Our organization has recently undergone a conversion to using an outside provider for much of our functionality, and it's requiring our customers to set up new user profiles on the outside provider's site. To help them with that, we'd like to set up a page that would allow the customer to look up their new outside provider account number based on the data we have in our system, including address info, name, and SSN (Aye, there's the rub).
I'm obviously concerned about sending SSN information from outside our secure login (where this page, unfortunately, needs to be located). What are best practices for making sure this data is sent securely?
We're using VB.NET 4.0 and Visual Studio Premiuim 2012 for our work.
I'd appreciate any input you might have - security work is not my strong suit. Thanks!