October 01, 2014
According to an audit report released by the USPS Office of Inspector General today security for Change of Address (COA) submissions to USPS, either via hard copy or NCOALink, is insufficient. The OIG report states:
BACKGROUND
More than 40 million Americans change their addresses annually and submit change of address (COA) orders to the U.S. Postal Service. Customers can submit orders electronically through the Internet or submit hard copy orders through the mail or at a Post Office retail counter. The Postal Service provides COA information for a fee through National Change of Address Linkage (NCOALink) to licensees who facilitate relationships with business mailers. NCOALink is an application containing about 160 million COA records. The Postal Service requires licensees and their customers to complete a Processing Acknowledgment Form (acknowledgement form) to comply with the Privacy Act of 1974 and document the companies’ intended use of the data. 
Our objectives were to determine whether security controls over the COA manual process and NCOALink data adequately protect the confidentiality and integrity of customer data and identify potential solutions for improving the Postal Service’s acknowledgement form process.
What The OIG Found
Security controls over the COA manual processes and NCOALink data are not sufficient to protect the confidentiality and integrity of customer information. We visited one of the 22 Computerized Forwarding System sites and found personnel did not adhere to controls related to processing and retaining hard copy COA orders.
We also determined the Postal Service is using outdated software to [word redacted by OIG] data. In addition, NCOALink license agreements did not always have sufficient contract provisions to protect customer data, and management did not always monitor these agreements for licensee compliance.
Read Entire Audit Report (PDF)