Commission has begun reorganizing that chapter into what it calls National Performance Goals, while the two-identifier requirement continues to appear in its January 2026 materials for programmes including nursing care centres and home care. [UNVERIFIED: exactly which Joint Commission accreditation programmes moved from National Patient Safety Goals to National Performance Goals on 1 January 2026]

One structural fact explains much of the United States position. Section 510 of the annual Labor, Health and Human Services appropriations legislation has for many years prohibited the federal government from spending funds to promulgate or adopt a unique individual health identifier. The Patient ID Now coalition, whose members include the American Health Information Management Association and the American Medical Informatics Association, wrote to appropriators on 3 April 2026 urging repeal of section 510 from the fiscal year 2027 bill, having made the same request for fiscal year 2026 on 2 May 2025. As of August 2026 the prohibition remains, so American hospitals must match patients probabilistically on names and dates of birth as a matter of law rather than of engineering choice.

Death by database#

Chapter 9 sets out how a death travels between registers. What concerns us here is the living person the record lands on.

The United States mechanism is the clearest documented example. The Social Security Administration maintains the Numident, a record for every person issued a Social Security number, and annotates it with death information from state vital records offices, funeral homes, family members, financial institutions and other federal agencies. A subset is extracted into the Death Master File and distributed onward. In testimony GAO-13-574T of 8 May 2013 the Government Accountability Office noted that the full death file held roughly 98 million records against about 87 million in the public version; its follow-up report GAO-14-46, issued 27 November 2013, found that the agency verified reports from less reliable sources only for current beneficiaries, and verified no reports at all for non-beneficiaries.

The agency’s own figures give the rate.

Year Erroneous deaths corrected Source
2011 11,800 SSA 2019 fact sheet
2012 8,900 SSA 2019 fact sheet
2013 9,100 SSA 2019 fact sheet
2014 7,700 SSA 2019 fact sheet
2015 7,300 SSA 2019 fact sheet
2016 10,431 SSA 2019 fact sheet
2017 8,217 SSA 2019 fact sheet
2025 12,504 SSA OIG report 032311

The 2019 fact sheet, Social Security and the Death Master File, states that the agency receives approximately 2.9 million death reports a year and corrects about one-third of one per cent of them. The 2026 audit gives the current picture: about 5.6 million death records posted in calendar year 2025, of which 12,504, or 0.22 per cent, were later determined erroneous.

That audit — report 032311, dated 24 June 2026 and announced on 2 July 2026 — is worth reading closely, because it measures the correction rather than the error. The Office of the Inspector General drew a random sample of 175 beneficiaries from a population of 24,219 recorded as dead between January 2020 and December 2024 and later corrected. The agency followed its own policies in 95 of the 175 cases, 54 per cent; in 78 cases, 45 per cent, technicians did not record why the death had been posted or why it had been removed; and in two cases the payment record was not updated at all. The important conclusion: because the reasons are not recorded, the agency cannot identify trends or root causes, and cannot prevent recurrence.

That is a general law of identity errors, and it deserves its own line. A correction that does not record its own cause converts a systemic defect into an endless supply of individual accidents.

The propagation problem is best seen drawn out.

  death report (state, funeral home,
  relative, bank, other agency)
        |
        v
  [ Numident record annotated ]
        |
        +--> Death Master File extract
        |         |
        |         +--> other federal agencies
        |         +--> states and pensions
        |         +--> banks and insurers
        |         +--> data brokers and screening
        |
        +--> benefit payment stopped

  correction path (person must walk it):
    prove identity in person  ->
    Numident annotation removed ->
    next DMF extract ->
    each recipient re-imports ->
    each recipient un-freezes

  the arrows going down are automatic.
  the arrows coming back are manual, and
  the last two are nobody's job.

One contested episode is worth recording precisely, because it shows that a death record can be a policy instrument as well as an accident. In April 2025 the New York Times reported that the Social Security Administration had entered about 6,300 living non-citizens into the Death Master File as an immigration enforcement measure; a Freedom of Information Act response dated 17 July 2025 stated that in early June 2025 the agency updated its records so that this population would no longer appear as deceased. In June 2026 a former senior agency executive disclosed to Congress that a plan had been discussed to extend the practice to about 2.7 million people, and the Commissioner of Social Security, Frank Bisignano, publicly denied that living people had knowingly been added to the file. Readers should treat the disputed part as disputed. What is not disputed is the mechanism: writing a death into a national identity register is a fast, cheap, one-way action with very large downstream effects, and nothing technical distinguishes an error from a decision.

