Here is how it legally is to be solved
To start there are to angles here or perceptions
a) When will you be hacked and what will they get?
b) Obfuscation - make it more difficult when or if
Tomcat: easily hackable but why and what always.. you can google this and come across 10's of great doc's which are current (from 2600 club) or 1000's which are antequaited and not applicable.
So, ask yourselve..
When I get sued for my data becoming public, what measures did I put in place to help the Attackers, or recievers of my data find usefull info.
Rule 1: Do not create a BO that includes the Name, Address, Phone and SSN - create a relation which is associated to the BO which is required to use the SSN (simple in Aware)
Rule 2: Do not store the ssn in the format which is easily human readable.
easy enough to create rules which will concantenane and help "confuse" would-be data hackers
Rule 3: SSL (to help enrcyp) and avoid onsite/remote man-in-the-middle attacks.... they go on and on..
On any event there are so many senarios in which someone who wants your data.
Make it hard for them to get to it, (This includes the users of the systems)
Make sure you are Indemnified in the event of Data Loss/Theft etc
Train the users that THEY are RESPONSIBLE if the data is shared (Click Through Agreements)
Europe or EU rules disallow the storage of personal numbers with user data. This is a country by country stipulation
USA have guidelines for Financial and other Institutions (rarely followed as you can see in the news)
Hopefully usefull,
Lars