Spirion AnyFind and Common Custom Data Types Defined

The following are Spirion AnyFind™ Data Types. Managing these Data Types are of critical importance to manage Personally Identifiable Information (PII) and to comply with regulations, as well as combat identity theft. You can search for the following Data Types:

Overview

Spirion AnyFind™ Data Types are provided by Spirion Sensitive Data Platform by default.

  • These data types are found on the Data Types page (Settings > Global Data Types), on the tab SPIRION DATA TYPES (ANYFINDS).
  • AnyFinds include Social Security number, credit card number, and phone number

Custom data types are created by users with Administrator rights,

  • These data types are found on the Data Types page (Settings > Global Data Types), tab "CUSTOM DATA TYPES."
  • Custom data types include ABN, IMEI, and ICCID

ABN

Custom data type. This data type must be created by you, the user.

Australian Business Number, a unique 11-digit identifier for businesses in Australia for government, tax, and business dealings.

  • The ABN is an 11-digit number where the first 2 digits are a checksum.
    • Unlike with the tax file number (TFN), the ATO has publicised the formula for checking and creating valid ABN checksums.
    • The nature of the ABN algorithm means that any 9-digit number can be made into a valid ABN.
  • Australian ABN identifies entities like sole traders, companies, and non-profits for tax (GST), invoicing, and grants.
  • Purpose: A unique identifier for businesses dealing with the Australian government and other businesses, helping verify identity and avoid PAYG tax.
  • Who needs it: Most Australian businesses, including sole traders, companies, and partnerships.
  • Uses: Invoicing, claiming GST credits, applying for grants, setting up an Australian domain name, and identifying your business.

Australia Tax File Numbers (TFN)

Spirion data type (AnyFind). This data type is provided by default.

  • An Australian Tax File Number (TFN) is a unique, personal reference number in the Australian tax and superannuation systems
  • An Australian Tax File Number (TFN) is a unique, 9-digit number
  • The number is issued by the Australian Taxation Office (ATO).
  • Recipients keep their Tax File Number for life, even if they change jobs, name, or move overseas.
  • Tax File Numbers can be used to open credit cards and bank accounts on someone's behalf, so searching for this Data Type is of critical importance to prevent identity theft.

Bank Account Number AnyFind

Spirion data type (AnyFind). This data type is provided by default.

  • Application: Universal (not region-specific)
  • Default Ordinal Value: 50
  • Default Dollar Value: $83

Purpose

  • The Bank Account Number AnyFind discovers banking and financial account numbers in scanned data.
  • It uses keyword-based contextual validation to enhance accuracy — meaning a numeric candidate is flagged as a match only when a recognized banking keyword appears nearby in the same location.

Sub-Types

The Bank Account AnyFind encompasses four detection categories:

Sub-Type

Setting

Default

General Account Numbers

EnableGeneralAccountNumbers

Enabled

ABA Routing Numbers

EnableABARoutingNumbers

Disabled

International Bank Account Numbers (IBAN)

EnableIBAN

Disabled

SWIFT/BIC Codes

EnableSWIFTBICCodes

Disabled

Keyword Validation

By default, the AnyFind requires an additional keyword in the location (RequireAdditionalKeyword = Require).

The following is the complete list of banking terms that generate a true positive (matched case-sensitive):

Banking, BANKING, banking, Bank, BANK, bank, ABA/routing, ABA routing, ABA Routing, ABA ROUTING, ABA #, ABA#, ABA Number, ABA NUMBER, SWIFT, Swift, Savings, SAVINGS, Checking, CHECKING, Financial, FINANCIAL, financial, Deposit, deposit, DEPOSIT, MUTUAL, Mutual, mutual, Loan, loan, LOAN, Interest Rate, INTEREST RATE, interest rate, TRUST, Trust

Known gap: Some terms have only 2 case variants instead of 3. Specifically, the lowercase forms swift, savings, checking, and trust are not recognized as valid keywords.

  • For example, checking account: 7032889518 does not match, while Checking account: 7032889518 does.

How It Fits Into the Platform

  • Can be used standalone in playbook decision logic (e.g., IF Data Type = Bank Account Number)
  • Can be combined with other AnyFinds or custom Data Types in Sensitive Data Definitions (SDDs) for context-aware detection (for example, "Bank Account Number NEAR Social Security Number")
  • English keyword validation enhances accuracy but is not strictly required for all sub-types — it depends on the RequireAdditionalKeyword setting

CCPA

Custom data type. This data type must be created by you, the user.