Watchlists, and the arithmetic of rare things#

A watchlist system is a screening test, and every screening test obeys the same arithmetic. The quantity that matters to the person stopped is the positive predictive value: given that the system raised an alert, what is the probability that the alert is correct.

PPV = (p * TPR)
      -----------------------------------
      (p * TPR) + ((1 - p) * FPR)

p    = share of people screened who really
       are on the list  (the base rate)
TPR  = share of listed people alerted on
FPR  = share of unlisted people alerted on

Work it with numbers. Take a deployment where one person in 100,000 passing the camera is genuinely on the list, so p = 0.00001; a system that alerts on 90 per cent of listed people, TPR = 0.9; and a wrong alert on one unlisted person in 10,000, FPR = 0.0001.

Per one million screened: 10 are listed and the system alerts on 9 of them; the other 999,990 are not listed and it alerts on about 100. Total alerts 109, of which 9 are right, so the positive predictive value is 8.3 per cent. More than nine alerts in ten are wrong, from a system that finds nine wanted people in ten and is wrong about only one unlisted person in ten thousand.

Now improve the false alert rate from 1 in 10,000 to 3 in 1,000,000 and change nothing else. Per million screened: 9 true alerts, 3 false alerts, PPV = 75 per cent. A thirty-three-fold improvement moved the predictive value from 8 per cent to 75. Arguing about accuracy in the abstract is useless; arguing about the specific false alert rate and the specific base rate is the only conversation worth having.

Two real deployments show both ends of the range.

Deployment Alerts False alerts
South Wales, June 2017 2,470 2,297
Met LFR, Sep 24 to Sep 25 see note 10

South Wales Police deployed automated facial recognition around the UEFA Champions League final held in Cardiff in June 2017; by the force’s own published figures the system produced 2,470 alerts of which 2,297 were false, a rate the force reported as 92 per cent. The Metropolitan Police published a report on 31 October 2025 covering deployments between September 2024 and September 2025: 962 people arrested, more than three million faces scanned, ten people falsely alerted on of whom eight were black, no arrest following a false alert, and a stated false alert rate of 0.0003 per cent of faces scanned. Big Brother Watch, which is bringing a legal challenge alongside Shaun Thompson, wrongly identified by a camera in February 2024, responded that 80 per cent of those wrongly flagged were black. The force said the imbalance rested on a very small sample and was not statistically significant.

Both sets of figures are true and they are not comparable, and understanding why is the entire lesson. The South Wales number is a proportion of alerts. The Metropolitan Police number is a proportion of faces scanned. A system can have a superb false alert rate per face and a dreadful proportion of wrong alerts, or the reverse, depending entirely on how many wanted people are actually walking past. Any published accuracy figure for a screening system that does not state its denominator is not an accuracy figure.

The base rate also explains why the same technology behaves so differently from one deployment to another. A van parked where wanted people are expected has a base rate thousands of times higher than a camera scanning a commuter station at random. Targeting is not a detail of deployment; it is the dominant term in the equation. And name-based screening is worse than face-based screening on exactly this axis, because names are shared: matching a first and last name against a sanctions list, with no other identifier, across a population of hundreds of millions is a test whose predictive value is not low but negligible.

Nomination, and the case of Rahinah Ibrahim#

Screening arithmetic assumes the list is right. Often the error is in the list.

Rahinah Ibrahim, a Malaysian doctoral candidate at Stanford University, was placed on the United States No Fly List in 2004 because a Federal Bureau of Investigation agent completed the nomination form incorrectly: the form of the day required boxes to be ticked to indicate the databases in which a person should not be listed, and the agent did the opposite of what he intended. In 2005 she was handcuffed and prevented from flying; her visa was later revoked. She sued in 2006, and the case was tried before Judge William Alsup of the United States District Court for the Northern District of California in December 2013, and on 14 January 2014 the judge issued a public summary finding that a plaintiff who shows wrongful listing and consequent government action is entitled by due process to a remedy requiring the government to cleanse and correct its lists. The government declined to appeal in March 2014. From the tick of a box to the correction of the record: roughly ten years, of which about eight were litigation and two appeals to the Ninth Circuit.

