identity protection
The 'In Case Something Happens to Me' Binder — And the Identity Risk Hiding Inside It
Bottom line up front: If you've written down your account numbers, passwords, and Social Security number in a notebook, a document on your computer, or a folder for your spouse or adult child "just in case" — that's smart planning, but it's also one of the most concentrated identity theft risks in your home. The fix isn't to stop making the list. It's to store it properly and add ongoing monitoring so that if the list is ever lost, copied, or found by the wrong person, you find out immediately instead of months later. Aura does the monitoring part — watching your Social Security number, bank accounts, and credit for exactly this kind of exposure — and it lets you add family members to the same protection.
Last updated: 2026-07-04
The Problem Nobody Talks About at Estate Planning Time
If you're like most people over 60, at some point you sat down and made a list. Maybe it was after a health scare. Maybe your spouse asked, "If something happens to me, how would you even find our bank accounts?" Maybe an adult child suggested it during a holiday visit.
Whatever the reason, you probably created some version of an emergency document — sometimes called an "in case of emergency" binder, a "if I die" folder, or just "the list." It usually includes:
- Bank and brokerage account numbers
- Login usernames and passwords for financial and email accounts
- Your Social Security number and Medicare number
- Insurance policy numbers
- The combination to a safe, or the location of a safe deposit box key
- Contact information for your attorney, accountant, and financial advisor
- Sometimes, a full inventory of assets
This is genuinely good planning. Financial advisors and estate attorneys recommend it constantly, because the alternative — a spouse or adult child scrambling to find basic account information during a medical crisis or after a death — is far worse.
But almost nobody thinks about where that document lives after it's created, or what happens if it's ever lost, stolen, or copied. A single piece of paper or one unencrypted file contains everything a stranger would need to open credit in your name, drain a bank account, or file a fraudulent tax return. It's not a scattered risk like most identity theft — it's everything in one place.
Why This Document Is More Dangerous Than People Realize
Think about where these documents typically end up:
A notebook in a kitchen drawer or filing cabinet. Accessible to anyone who enters your home — a contractor, a home health aide, a house cleaner, or a burglar who isn't even looking for it specifically but finds it anyway.
A Word document named "Passwords" or "Important Info" on a home computer. If that computer is ever hacked, sold, donated, or repaired by a technician, the file goes with it — often without you realizing it was ever exposed.
An email sent to an adult child "just so someone has it." Email accounts get compromised more often than people expect, and once it's in an inbox, it's also in that inbox's search history, forwarded threads, and possibly a phone that gets lost.
A photocopy given to multiple family members "to be safe." Every copy is a new point of failure. You can't control what happens to a piece of paper once it leaves your hands.
None of this means you did something wrong by making the list. It means the list needs two things most people never add: a secure storage method, and a way to know if it's ever been exposed.
Step One: Store It Somewhere Actually Secure
You don't need to become a technology expert to fix this. A few changes make a real difference:
- Use a password manager instead of a plain document for logins and account numbers. A password manager encrypts everything behind one master password, so even if a device is lost, the information inside is scrambled and unreadable.
- If you keep a physical copy, put it in a fireproof safe or a bank safe deposit box — not a drawer, folder, or filing cabinet that's accessible to anyone in the house.
- Never email the full document. If you need to share it with a spouse or adult child, use a secure sharing feature built into a password manager, or hand over a sealed physical copy in person.
- Limit how many copies exist. One updated original, stored securely, with clear instructions for a trusted person on where to find it — is safer than five copies scattered across drawers and inboxes.
- Review and update it once a year, and shred old versions completely rather than tossing them in the trash.
These steps reduce the chance that your emergency document ever becomes someone else's opportunity.
Step Two: Assume It Could Still Get Out, and Watch for It
Here's the part most emergency planning advice leaves out: even with careful storage, information gets exposed in ways you don't control. A financial advisor's office gets breached. A hospital's records system is hacked. A family member's phone is stolen with a photo of "the list" still in the camera roll. You can do everything right and still be one data breach away from someone having your Social Security number.
This is where ongoing monitoring matters more than any single storage decision. The goal isn't to make identity theft impossible — nobody can guarantee that. The goal is to make sure that if your information ever surfaces somewhere it shouldn't, you find out in hours or days instead of discovering it six months later when a collections notice arrives for a credit card you never opened.
If your information is ever exposed, know immediately — not months later
Aura monitors your Social Security number, bank accounts, credit reports, and personal information around the clock. If your SSN appears on the dark web, a new account is opened in your name, or your address is changed without your knowledge, Aura sends an immediate alert — plus up to $1 million in identity theft insurance and a U.S.-based restoration team if something does go wrong. You can also add your spouse or adult children to the same plan, so the whole family is watched, not just one account.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
What to Do If You Realize Your Document Has Already Been Exposed
If you're reading this and realizing your emergency binder has been sitting in an unlocked drawer for ten years, or was emailed to three relatives, don't panic — but do act:
- Update your storage immediately using the steps above.
