Using social security numbers for authorizing access

Using social security numbers for authorizing access

I am a senior security analyst in a large health care software company. I have a user that was using FTP to connect to a client, server to server. The client requested the user's social security number in order to allow access. This was because (the client said) of HIPAA (and RACF Mainframe Security)restriction. Any thoughts on this scenario?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

If I understand your question correctly, I'm not aware of any HIPAA mandate that states a social security number must be used for client access. If anything, HIPAA mandates protecting SSNs and requires the minimum amount of protected health information necessary to get the job done. This can be used, but if it is determined during a risk assessment that threats or vulnerabilities exist in transmitting a SSN (or any confidential info) across a FTP, or any data communications, session, then certain systems must be in place to protect that information (i.e. encryption, authentication, etc.).


For more information on this topic, visit these other SearchSecurity.com resources:
  • Best Web Links: Health Care/Health Services Security
  • Ask the Expert: Encrypting e-mail and what is considered confidential under HIPAA
  • Ask the Expert: HIPAA compliance for company building health care application


    This was first published in March 2003