Two features generalize. First, the error was a single data entry action taken in seconds, and it survived nine years of process designed to catch exactly that. Second, the person could not discover the error, because the government’s policy was — and as a general matter remains — not to confirm or deny a person’s watchlist status in response to a traveller complaint. A correction process that will not tell you what you are trying to correct is not a correction process.

The list’s size is not published precisely; it has been described in litigation and press reporting as containing more than a million known or suspected terrorists, with the No Fly List a small subset. In Elhady v. Kable the Eastern District of Virginia held on 4 September 2019 that the watchlisting system violated due process; the Fourth Circuit reversed on 30 March 2021, holding that the practice fell within the executive’s authority to regulate travel and control the border.

The redress channel is the Department of Homeland Security Traveler Redress Inquiry Program, and the Government Accountability Office measured it in report GAO-25-108349, Terrorist Watchlist: Nomination and Redress Processes for U.S. Persons, published 14 August 2025. From 7 December 2021 through 30 September 2023 the programme received about 20,000 redress inquiries. Of those, 289 — 1.5 per cent — were related to the terrorist watchlist. Their outcomes were: 171 with no change to status, 88 where the individual was removed, 21 where a misidentification was corrected, and 9 where the status was downgraded. The GAO recommended, among other things, that timeframes be established, which tells you that at the time of publication there were none.

Outcome Cases Share
No status change 171 59 per cent
Removed from list 88 31 per cent
Misidentification fixed 21 7 per cent
Status downgraded 9 3 per cent

Read the table twice. Forty-one per cent of watchlist-related redress inquiries resulted in some change to the record. That is not the profile of a system whose errors are rare.

Criminal records: the burden that never shifts#

An identity error in a criminal record produces the most immediate physical consequence available in this chapter, which is that a person is locked up.

The governing American case is Baker v. McCollan, 443 U.S. 137, decided 26 June 1979 by six votes to three, Justice Rehnquist writing. Leonard McCollan obtained a duplicate of his brother Linnie’s driving licence, identical in every respect except that it carried Leonard’s photograph. Leonard was arrested on drug charges in October 1972 while impersonating his brother; when he failed to appear, a warrant issued in Linnie’s name. On 26 December 1972 Linnie was stopped for a traffic offence in Dallas, arrested on the warrant despite his protests, transferred to jail in Amarillo on 30 December, and released on 2 January 1973 when officials compared him to a photograph on file. The Court held that detention under a facially valid warrant did not violate due process, and that three days was not long enough to make it one.

Forty-four years later David Sosa was stopped in Martin County, Florida, in 2014 and held for three hours on a Texas warrant issued more than two decades earlier for a different David Sosa, then stopped again in 2018 on the same warrant and held in the county jail for three days over a weekend. He had a different date of birth, a different height and none of the tattoos in the warrant. The Eleventh Circuit, sitting en banc, held in Sosa v. Martin County, 57 F.4th 1297 (11th Cir. 2023), that under Baker he had no cognizable constitutional claim; the Supreme Court denied certiorari on 2 October 2023.

The rule from those two cases is the legal expression of this whole chapter: in the United States, if the paperwork is valid on its face, the fact that it names somebody else is, for a period measured in days, your problem and not the state’s.

The United Kingdom’s criminal record system has a formal dispute route, better in one respect and worse in another. A person who believes their Disclosure and Barring Service certificate is wrong must report the mistake within three months of the date on it. Where the disputed material is police information and the police disagree, the matter goes to the Independent Monitor at the Home Office, whose decision binds; where the dispute is about identity, the police may ask for fingerprints. The good part is a named external decision maker. The bad part is the three-month clock: an error that surfaces at the wrong moment simply expires.

The newest layer is biometric. As of the American Civil Liberties Union’s account published on 14 April 2026, fourteen people in the United States are publicly known to have been wrongfully arrested because police relied on a face recognition match. The best documented is Robert Williams, arrested outside his home in Farmington Hills, Michigan, in January 2020 after Michigan State Police ran a poor quality still from a 2018 shop theft through a face recognition system and it returned his old driving licence photograph. He was held for about thirty hours, and filed suit on 13 April 2021. The case settled on 28 June 2024, with Detroit City Council having approved a payment of 300,000 dollars in May 2024 and the department agreeing to policies enforceable in federal court for four years: no arrest may rest on a face recognition result alone, such a result may not lead directly to a photographic line-up, independent evidence must corroborate the lead, officers must be trained on the technology’s error characteristics including its higher error rates for people of colour, and cases from 2017 onward in which face recognition supported an arrest warrant must be audited.

