SPECIAL TOPICS - Social Security Numbers
 
  Social Security Numbers    
 
Penn is actively phasing out the use of Social Security numbers, using SSNs as a unique identifier only when necessary to fulfill legal requirements or when there is a sufficient need, such as when certain external organizations legitimately require them.
 
  Staff should review business process and IT systems to remove such sensitive data where possible, convert SSNs to PennID (write to privacy@pobox.upenn.edu for assistance), or as a last resort to mask all but the last four digits (e.g., XXX-XX-1234).  
 
Systems that must contain Social Security numbers must be registered as Critical Hosts under Penn’s principal information security policy the Critical PennNet Host Security Policy.
 
  For more information and appropriate steps to protect this sensitive data, see:    
     
     
         
Penn's Homepage
OACP Homepage Audit Homepage Compliance Homepage Privacy Homepage Contact Us
Copyright 2006-08 University of Pennsylvania  
Privacy Statement