If you stop paying, they want to make a report to the credit agencies.
I think the solution is simple then: The SSN should be used for read-only. Once the credit report is read/accessed, the credit bureau issues a write-only code. The company then deletes the SSN and only retains the write-only code. If the write-only code is leaked later in a hack, it is useless to criminals trying to open new accounts.
Folks haven’t learned that this data is a liability and not an asset.