Title: Allerton Presentation for New Administrators
1ssn
University of Illinois Social Security
Number Policy Implementation
January 10, 2001
2Your Packet
- Slides
- Glossary of Acronyms, Terms
- Sample Disclosure statements
3Presenters
Carol Livingstone livngstn_at_uiuc.edu Associate
Provost and Director, Management
Information Mike Corn mcorn_at_uillinois.edu Associ
ate Director, Univ Office of Planning
Budgeting Lisa Huson huson_at_uillinois.edu Assista
nt University Counsel
4Laws Regulations
Privacy Act of 1974 It shall be unlawful for
any Federal, State or local government agency to
deny to any individual any right, benefit, or
privilege provided by law because of such
individual's refusal to disclose his social
security account number.
5Privacy Act of 1974
- Exceptions
- To comply with another Federal law
- For a computer system in place
- prior to 1975
6Privacy Act of 1974
All government agencies must provide a disclosure
statement every time they ask for an SSN.
7Laws Regulations
FERPA
(Family Educational Rights
to Privacy Act)
Student ID numbers and Social Security numbers
are part of the educational record.
All pieces of the educational record must be
kept confidential unless they are defined as
directory information.
8But my bank insists on an SSN
The Privacy Act of 1974 places a special burden
on government agencies building databases. The
UI is a government agency. Private companies
are not bound by this Act and are free to require
an SSN.
9Why the fuss about SSN?
Identity theft a growing problem Many
financial institutions use the SSN as a password
if you can provide the SSN, you can open
accounts, access confidential information,
transfer funds.
10Why the fuss about SSN?
It is a felony, punishable by up to 5 years in
prison, to compel a person to provide a SSN in
violation of Federal law.
11UI SSN Policy
- Adopted in January, 2000
- Primary goal
- to ensure that University employees and students
comply with both the letter and the spirit of the
Family Educational Rights to Privacy Act and the
Privacy Act of 1974.
12UI SSN Policy
- Assigns responsibility for policy
implementation to one administrator per campus
and university administration. - Provides for a phased compliance strategy
- Establishes the UIN (University ID Number)
- as the permanent, university-wide
- identifier to replace the SSN
13Finding the UIN
UIN
14Phased Compliance Strategy
- Now Education/awareness
- Now Disclosure statements at points of service
- By Fall 2002 Modify all forms to have a
disclosure statement - By 2005 Replace SSN with UIN as primary
- identifier in all university computer systems
including departmental - systems
15Education/Awareness
- No use of all or part of SSN/UIN to post grades
- No use of all or part of SSN/UIN as a password
or PIN - Minimize paper reports with SSNs
- Shred any paper with SSNs
- FTP or e-mail transmission of SSNs must be
encrypted.
16SSN Policy Real Life
Ok, you know what the law and policy say. You
understand why protecting SSN is important.
What does this really mean to you in your daily
work?
17Phone-in points of service
18Phone-in points of service
You want to make your phone service efficient
and easy to use. The SSN is easy to
remember. If you insist on asking for an SSN
over the phone, you will need to read a
disclosure statement.
19Phone-in points of service
- Analysis Why do you need the SSN?
- To find the right record in a computer system
quickly. - To fill out a form electronically or on paper
20Phone-in points of service
Best solution Modify an electronic system to
have multiple ways to search name, Network ID,
UIN If continued use of SSN is approved by SSN
coordinators, can also use SSN as alternate
lookup.
21Phone-in points of service
If you had the ability to lookup both by SSN and
UIN, you could say Can you give me your UIN?
If you cant remember the UIN, a SSN is ok. A
disclosure statement would not be needed here
where the SSN is clearly not mandated.
22Phone-in points of service
If your request the SSN on the phone so that you
can enter it into a paper form, then you could
develop a procedure to ask for the UIN instead.
You can look up the SSN later before sending in
the form.
23Phone-in points of service
Remember, you may not give the person a hard time
about not having an SSN.
24Paper Forms Applications
25Paper Forms Applications
Generally, parts of the form will be entered into
a computer system. The form itself will be filed
and retained for some specified time.
