Data security (SSNs, banking info) is difficult, but they're table stakes in the payroll and benefits space (ex., how do you securely share personal information across different benefits providers).
Honestly, my main takeaway is I'm happy our company built everything (payroll and benefits) in-house from scratch.
We worry less about integrations issues, and it helps with security when you have more control over everything.
It's been extremely difficult building everything from the ground up, and I've definitely questioned our approach (more than once I said, "Why don't we just integrate with X?"), but I think this validates the path we've taken.
This is a lesson I'm going to take away for whatever other software/service I may end up working on.
This is not a good take away. The same could be said for rolling your own cryptography — control + no integration — which is a really terrible idea.
This doesn't validate your approach since the problem wasn't that a third party you were integrating with messed up your data. I understand why you wanted to build everything in house, but this isn't an example that validates your decision.