That settlement is, as of August 2026, the most complete published answer in this book to the question “what should the fix look like”, and it is worth noticing what it fixes. It does not make the matching more accurate. It changes what an organization is permitted to do with an uncertain match. That is almost always the higher-leverage intervention.

Denial of service by identity#

The most common identity harm is not being confused with somebody else. It is being unable to prove you are yourself, and losing everything that depends on it.

The defining case is the Windrush scandal in the United Kingdom. From 1948 onward, Commonwealth citizens travelled to Britain as British subjects; the Empire Windrush, which docked in June 1948, gave the cohort its name. The Immigration Act 1971 granted indefinite leave to remain to Commonwealth citizens already settled in the United Kingdom. It granted it automatically, which meant it granted it without issuing anybody a document. The Migration Observatory at Oxford estimated around 500,000 United Kingdom residents born in a Commonwealth country who arrived before 1971.

For forty years that mattered to nobody. Then a series of measures from 2012 onward required landlords, employers, banks and the health service to check immigration status before providing a service, which converted the absence of a document from a triviality into a disqualification. The Home Office had destroyed thousands of landing card slips in 2010, removing one of the few records that could have evidenced arrival dates.

The Joint Committee on Human Rights examined two cases and published its findings on 29 June 2018 in its Sixth Report of Session 2017-19, Windrush generation detention, HC 1034 and HL Paper 160. Anthony Bryan, then 60, and Paulette Wilson, then 62, had both come from Jamaica as children in the 1960s; both had the right to remain indefinitely; neither had a document proving it. Mr Bryan was held in an immigration detention centre twice, for almost three weeks in total; Ms Wilson was detained for a week. The committee found that the Home Office had dismissed ample evidence, including their own accounts, testimony from family and from people who had known them for decades, and submissions from lawyers.

The committee’s central finding is the sentence to carry out of this chapter: “It is for the Home Office to satisfy itself that it has a power to detain an individual — not for an individual to have to satisfy the Home Office that they should not be detained.” It further found that the department had required standards of proof that went beyond its own guidance and were impossible to meet, and that officials had then treated failure to meet those standards as grounds to detain.

Wendy Williams’ independent Windrush Lessons Learned Review, laid before Parliament on 19 March 2020, made 30 recommendations. The Home Office published its Comprehensive Improvement Plan on 30 September 2020, and Ms Williams returned on 29 September 2021 to assess progress against them.

The compensation scheme, established in 2019, is where the redress lesson lives. The National Audit Office’s report on the government’s compensation and financial recognition schemes, published 17 April 2026, recorded 11,475 claims received by January 2026. Of 9,224 concluded claims, 3,148 — about a third — resulted in a payment and 5,203 — 56 per cent — in a nil award, the remainder ineligible or withdrawn; the average successful payment was 32,100 pounds. The report noted accounts of cases initially refused being reconsidered and compensated when solicitors filed the same cases. The Reverend Clive Foster, appointed Windrush Commissioner in June 2025, said the high rate of nil awards retraumatizes claimants and undermines trust, and that he intended to review a sample of nil award decisions.

Windrush scheme, to Jan 2026 Count
Claims received 11,475
Claims concluded 9,224
Concluded with a payment 3,148
Concluded with nil award 5,203

Seven years after a scheme was created to remedy an identity failure, more claims had been concluded with nothing than with something. That is not an argument against redress schemes. It measures how hard redress is once the evidence a person needs has been destroyed, and reminds us that a compensation scheme sits downstream of an evidentiary problem it cannot solve.

The Indian experience adds a second mechanism: exclusion not by a wrong record but by failed recognition. The State of Aadhaar 2019 report, produced by Dalberg with support from Omidyar Network, found that 0.8 per cent of respondents had been excluded from at least one welfare service for Aadhaar-related reasons, and that 1.5 per cent of public distribution system users had experienced a biometric authentication failure and did not receive their rations on their most recent attempt. Siddharth Singh and Ashwini Chhatre at the Indian School of Business examined the Andhra Pradesh public distribution system over 1 to 16 December 2017: of about 3.77 million ration cards on which authentication was attempted, 94,030 failed, an average rate of 2.5 per cent with district rates up to 5.2 per cent, about 92 per cent of failures caused by biometric mismatch.

