Reports do not support hidden fields. If you allow users to define their own reports they can print any data they allowed to access in the system. So, data access should be controlled on the system level, not in reports. For this purpose you can use access level options like "Creator Only" or, for more flexibility, rules with READ PROTECT action. For example, to ensure that a sales person can see his own sales data but not that of other sales people, you can add the following rule to object Sale:
If LoggedInSystemUser <> Sale.SalesPerson Then READ PROTECT Sale FROM SalesPerson
Aware IM automatically applies protection rules to all user queries so that even if the user runs a query like "FIND ALL Sale" he would see only his sales, not those or others.
The benefit of this approach is that you control data access in one place. Users can create they own reports or run their own queries, if you allow them. Also, in your configuration you do not have to create separate queries for different access levels just to filter out restricted data. Aware IM will do it automatically based on defined protection rules.