The California Consumer Privacy Act (CCPA), effective since 2020 and amended by the CPRA, grants California residents significant control over their personal data, including the rights to know, delete, correct, and opt-out of the sale or sharing of their information. It applies to for-profit businesses meeting specific, high-volume data or revenue thresholds.

Key Aspects of the CCPA:

  • Consumer Rights: Residents can request to see what information a business has collected, delete that information, opt-out of data sales/sharing (including targeted advertising), and receive equal service/pricing even if they exercise these rights.
  • Business Requirements: Covered businesses must update privacy policies, implement methods for submitting consumer requests, and provide a clear "Do Not Sell or Share My Personal Information" link.
  • Penalties & Enforcement: The California Privacy Protection Agency (CPPA) and state Attorney General enforce the law, with fines up to per unintentional violation and per intentional violation.
  • Recent Changes: The CCPA was significantly expanded by the California Privacy Rights Act (CPRA), which added rights regarding sensitive personal information and corrected information. 

The CCPA applies to businesses that do business in California and meet one of the following:

  • Have an annual gross revenue over 1 million USD.
  • Buy/sell/share the personal information of 100,000 or more California residents/households.
  • Derive 50% or more of their revenue from selling/sharing personal information. 

Canada Social Insurance Numbers (SIN)

Spirion data type (AnyFind). This data type is provided by default.

  • Social Insurance Number (SIN) is a unique 9-digit number used by the Canadian government to identify individuals for tax purposes and to administer national programs. It is essential for anyone who wants to work legally in Canada or access government benefits. 
  • Employment: A SIN must be provided to an employer within 3 days of starting a job so they can report your income and taxes.
  • Taxes: The Canada Revenue Agency (CRA) uses a person's SIN to identify them when they file annual income taxes.
  • Benefits: A SIN is required to receive payments from government programs like the Canada Pension Plan (CPP)Employment Insurance (EI), and the Canada Child Benefit
  • Canadian Citizens and Permanent Residents are issued a permanent SIN that does not expire.
  • Temporary Residents: International students and foreign workers are issued a temporary SIN beginning with the number "9". These numbers have an expiry date, usually matching the individual's work or study permit.
  • Social Insurance Numbers are used in Canada and can be used to open credit cards and bank accounts on your behalf, so searching for this Data Type is of critical importance to prevent identity theft.

Credit Card Numbers

Spirion data type (AnyFind). This data type is provided by default.

  • A credit card number is a unique identifier (typically 13-19 digits) on your card
  • The number is composed of sections identifying the industry, issuer, and your account
  • The final digit acts as a checksum for validity, essential for transactions but requiring careful protection from fraud.
  • Credit card numbers can be used to make unauthorized purchases on your behalf.

Structure of a Credit Card Number

  • First Digit (MII): The first number starts with a 3, 4, 5, or 6.
    • This first number is called the major industry identifier (MII) number, and it shows the primary industry associated with the card or card issuer
      • Example: 4 for Visa, 5 for MasterCard, 6 for Discover
    • Numbers 3 through 6 represent the MIIs most used by the majority of personal credit card issuers.
    • Other MII examples:
      • 1 - Designates an air travel and financial services issuer
      • 7 - Primarily used for cards issued in the petroleum industry
  • 2nd through 6th Digits - Issuer Identification Number (IIN/BIN): The next 5-digit set of numbers is called the issuer identification number (IIN) or the bank identification number (BIN).
    • These numbers refer to the credit card company that issued the card, and also identified which payment network the card belongs to.
  • 7th through 14th or 15th Digits: This section immediately follows the IIN.
    • The individual account number is assigned by the card issuer and is unique to each credit card account.
    • Your account number and card number aren’t the same.
    • While the MII and IIN let merchants know what institution the money is coming from, this section can tell them which accounts may be charged.
  • Checksum Digit: The very last digit is a calculated number to verify the card's authenticity. 

Security & Protection

  • CVV/CVC: The 3 or 4-digit security code (usually on the back) is needed for online/phone purchases, says Lloyds Bank and American Express
  • Passwords: Passwords can be used to authenticate you online.
  • Bank Account Numbers: Can be used to gain access to your financial information and conduct transactions on your behalf.