A false non-match is an identity error even though no record is wrong, and its victims are systematically the people whose fingerprints are worn by manual labour, which is to say the people the scheme exists to serve. Any authentication system without a workable exception path converts its own error rate directly into denial of the service. The exception path is part of the system, not a concession to it.

What a good correction process looks like#

Gather everything above and a specification falls out. A redress process is adequate when it has all eight of these properties. Almost every real one fails on at least three.

  1. Notice. The person is told that a decision was made about them, which system made it, and on what data. A system that will not confirm what it holds cannot be corrected.
  2. A named route. One published channel, one identifier for the case, one named function accountable for it. Not a general complaints address.
  3. A clock with a deadline in law. A duty to answer within a stated period, with the consequence of missing it specified.
  4. The burden on the holder of the record. The organization must satisfy itself that the record is right; the person is not required to prove a negative. This is the Joint Committee’s sentence, generalized.
  5. Interim relief. While the dispute is open, the disputed item is suppressed or the service is restored. Otherwise the correction arrives after the harm has finished happening.
  6. Propagation. Everyone who received the wrong data is told, by the organization, not by the person.
  7. Cause recorded. Why the error was made and why it was removed, in a form that can be counted. Without this there is no learning, which is exactly what the Social Security audit found.
  8. Recurrence prevention. A durable block that stops the same wrong data being re-imported from the same upstream source next month.

Measured against those eight, here is how four real processes score.

Process Deadline to answer Burden sits with
FCRA dispute, US 30 days The agency
GDPR rectification One month The controller
DBS dispute, UK Not published Police and DBS
DHS TRIP, US None established The traveller

The Fair Credit Reporting Act is the strongest of the four on paper. 15 U.S.C. 1681i requires a reasonable reinvestigation within 30 days of a dispute, extendable by 15 days if the consumer supplies further relevant information; requires information found inaccurate, incomplete or unverifiable to be promptly deleted or modified and the furnisher notified; requires written results to the consumer within five business days; and, in subsection (d), requires the agency to notify, at the consumer’s request, persons who received the report in the preceding six months, or two years for employment purposes. That last provision is property six, propagation, written into statute, and it is rare.

The gap between statute and practice is measurable. The Consumer Financial Protection Bureau’s December 2025 report records average response times of around 40 days for TransUnion, around 40 to 50 days for Equifax, and close to the full 60-day limit for Experian since early 2023, with all three exceeding 50 days on average in recent months. A statutory deadline of 30 days is being met, in practice, in something closer to 50.

The European position is stated more generally and covers everything. Article 5(1)(d) of the General Data Protection Regulation makes accuracy a principle and requires inaccurate personal data to be erased or rectified without delay. Article 16 gives the data subject the right to obtain rectification of inaccurate data and completion of incomplete data. Article 19 requires the controller to communicate any rectification or erasure to each recipient to whom the data have been disclosed, unless that proves impossible or involves disproportionate effort, and to inform the data subject who those recipients were on request. Article 12(3) sets the response period at one month, extendable by two further months for complex requests.

Article 19 is the most under-used provision in European data protection law. It is property six as a general duty rather than a sectoral one, and it is the legal hook for the sentence a person in Anita Rao’s position most needs: not only correct your copy, but tell everyone you gave the wrong copy to, and tell me who they were.

Measuring redress with four numbers#

If you run a system that holds identity records, these are the four numbers to put on the wall. None of them is the error rate.

{
  "case_id": "RDR-2026-014882",
  "opened": "2026-04-02T09:14:00Z",
  "first_substantive_reply": "2026-04-09",
  "record_corrected": "2026-06-18",
  "downstream_notified": 6,
  "downstream_total_known": 9,
  "downstream_unknown": true,
  "interim_suppression_applied": true,
  "cause_code": "MATCH_FALSE_LINK_DOB_FORMAT",
  "upstream_source": "FURNISHER_4471",
  "block_rule_installed": true,
  "recurrence_within_12m": false
}

The four numbers that record derives are: time to first substantive reply, from first contact to the first response engaging with the facts rather than acknowledging receipt; time to correction, from first contact to the master record being right; propagation completeness, the proportion of known recipients of the wrong data who have been told, flagged explicitly when the denominator is unknown; and recurrence rate, the proportion of corrections undone within twelve months by the same source re-supplying the same wrong data.