26Paper Forms Applications
Analysis Does your process really need an SSN?
(What do you do now when someone leaves it
blank?)
27Paper Forms Applications
Best solution Change your form to request a UIN
instead. If you need the SSN for a valid
reason, translate the UIN to an SSN later
electronically after data entry.
28Paper Forms Applications
- If you insist on asking for an SSN, then you
must - Add an approved disclosure statement to the
printed form - Ensure that the forms are secured and disposed
of properly.
29Electronic Forms/Applications
30Electronic Forms/Applications
Does your unit have web or networked applications
that ask a person for his/her SSN? Examples
student admissions, employment applications, web
college info system, short course applications
31Electronic Forms/Applications
Analysis Does your process really need an SSN?
(What do you do now when someone leaves it
blank?) If the SSN is used as a secure log in ID
or password, youre in big trouble.
32Electronic Forms/Applications
Best solution Modify an electronic form or
application to use a name, the Network ID, or
UIN instead of the SSN. If you really need the
SSN, get it electronically later from the UIN or
network ID.
33Electronic Forms/Applications
- If you insist on asking for an SSN, then
- Request the permission of the SSN coordinators.
- Add a disclosure statement to the electronic form
(can be a link)
- Ensure that the data transmission is
- secure and encrypted. (https, not http)
- Ensure that access to the underlying database
is restricted.
34Walk-in Points of Service
35Walk-in Points of Service
Again, you want your service to be efficient and
simple for the client. But this face-to-face
contact is where asking for an SSN is the most
awkward.
36Walk-in Points of Service
- Analysis Does your process really need an SSN?
- What do you do now when the client doesnt know
it or wont provide it?
37Walk-in Points of Service
Success stories The SSN is no longer required on
any check accepted by the university. McKinley
Health Center has switched its filing system to
be based on UIN, not SSN.
38Walk-in Points of Service
Breaking news An SSN is not required in order
to process a refund check for anyone.
39Walk-in Points of Service
Best solution change your process to require a
UIN instead. If you really need the SSN
translate the UIN to an SSN later. If you are
looking up a record on-line, change your system
to lookup on either UIN or SSN.
40Walk-in Points of Service
If you must ask for the SSN, you must post or
provide an approved disclosure statement. Dont
ask for an SSN out loud in any public area where
it can be overheard. Ask client to write it down
or type it in themselves.
41Walk-in Points of Service
If the SSN is voluntary, you must not argue with
anyone who wishes to withhold an SSN. Be
especially careful when you hold some power over
the client.
42Walk-in Points of Service
Remember, anyone withholding an SSN is doing it
out of principle, not just to make your work
harder. It will be a credit to you and your
staff if you can figure out how to work around
this pleasantly.
43Disclosure statements
44Disclosure statements
- Required every time the university asks for an
SSN
- Over the phone
- On paper
- In an electronic form
- In person
- Must be approved by the
- SSN coordinators legal counsel.
45Disclosure statements
- Must contain 4 elements
- What statute or other authority permits asking
for SSN - Whether disclosure is mandatory or voluntary
- What are consequences of not providing the SSN
- What uses will be made of the SSN
461. Authority
What statute or regulation gives you the
authority to ask for an SSN?
471. Authority Examples
Federal tax regulations require us to request an
SSN from every employee. The Taxpayer Relief Act
of 1997 requires us to submit SSNs to the federal
government to ensure that you get a tax credit
for college costs. Applicants for
Federally-supported financial aid are required by
Federal law to provide an SSN.
482. Mandatory or Voluntary?
Provision of the SSN is voluntary. You are not
required to provide an SSN. Provision of the
SSN is mandatory. You must provide an SSN.
493. Consequences of refusal
If the SSN is mandatory, the consequence is
denial of service Failure to provide an SSN
will result in denial of your federal loan
application. Failure to provide an SSN will
result in termination of the offer of
employment.
503. Consequences of refusal
If the SSN is voluntary, we cannot deny services.
