Cybersecurity Policy Report, Senate Bill Would Require GAO to ‘Pick Up’ After DOGE With Cybersecurity Audits, (Jul 31, 2025)
Organizations Mentioned:Social Security Administration

Three Senate Democrats have introduced the Pick Up After Your DOGE Act, which would require the Government Accountability Office to look for security vulnerabilities in government computer systems accessed by the White House Department of Government Efficiency (DOGE).
“The DOGE-boys have weaseled their way into Americans’ most sensitive data systems, claiming to hunt ‘waste, fraud, and abuse,’ while actually creating waste, fraud, and abuse,” Sen. Sheldon Whitehouse (D., R.I.), the bill’s sponsor, said in a news release.
“The Pick Up After Your DOGE Act protects seniors and all Americans by fixing any bugs or backdoors that DOGE may have purposefully or negligently created in Social Security, Medicare, and other highly sensitive government data systems,” Sen. Whitehouse said.
“It could take years to undo the damage and hold DOGE officials fully accountable for any violations of federal law,” according to Sen Ron Wyden (D., Ore.), a co-sponsor of the bill. “I’m glad to work with Senator Whitehouse on this bill to jumpstart the massive cleanup effort required to root out the damage DOGE has inflicted and shore up these systems.”
Sen. Elizabeth Warren (D., Mass.) is also a co-sponsor of the bill (S.B. 2533, 119th Cong. (2025)).
“Since the start of the Trump Administration, DOGE employees with little training and few qualifications have gained access to sensitive data and computer systems at numerous federal agencies,” the senators said.
“The DOGE infiltration poses substantial risks to Americans’ data and wellbeing. Vulnerabilities and bugs left behind in these systems could put Americans at risk of getting scammed, hacked, or even spied on by foreign governments,” they added.
The bill would require the head of the U.S. DOGE Service to identify all computer systems accessed by DOGE so that GAO could begin assessing those systems, according to its text.
The GAO audits would prioritize systems at the Social Security Administration, Department of Health and Human Services, Centers for Medicare and Medicaid Services, Treasury, and the Internal Revenue Service. Agencies would have 90 days to fix any vulnerabilities discovered by GAO.
MainStory: TopStory FederalLegislation DataSecurity DataPrivacy DOGE