The fourth is the one nobody measures and the one people complain about most. A credit file corrected in June is re-polluted in August because the furnisher still holds the wrong link. A hospital index unmerged in one system is re-merged by the nightly feed from another. Unless the correction installs a durable rule at the point of entry, it is not a correction; it is a pause.

correction without a block:

  upstream --> [ fix ] --> record right
     |                        ^
     |    next monthly feed   |
     +------------------------+   wrong again


correction with a block:

  upstream --> [ block rule: do not link
                 FURNISHER_4471 tradelines
                 to file 8842 without a
                 full identifier match ]
                        |
                        v
                  record stays right

Anita Rao, end to end#

Now the worked example with real mechanics attached. The dates are constructed; every step maps onto a documented process named above.

Date Event
12 Jan Hospital indexes overlay
04 Feb Loan refused, mixed file
09 Mar Benefit stopped, death flag
02 Apr Three disputes opened
09 Apr Bureau acknowledges only
21 Apr Alive in person at office
07 May Benefit restored, no backpay
18 Jun Credit file corrected
11 Aug Same judgment reappears
03 Sep Second dispute opened
19 Nov Block rule installed
27 Nov Hospital records unmerged

Read down the right-hand column and count the properties that were absent. She was given notice of none of the three errors; she discovered each by being refused something. Interim relief existed nowhere: the loan was not held open, the benefit was not paid pending review, and the merged medical record was read by clinicians for ten more months. Propagation happened for none of them; the insurer and two clinics that copied the merged record in February were never told. The cause was recorded in one system of three. And the credit correction failed property eight and had to be done twice.

Total elapsed time from first harm to a stable correct state: about ten and a half months. Total staff time spent by the organizations involved, generously counted: a few hours. When the cost of an error falls almost entirely on somebody who cannot influence the design, the design will not improve, because nothing in the organization’s own instrumentation ever turns red.

Two design rules that move the cost#

First: make the record’s uncertainty visible to whoever acts on it. A clinician reading a chart merged from two sources should see that at the top; a lender reading a file where two of six identifiers matched should be told the match was partial. Most systems collapse a probabilistic decision into a certain-looking display, and that collapse is where the harm is manufactured. The Detroit settlement’s core provision — a face recognition result is a lead and never a ground for arrest — is this rule applied to policing.

Second: make the error cost the operator something measurable. Statutory deadlines, damages, published redress statistics and mandatory root-cause coding all convert an invisible external cost into a visible internal one. Neither makes matching more accurate. Both make being wrong expensive, which is the only thing that reliably makes organizations careful.

11.98 Common wrong ideas#

Wrong: Identity errors are rare freak events. Right: They are the normal output of correctly functioning systems; the Social Security Administration’s own audit found 12,504 erroneous death postings in calendar year 2025 out of about 5.6 million, a rate of 0.22 per cent that is good engineering and twelve thousand personal emergencies at once.

Wrong: If a screening system is 99 per cent accurate, a flag means you are probably guilty. Right: When the thing screened for is rare, most flags are wrong; with one listed person in 100,000 and a false alert rate of one in 10,000, nine alerts in ten are wrong even though the system finds nine listed people out of ten.

Wrong: The worst identity error is having somebody else’s data added to your record. Right: The mirror error — your history split across two records so each looks sparse — is at least as dangerous and much harder to detect, because an incomplete record is indistinguishable from a record for somebody with an uneventful past.

Wrong: Once the master record is corrected, the problem is solved. Right: Correction and propagation are different acts with different owners; copies taken while the record was wrong stay wrong until their holders are told, which is why article 19 of the General Data Protection Regulation and 15 U.S.C. 1681i(d) both create a duty to notify prior recipients.

Wrong: A person wrongly recorded as dead simply shows up and proves otherwise. Right: The record removes the means of proving anything — the account is frozen, the benefit has stopped, the card does not work — so the evidence needed to fix the error sits downstream of the error, which is why these cases take months.

Wrong: If a record is wrong, the burden is on the organization to put it right. Right: In practice the burden silently inverts and the person is asked to prove a negative; the Joint Committee on Human Rights had to state the correct rule explicitly in June 2018, that it is for the Home Office to satisfy itself it has a power to detain and not for the individual to satisfy it otherwise.

Wrong: A compensation scheme fixes the harm. Right: Money arrives long after the harm and only for provable losses; of 9,224 concluded Windrush claims to January 2026, 3,148 resulted in a payment and 5,203 in a nil award, which measures how much of an identity harm a compensation scheme’s categories can capture.