CUI

Custom data type. This data type must be created by you, the user.

Controlled Unclassified Information (CUI) is sensitive, non-classified federal information requiring safeguarding or dissemination controls. Established by Executive Order 13556, CUI ensures consistent handling of sensitive data across government agencies and contractors. It covers diverse categories, such as PII, intellectual property, and technical data, often subject to DFARS 7012. 

Key details about CUI include:

  • Purpose: Standardizes how sensitive information is marked, handled, and protected to prevent unauthorized disclosure, without reaching the level of classified national security information.
  • Categories: Covers areas including Critical Infrastructure, Defense, Financial, Intelligence, Law Enforcement, and Controlled Technical Information.
  • Applicability: Applies to government employees and contractors, universities, or private entities holding such data on behalf of the government.
  • Marking: Controlled Unclassified Information is marked to inform holders that it requires special handling, typically with a "CUI" header and specific category indicators.
  • Compliance: Controlled by regulations like 32 CFR Part 2002 and often requires compliance with NIST SP 800-171 for security controls. 

Examples include Personally Identifiable Information (PII), Protected Health Information (PHI), and attorney-client privileged information

CUI can be created as a Regular Expression.

Driver Licenses

Spirion data type (AnyFind). This data type is provided by default.

  • A U.S. driver's license, issued by each state's DMV, is required to drive, with requirements varying by state but generally including proving identity (birth certificate, passport), residency (utility bill), and legal presence (for non-citizens). 
  • The process involves passing vision, written (knowledge), and on-road (skills) tests, plus paying fees, with most people getting a standard Class D license for personal vehicles.  
  • Commonly used as a way to identify who you are.
  • Driver license formats vary by U.S. state

Dates of Birth

Spirion data type (AnyFind). This data type is provided by default.

  • A person's "date of birth" (or birthdate) is simply the specific day, month, and year they were born, a key piece of personal information used on forms, documents, and for age verification, usually written as MM/DD/YYYY (United States) or DD/MM/YYYY (most other places). 
  • Recorded on birth certificates. 
  • Commonly used as a way to authenticate a person over the phone as companies typically ask you to confirm you are who you say by stating your Date of Birth.
  • Found in passports, driver's licenses, and old family records. 
  • Format: Most commonly Month/Day/Year (example: 01/15/1990 in the United States) or Day/Month/Year (example: 15/01/1990). 
  • Usage: Essential for official records, IDs, banking, and healthcare. 

E-Mail Addresses

Spirion data type (AnyFind). This data type is provided by default.

  • An e-mail address is a unique digital identifier (like username@domain.com) used for sending and receiving electronic messages
  • Consists of a local part (username), the @ symbol, and a domain name that points to the mail server
  • Essential for online communication, account creation, and services. 
  • When entering a unique E-Mail Address, it must be entered as no more than 100 letters, numbers, dashes, periods, or underscores, but without any other characters.
  • One '@' character is required.

Email Address AnyFind

  • Method: AnyFind (built-in detector)
  • Application: Universal (not region-specific)

Purpose

  • The Email Address AnyFind discovers email addresses in scanned data.
  • It detects the standard user@domain.tld format and validates candidates against a maintained list of known domain names shipped with the AnyFind definition files (domains.dat).
  • Unlike many other AnyFinds, the Email Address AnyFind does not require contextual keyword validation — the structural pattern of an email address (local-part@domain) is sufficiently distinctive to serve as its own validator.

Detection Behavior

Property

Detail

Pattern

local-part@domain.tld — standard RFC-compliant email address format

Keyword Requirement

Not required — pattern + domain validation is sufficient

Domain Validation

Validated against domains.dat, a list of domain names shipped with the AnyFind definition files and updated as needed

Internationalization

By default, only Latin characters are accepted in both the username (local-part) and domain. International (non-Latin) characters in either component must be explicitly enabled via advanced settings.

Domain Restriction Logic (Critical Detail)

The DomainRestrictionOption setting controls the scope of email domain matching and interacts with the include/exclude list as follows:

DomainRestrictionOption

Behavior

All domains (default)

Matches email addresses at any valid domain found in domains.dat. The include/exclude list is not used.

Common domains

Matches email addresses only at well-known, commonly used domains (e.g., gmail.com, yahoo.com, outlook.com, etc.). The include/exclude list is not used.

