MNG-008 · START HERE & SYSTEM MAP
Privacy, Records Sharing & Digital Security
Protect military, medical, financial, family, and benefit records while preserving usable evidence and authorized sharing.
Separate preservation from disclosure
Keep the complete record in protected storage. Share only the documents and data reasonably necessary for the transaction. A complete personal archive and a submission packet should not automatically be the same thing.
Third-party access
NARA explains that non-archival OMPF records are subject to privacy restrictions and that authorized third-party requesters generally need signed, dated authorization specifying what may be released. Preserve every authorization and its scope.
Digital-security baseline
- Use multifactor authentication where available.
- Protect recovery codes and recovery email/phone access.
- Do not send SSNs, medical records, identity documents, or financial data through an insecure channel merely because someone requests them.
- Verify the official domain and recipient before uploading sensitive records.
- Encrypt or otherwise protect local backups containing sensitive information.
- Keep a disclosure log for especially sensitive records: what was sent, to whom, when, why, and under what authorization.
Public history is different from personal claims work
Older archival military records can have different access rules from recent federal personnel files. Do not assume that a document suitable for a private claim file is appropriate for public posting. Redact or withhold unnecessary PII and sensitive family, medical, financial, or security information.
Official sources
- NARA — OMPF access for veterans and next of kin
- NARA — FOIA and Privacy Act for military records
- CISA — Phishing-resistant MFA
Source status: SRC-023; SRC-024; SRC-025 Verified October 4, 2026. Recheck the controlling office, form edition, and instructions before a deadline-sensitive filing.