Wrong: A biometric check cannot produce an identity error because bodies do not lie. Right: Biometric systems fail in both directions, and their false non-matches fall hardest on people with worn fingerprints; in one Andhra Pradesh study, 94,030 of about 3.77 million ration card authentications failed over sixteen days in December 2017, about 92 per cent from biometric mismatch.

Wrong: The alert is the harm. Right: The alert is a filter; the harm is what is attached to it, which is why the most effective remedy in this chapter — the Detroit settlement of 28 June 2024 — changed not the matching but the rule that no arrest may rest on a face recognition result alone.

11.99 Chapter summary in 20 lines#

  1. An identity system makes exactly two kinds of error: it joins two people into one record, or it splits one person across two.
  2. A wrongly joined record creates false facts and a wrongly split record creates missing facts, and missing facts are harder to notice because absence has no shape.
  3. Health information management inverts the plain words: two people in one record is an overlay, one person in two records is a duplicate, and one person in two indexes is an overlap.
  4. A fourth class has no standard name — a correctly resolved record carrying a false status such as deceased, sanctioned or barred — and it does the fastest damage, because status flags are built to be acted on at once and questioned later.
  5. Mixed credit files arise from partial matching on shared names, shared addresses and truncated identity numbers, and the Federal Trade Commission’s study of 11 February 2013 found one consumer in five with a verified error and five per cent with an error serious enough to change their credit terms.
  6. Julie Miller disputed her Equifax file eight times in 2010 and 2011, sued in October 2011, won 180,000 dollars compensatory and 18.4 million dollars punitive on 29 July 2013, and saw the punitive award cut to 1.62 million dollars on 20 May 2014.
  7. TransUnion LLC v. Ramirez, decided 25 June 2021 by five votes to four, concerned a product matching first and last names only against a sanctions list, and held that of 8,185 class members only the 1,853 whose reports reached third parties had standing.
  8. The duplicate rate in hospital master patient indexes is commonly quoted at 8 to 12 per cent, rising to 15 or 16 per cent in large systems.
  9. Of 398,939 confirmed duplicate pairs studied in Perspectives in Health Information Management in Spring 2016, middle name disagreed in 58.1 per cent and Social Security number in 53.4 per cent, and only 4.99 per cent agreed on all six key fields.
  10. ECRI’s Patient Safety Organization analysed 7,613 wrong-patient events from 181 organizations reported from January 2013 and found nine per cent caused temporary or permanent harm, with two deaths.
  11. The 2024 Serious Hazards of Transfusion report recorded 899 wrong blood in tube near misses, 40.8 per cent from failure to identify the patient at phlebotomy, and 84.2 per cent caught by an independent laboratory check rather than at the bedside.
  12. The Social Security Administration posted about 5.6 million death records in calendar year 2025 and later found 12,504 of them, 0.22 per cent, to be erroneous.
  13. Audit report 032311 of 24 June 2026 found that in 45 per cent of corrected death records the agency did not document why the death was posted or removed, so it cannot find root causes and cannot prevent recurrence.
  14. A person wrongly recorded as dead must prove they are alive to each downstream system in turn, without the account, benefit or card the record has already taken away.
  15. Positive predictive value is governed by the base rate: with one listed person in 100,000, a 90 per cent detection rate and a false alert rate of one in 10,000, only 8.3 per cent of alerts are right.
  16. Accuracy figures are incomparable unless the denominator is stated: South Wales Police reported 2,297 false alerts out of 2,470 at the 2017 Champions League final, while the Metropolitan Police reported ten false alerts against more than three million faces scanned from September 2024 to September 2025.
  17. Rahinah Ibrahim was watchlisted in 2004 because an agent completed a nomination form backwards, was stopped in 2005, sued in 2006, and obtained a ruling on 14 January 2014 requiring the government to cleanse its lists.
  18. Report GAO-25-108349 of 14 August 2025 found that of about 20,000 redress inquiries between December 2021 and September 2023, 289 concerned the watchlist and 41 per cent of those produced a change.
  19. The Joint Committee on Human Rights found on 29 June 2018 that it is for the Home Office to satisfy itself that it has a power to detain, not for the individual to satisfy it otherwise, which is the correct allocation of burden for every dispute in this chapter.
  20. A correction process is adequate only with all eight properties — notice, a named route, a legal deadline, the burden on the record holder, interim relief, propagation, a recorded cause and a durable block — measured by time to first reply, time to correction, propagation completeness and recurrence rate.

