However, when they are tied in with other identifying information this is when they become unique identifiers. The more associated information that is tied to the SSN the "more secure" the mechanism of identification is. I have noticed this proposal of just not using SSN at all and incorporating something else. An alternative is the password which has been proven to not be the best case scenario as users pick easy passwords to remember. Then 2fa become popular and is becoming much easier to use. Then there were gaps in the sms or voicemail method of 2fa. My point being that no matter the mechanism put into place to uniquely identify an individual there is no silver bullet. The more layers a company adds on the better. Not to say I support HIPPA or any other archaic legislation (PCI etc) these organizations are tasked with instituting laws or guidelines that are being outdated as fast as they are implemented and are required to make it as reasonable for every entity that is covered under these laws.