- Check your credit reports at annualcreditreport.com (the only federally authorized free source) for accounts you don't recognize — these are among the warning signs of identity theft worth knowing in advance.
- Consider a credit freeze with all three credit bureaus, which blocks anyone — including you, temporarily — from opening new credit in your name without lifting it first.
- Change passwords for any accounts listed in the document, starting with email and banking, and turn on two-factor authentication while you're there.
- Sign up for identity monitoring so you have an ongoing early-warning system instead of relying on periodically checking manually.
None of this means the sky is falling. Most emergency documents never cause a problem. But treating the exposure as real, rather than assuming it's fine because nothing bad has happened yet, is exactly the mindset that keeps people safe.
What Actually Belongs in the Document (and What Shouldn't Be There at All)
Part of reducing risk is being thoughtful about what you write down in the first place. Not everything needs to be in the emergency document itself — some things are safer referenced by location rather than spelled out in full.
Include:
- Full legal name, date of birth, and where your Social Security card is physically kept (not necessarily the number itself, if you can avoid it)
- Bank and brokerage names and account numbers — but consider leaving PINs and passwords in a separate, more secure password manager entry rather than the same page
- Names and phone numbers for your attorney, financial advisor, accountant, and insurance agents
- The location of your will, power of attorney documents, and health care directive
- Where to find life insurance policies and beneficiary paperwork
- Instructions for pets, home maintenance items (like a security system code), and anyone who needs to be notified
Leave out, or store separately with extra protection:
- Full passwords in plain text — these belong in a password manager, referenced by "see password manager" in the main document
- Full Social Security numbers written out multiple times across multiple copies
- PINs for debit cards or safes written next to the account number they unlock
This separation matters because it means a single lost or copied page doesn't hand over everything at once. Someone would need to find both the document and the password manager (protected by its own master password) to do real damage.
A Word About Digital Executors and Online Accounts
Modern estate planning has a wrinkle that didn't exist a generation ago: most people now have email accounts, social media profiles, photo storage, and subscription services that also need to be handled after a death or incapacitation, not just bank accounts. Google, Apple, and Facebook all have "legacy contact" or "inactive account manager" settings that let you designate someone in advance to access or close these accounts — worth setting up once, rather than leaving a family member to guess your passwords or contact customer service with a death certificate.
This is a good task to pair with updating your emergency document: spend one afternoon setting legacy contacts on your major accounts, and note in your document which services have this set up so whoever handles your affairs knows where to start.
Talk to Your Family About This Too
If you're the one who created the emergency document, you're probably also the one who needs to have a slightly awkward conversation with whoever else has a copy — a spouse, an adult child, a sibling named as executor. Ask them plainly: where is their copy stored? Is it in a drawer, a phone, an email? A five-minute conversation can close the biggest gap in an otherwise well-thought-out plan.
This is also a good moment to loop in family members on identity monitoring generally. Adult children are targeted by identity thieves too, and elderly parents are sometimes not the only vulnerable person in a family's financial picture. A monitoring plan that covers multiple family members under one umbrella is often simpler — and cheaper per person — than everyone signing up separately.
The Planning You've Already Done Was the Hard Part
Making the decision to get your affairs in order, sit down, and write out account numbers and instructions for your family is the part most people put off for years. If you've already done that, you've done the difficult work. Securing it properly and adding monitoring on top is a much smaller step — a few hours, not a few years of avoidance.
Get plain-English guidance on protecting your identity and your family's information — delivered every Tuesday, no jargon, no scare tactics.
Free weekly security alerts for seniors
Plain-English updates on protecting your accounts, your identity, and your family's information — no jargon, no scare tactics. Join 3,000+ readers who stay informed without becoming tech experts.
Last updated: 2026-07-04
Related reading
Power of Attorney Abuse: 9 Warning Signs Every Senior Should Know
A power of attorney is meant to protect you, but it can be turned into a weapon. Learn the warning signs of POA abuse and exactly how to protect your money.
Best Data Broker Removal Services for Seniors (2026) — Get Your Info Off Scammer Lists
We compared 6 data broker removal services for seniors. Here's which ones actually scrub your personal info from the sites scammers use to target you.
What to Do When a Company Gets Hacked and Has Your Data
Step-by-step response plan when you get the 'your data was compromised' email. Freeze credit, change passwords, monitor accounts.