Chapter sources: the United States Social Security Administration Office of the Inspector General audit report Beneficiaries Incorrectly Recorded as Deceased, report 032311, dated 24 June 2026 and announced 2 July 2026; the Social Security Administration fact sheet Social Security and the Death Master File, June 2019, for the annual report volume and the correction counts for 2011 to 2017; Government Accountability Office testimony GAO-13-574T of 8 May 2013 and report GAO-14-46, Social Security Death Data: Additional Action Needed to Address Data Errors and Federal Agency Access, 27 November 2013; New York Times reporting of April 2025 and a Freedom of Information Act response of 17 July 2025 on non-citizens entered into and removed from the Death Master File, with the June 2026 congressional disclosure and the Commissioner of Social Security’s denial; the Windrush Lessons Learned Review by Wendy Williams, laid before Parliament on 19 March 2020 with 30 recommendations, the Home Office Comprehensive Improvement Plan of 30 September 2020, and Ms Williams’ return on 29 September 2021; the Joint Committee on Human Rights Sixth Report of Session 2017-19, Windrush generation detention, HC 1034 and HL Paper 160, 29 June 2018; the National Audit Office report on the government’s compensation and financial recognition schemes, 17 April 2026; the Immigration Act 1971 and the Migration Observatory estimate of pre-1971 Commonwealth arrivals; ECRI’s Patient Safety Organization deep-dive analysis of patient identification, 2016; Beth Haenke Just, David Marc, Megan Munns and Ryan Sandefer, Why Patient Matching Is a Challenge: Research on Master Patient Index (MPI) Data Discrepancies in Key Identifying Fields, Perspectives in Health Information Management, volume 13, Spring 2016, with the RAND Corporation duplicate rate estimates and the Children’s Medical Center Dallas cost study cited in its introduction; the Serious Hazards of Transfusion annual report for 2024, chapter on near miss wrong blood in tube; Joint Commission National Patient Safety Goal NPSG.01.01.01 and its element of performance 1, effective January 2025 and January 2026; Patient ID Now coalition letters to appropriators of 2 May 2025 and 3 April 2026 on section 510 of the Labor, Health and Human Services appropriations bill; the Federal Trade Commission press release of 11 February 2013 reporting the study mandated by section 319 of the Fair and Accurate Credit Transactions Act of 2003; Miller v. Equifax Information Services LLC, 3:11-cv-01231, District of Oregon, verdict of 29 July 2013 and opinion of 20 May 2014; TransUnion LLC v. Ramirez, 594 U.S. 413, decided 25 June 2021, five to four, Kavanaugh J.; the Consumer Financial Protection Bureau Annual Report of Credit and Consumer Reporting Complaints, December 2025, and Consumer Response Annual Report, 31 March 2026; 15 U.S.C. 1681i, subsections (a)(1)(A), (a)(5)(A), (a)(6) and (d); Regulation (EU) 2016/679, articles 5(1)(d), 12(3), 16 and 19; Baker v. McCollan, 443 U.S. 137, decided 26 June 1979, six to three, Rehnquist J.; Sosa v. Martin County, 57 F.4th 1297 (11th Cir. 2023) (en banc), certiorari denied 2 October 2023; Elhady v. Kable, Eastern District of Virginia opinion of 4 September 2019 and Fourth Circuit reversal of 30 March 2021; the ruling of Judge William Alsup of 14 January 2014 in Ibrahim v. Department of Homeland Security; Government Accountability Office report GAO-25-108349, Terrorist Watchlist: Nomination and Redress Processes for U.S. Persons, 14 August 2025; South Wales Police published figures for the June 2017 UEFA Champions League final deployment; the Metropolitan Police live facial recognition report of 31 October 2025, with the response of Big Brother Watch and the case of Shaun Thompson; the American Civil Liberties Union account of 14 April 2026 recording fourteen wrongful arrests following reliance on face recognition, and the Williams v. City of Detroit settlement of 28 June 2024; the State of Aadhaar 2019 report produced by Dalberg with support from Omidyar Network; and Siddharth Singh and Ashwini Chhatre, Aadhaar Authentication Failure in the Public Distribution System of Andhra Pradesh, Indian School of Business.