There is sensitive information such as SSNs in documents that we currently store. What should we do with such documents?

Many older documents and files exist that include SSN. This material is a major security concern. Paper copies must be kept locked and inaccessible to unauthorized users. Electronic copies must be moved to secure storage and/or encrypted. Many data files are simple to sanitize. (IE. just delete the SSN column from an old class roster).

Conduct an assessment of your data to determine if it is still required. If the data is no longer required, the best answer is to simply delete.