Custom

Activates the DomainRestrictions list. Behavior depends on IncludeDomainRestrictions: Include List = only match emails at the specified domains; Exclude List = match emails at all domains except the specified ones.

Important limitation: The DomainRestrictionOption must be set to "Custom" to use the include/exclude list. The include/exclude functionality operates at the top-level domain level only — it does not filter on sub-domains. For example, you can exclude .com but you cannot exclude spirion.com specifically. This means customers who want to "search all domains but exclude their internal company domain" cannot achieve this with the current implementation.

Domain Validation File

The AnyFind relies on domains.dat, a file shipped as part of the AnyFind definition package. This file contains the list of domain names used by the searcher to validate email address domains. It is updated "as needed" and its version is tracked by datver.dat.

How It Fits Into the Platform

  • Can be used standalone in playbook decision logic (e.g., IF Data Type = Email Address)
  • Can be combined with other AnyFinds or custom Data Types in Sensitive Data Definitions (SDDs) for context-aware detection (e.g., "Treat as higher risk only when a proprietary Dictionary term appears near an Email Address AnyFind")
  • Results are reported to the console under the E-mail Address match type
  • The internal settings key is EmailAddress
  • The Health Information AnyFind does not include an Email Address validator, so email addresses are not used in healthcare-specific validation workflows

Best Practice Notes

  • Default configuration with "All domains" will match email addresses at any recognized domain — this produces the broadest results. For organizations that only care about specific domains (e.g., detecting customer email addresses at common providers), switching to "Common domains" significantly reduces volume.
  • Excluding internal domains is a frequent customer request (e.g., "find all email addresses except our own company's"). This cannot be accomplished natively with the exclude list. As a workaround, use negative keywords containing your internal domain name to suppress matches that appear near company-internal context.
  • International email addresses (IDN domains, Unicode local-parts) are increasingly common but are disabled by default. Enable AllowInternationalDomains and/or AllowInternationalUsernames if your organization handles international correspondence or has a global presence.
  • False-positive rate is generally low because the user@domain pattern is highly distinctive. The primary tuning need is usually reducing volume (too many true positives) rather than eliminating false positives — domain restriction is the most effective lever for this.

ePHI

Custom data type. This data type must be created by you, the user.

Electronic Health Information.

Electronic Protected Health Information (ePHI) is any identifiable health data (treatment, payment, or condition) created, stored, or transmitted in digital format, such as EHRs, images, or emails. Under HIPAA, it requires strict administrative, physical, and technical safeguards like encryption to ensure security, confidentiality, and integrity. 

Key Aspects of ePHI

  • Definition & Scope: ePHI is a subset of Protected Health Information (PHI). While PHI can be paper or electronic, ePHI specifically refers to data in electronic media.
  • Examples: Electronic health records (EHRs), digital lab results, X-rays, MRIs, and billing information.
  • Security Requirements: The HIPAA Security Rule requires safeguarding this data, as it is easily copied and transmitted, posing higher breach risks.
  • Protection Measures: Implementing encryption for data at rest and in motion, using secure messaging, and restricting access to authorized users.
  • Violations & Penalties: Unauthorized access, such as via cyberattacks, leads to breaches. Violations can result in significant financial penalties, including fines up to $1.9 million per year depending on the level of negligence. 

Health Information

Spirion data type (AnyFind). This data type is provided by default. Other health information data types, such as MRN, are custom data types and must be created by you, the user.

  • There are many regulations about Health Information that must be complied with. See below. Also see "ePHI," above.

Medical Record Number (MRN)

  • Medical Record Number (MRN) is a unique identifier assigned by a healthcare facility or hospital system to track a patient’s health information over time. It serves as a permanent internal code that links all of an individual's medical history, treatments, and laboratory results within that specific organization.
  • Organization-Specific: Most patients have different MRNs for different hospital systems (example: 1 for Inova and another for Sentara), as there is currently no universal national medical ID in the U.S..
  • Permanent: Unlike a visit or "encounter" number, which changes every time you see a doctor, an MRN remains the same for your entire life within that healthcare network.
  • Privacy Protected: Under HIPAA, an MRN is considered Protected Health Information (PHI) and is used in place of names or Social Security numbers to reduce the risk of identity theft and data breaches. 
  • Discharge Papers: MRNs can be found at the top or bottom corner of visit summaries, lab orders, or hospital discharge instructions.
  • Wristbands: If currently admitted, the number is printed on your hospital identification band.
  • Insurance Cards: Some integrated systems, such as Kaiser Permanente, print the MRN directly on the front of the member ID card. 

