I would recommend using CanCan for security if they haven't done so already so you can't just type in other users user_id in the url to view or edit.
https://github.com/ryanb/cancan
Cancan is great way to make sure that you can only read or edit your own records in the database with Rails.