We can indicate that service may be slower or
require more steps. Failure to provide an SSN
may result in delay of your tuition waiver until
you complete a form in Room Failure to
provide an SSN will delay action on your
application. Providing an SSN allows us to
process your application faster
514. Use of SSN be complete
The SSN will become part of your permanent
record of employment. Internally, it will be
maintained in a secure database available only to
those employees who need to use it for university
business. It will be provided to the federal and
state government as part of the annual W2 tax
reporting process.
524. Use of SSN be complete
The SSN will be provided to the Federal
Government as part of our annual report on your
radiation exposure. This will allow the
government to maintain a lifelong record of your
exposure. The SSN will be given to persons
outside the university only as permitted by law
53I need the SSN to do my job!
The university will continue to have an SSN for
all employees and for most students. Its use
will be limited to those who really need it. If
you need it, you will have access to it.
54UI Integrate (UI2, ERP)
UI Integrate is the five-year, 197 million
dollar project to replace the aging university
administrative systems on all three campuses with
a system built on an integrated, modern database.
55UI Integrate Components
56UI Integrate the UIN
- The primary ID number will be the UIN
- A UIN will be assigned at the earliest point
possible and will be permanent. - Special care will be taken to avoid assigning two
UINs to one person. - UINs will be unique across all three campuses.
57UI Integrate the SSN
- SSNs will be stored in the database if collected,
but in a separate screen. - Access to that screen will be limited.
- For admissions records, an alternative search
mechanism using SSN will be built.
58UI Integrate Timeline 2002
- Biographical/Demographical information
- Employee Relations
- Benefits Administration
- Student Recruiting
- Undergrad, Grad, Professional Admissions
- (starting Fall, 2002 for FA03 class)
59UI Integrate Timeline 2003
- Time Attendance (ESTR)
- Payroll (ECOS)
- Employment Administration
- General Ledger (UFAS)
- Grants Contracts
- Fixed Assets
- Accounts Payable
- Purchasing
- Course Catalog (web)
- Financial Aid
- Student Accounts Receivable
- Time Attendance (ESTR)
- Payroll (ECOS)
- Employment Administration
- General Ledger (UFAS)
- Grants Contracts
- Fixed Assets
- Accounts Payable
- Purchasing
- Course Catalog (web)
- Financial Aid
- Student Accounts Receivable
60UI Integrate Timeline 2004
- Budget (BPS, BPL) (for FY04)
- Registration (summer 2004)
- Academic Records
- Class Scheduling (Timetable)
- Enrollment Management
- Transfer Credit Articulation
- Degree Processing
61Decision Support the SSN
Decision Support is a separate project running
parallel to UI Integrate. Goal to build a
data retrieval environment for all the data
needed to run the university. Decision Support
is a new, permanent university function.
62Decision Support the SSN
- The DS data warehouse will carry SSN.
- Access to the table with SSN will be limited.
- The UIN will be used to link data between tables,
not the SSN. - All reports will be rewritten, and few will carry
SSN
63Utilities to help you convert
- i-card query
- UIN to SSN conversion web page
-
- SSN to UIN bulk conversion utility
64i-card Query
Enter a name, UIN, SSN or network ID Get back
info from i-card database name,
student/employee status, fees paid, address,
picture, UIN, network ID (not SSN)
65UIN to SSN Web Page
- Enter UIN
- Get SSN ID picture
- Use for points-of-service
- ask for the UIN instead of the SSN and convert it
on the spot.
66Bulk conversion utility
- Send in a list of SSNs
- Get a list of UINs
- Use to convert all your existing databases
currently using SSN. - Can also do it one SSN at a time.
67Other resources
- SSN coordinators
- Approve disclosure statements
- Approve uses of SSN
- Respond to complaints
- Consult/advise on alternatives
- SSN Policy web page
- http//www.ssn.uillinois.edu
68Summary
ssn
- SSN use is restricted by law and policy
- Approved disclosure statements are required any
time SSN is requested - By 2005, SSN will be eliminated from UI systems
reports where it is not needed. - By 2005, no UI system may use SSN as the
primary identifier
69Questions??
ssn