DEA Number (Drug Enforcement Administration Registration Number)

  • Other health information may include a DEA Number (Drug Enforcement Administration Registration Number) which is a unique identifier assigned to healthcare providers and facilities that allows them to legally prescribe, dispense, or administer controlled substances. 
  • Unlike a personal address or SIN, a DEA number is not assigned to patients. It is only issued to the following 3 entities: 
    • Individual Practitioners: Physicians (MD/DO), dentists, nurse practitioners, physician assistants, veterinarians, and optometrists.
    • Facilities: Hospitals, clinics, pharmacies, and manufacturers.
    • Mid-level Practitioners: Assigned with a first letter of "M" to distinguish them from high-level practitioners (typically "A", "B", "F", or "G"). 
  • In Medical Records
    • Prescription Authentication: Pharmacists use the DEA number to verify that a provider has the legal authority to order controlled medications (like narcotics or sedatives).
    • Tracking and Monitoring: It enables the DEA to track prescribing patterns and identify potential fraud, misuse, or drug diversion.
    • Record Retention: Providers must maintain thorough records of all controlled substance transactions associated with their DEA number for at least 2 years
  • Structure of DEA Number
    • A valid DEA number always follows a specific 9-character format:
      • 1st Letter: Identifies the type of registrant (example: Characters A/B/F/G for doctors, M for mid-level).
      • 2nd Letter: Usually the first letter of the provider's last name (or "9" for businesses).
      • 7 Digits: A unique sequence where the last digit is a "check digit" calculated through a specific mathematical formula to prevent errors or forgery.

National Provider Identifier (NPI)

  • Other health information may include an NPI. A National Provider Identifier (NPI) is a unique 10-digit identification number issued to healthcare providers in the United States.
  • Established by HIPAA, it serves as a universal standard to identify individual clinicians and healthcare organizations in all administrative and financial transactions, such as billing insurance. 
  • Universal & Permanent: An NPI replaces all "legacy" identifiers previously assigned by different insurance plans. It stays with a provider for their entire career, regardless of changes to their name, specialty, or practice location.
  • "Intelligence-Free": The number does not contain coded information about the provider, such as their state of practice or medical specialty.
  • Public Record: NPI numbers are not private. They are listed in a public database for verification by patients, pharmacies, and other providers. 
  • Two Types of NPIs:
    • Type 1 (Individual): For sole practitioners, such as physicians, dentists, nurse practitioners, and physical therapists.
    • Type 2 (Organization): For healthcare entities, including hospitals, clinics, group practices, pharmacies, and laboratories. 
  • Uses:
    • Billing & Claims: Providers must have an NPI to submit electronic claims to any health plan, including Medicare and Medicaid.
    • Prescriptions: Pharmacists use NPIs to identify the prescriber on a prescription. While a DEA number is required for controlled substances, an NPI is the standard identifier for all other medications.
    • Referrals: When a doctor refers you to a specialist, they use the specialist's NPI to ensure medical records and billing are correctly linked. 

ICCID

Custom data type. This data type must be created by you, the user.

An ICCID (Integrated Circuit Card Identifier) is a unique serial number for your SIM card (or eSIM) that identifies it to the mobile network, acting like a digital fingerprint.

  • Typically 19-20 digits long and found on the card or in device settings.
  • Used for network authentication and SIM management. 
  • It is distinct from your phone number (MSISDN) or device ID (IMEI) and helps carriers manage services, track devices, and troubleshoot issues.  
  • Format: ITU-T E.118 standard format, starting with '89' (telecoms), followed by the country code (CC), issuer identifier (II/MNC), the unique SIM number (Account ID), and ending with a Luhn algorithm-calculated check digit for error detection, identifying the card and carrier.
    • ICCID Format Breakdown:
      • 89 (MII - Major Industry Identifier): 
        The first 2 digits always signify it's a telecommunications card (like a SIM).
      • CC (Country Code): 
        Next 2 or 3 digits identify the country where the SIM was issued (for example, 310 for the USA).
      • II (Issuer Identifier/MNC): 
        1 to 4 digits identifying the specific mobile network operator (for example, AT&T, Verizon).
      • IAIN (Individual Account Identification Number): 
        A unique sequence of digits identifying the specific SIM card account.
      • C (Check Digit): 
        The final digit, calculated using the Luhn algorithm, validates the number for accuracy. 
    • Example8931021000000381209
      • 89: Telecoms, 310: USA, 210: Telnyx (Issuer), 00000038120: Unique SIM Identifier, and 9: Check Digit.

