Many other national id's are not used like that and do not have any issues.
They should have to prove, beyond simply an SSN, that an individual is responsible for the debt before being able to send it to collections or report it to credit agencies.
You can for numbers issued before 2011, they're random now. The first three numbers are tied to the zip code of the application and the month/year of the application can be determined by the group numbers (the two in the middle).
That's often the case with Bank Account and Credit Card numbers too that the parts commonly masked are the least significant from a security entropy standpoint (are often built algorithmicly and tend to cluster; CC numbers often encode processor and bank in the first bunch of numbers). The parts left unmasked to make them easy to recognize are easy to recognize precisely because they have the most security "entropy" and are the most sensitive parts.
SSNs adapted in 2011 and CC Numbers are in the process of adapting (and I suppose Bank Numbers are adapting at a per-Bank rate), but it's almost funny how universally this "best practice" of masking these security identifiers started from the "wrong end" and have forced their own generation algorithms to move a lot more entropy into their prefixes and middles.
But when an real random GUID is used then this is not a problem.
Only if knowledge of one's "GUID" was regarded as sufficient to authenticate as them surely?
Maybe an ability to generate virtual IDs based on a permanent id (like with virtual credit cards) might help though this is sometimes tricky to use correctly in a privacy-preserving way.