What it's used for:

  • Identification & Authentication: Mobile networks use it to recognize and verify your SIM card.
  • SIM Management: Operators use it to track, provision, and troubleshoot SIMs, especially for IoT devices.
  • Service Activation: Helps activate services and link them to the correct chip.

IMEI

International Mobile Equipment Identity (IMEI) is a unique 15-digit number identifying GSM, WCDMA, and iDEN mobile phones, acting as a device "fingerprint" to track stolen or unauthorized devices. It differs from a serial number, allowing carriers to block devices, and is found by dialing *#06#, in settings, or on the SIM tray/battery compartment. 

  • Function: Enables tracking and blocking of lost or stolen devices, and verifies device authenticity/compatibility, particularly for used phones.
  • Format: The IMEI (15 decimal digits: 14 digits plus a check digit) or IMEISV (16 decimal digits: 14 digits plus 2 software version digits) includes information on the origin, model, and serial number of the device.
    • As of 2004, the format of the IMEI is AA-BBBBBB-CCCCCC-D, although it may not always be displayed this way.
    • The IMEISV does not have the Luhn check digit but instead has 2 digits for the Software Version Number (SVN), making the format AA-BBBBBB-CCCCCC-EE
    • The structure of the IMEI/SV is specified in 3GPP TS 23.003.
    • The model and origin comprise the initial 8-digit portion of the IMEI/SV, known as the Type Allocation Code (TAC).
    • The remainder of the IMEI is manufacturer-defined, with a Luhn check digit at the end.
    • For the IMEI format prior to 2003, the GSMA guideline was to have this Check Digit always transmitted to the network as zero.
    • This guideline seems to have disappeared for the format valid from 2003 onwards.

Commonly Associated Information

  • Dual SIM: Devices with multiple SIM cards may have multiple IMEI numbers.
  • Distinction: It is distinct from the manufacturer's serial number.
  • Industry Standard: It is utilized by carriers worldwide to identify devices on cellular networks. 

Personal Addresses

Spirion data type (AnyFind). This data type is provided by default.

  • personal address (often called a residential or home address) is the specific geographic location where an individual or family lives.
  • A personal address is not necessarily the same as a mailing address, business address, or legal address. It serves as a primary point of contact for personal correspondence, legal identification, and accessing essential services. 
  • Standard Format: In the U.S., it typically includes the recipient’s name, house/apartment number, street name, city, state, and ZIP code.
  • Legal Identity: It is the official "home of record" used on government documents like driver's licenses, passports, and voter registrations.
  • A permanent personal address is considered a long-term residence, distinguishing it from temporary or vacation addresses. 

Common Uses

  • Official Documentation: Required for tax records, vehicle registration, and background checks.
  • Utility Services: Used to activate electricity, water, and internet services.
  • Financial: Can be used to open credit card accounts and bank accounts on your behalf.

Passport Numbers

Spirion data type (AnyFind). This data type is provided by default.

  • A passport number is a unique alphanumeric code identifying your specific travel document, found on the photo page (usually top right) and often the back cover, used for travel, visas, and identity verification; it changes with each new passport issued, unlike a national ID. 
  • Structure: U.S. passports now use a letter followed by 8 numbers, while formats vary by country. 
    • A passport is a travel document that certifies the identity and nationality of its holder.
    • Most passports contain information such as name, place and date of birth, photograph, signature, and other relevant identifying information.

Passport Number AnyFind

  • Method: AnyFind (built-in detector)
  • Application: US Passports (primary); Canadian Passports (optional, added separately)
  • Default Ordinal Value: 75
  • Default Dollar Value: $124

Purpose

The Passport Number AnyFind discovers passport numbers in scanned data.

  • It primarily targets US passport numbers, which are formatted as 9-digit numeric strings.
  • It uses contextual keyword validation — the word "Passport" (or a related term) must appear nearby in the same location for a candidate to be flagged as a match.

Detection Pattern & Validation

Country

Format

Default

Notes

US/UK

9-digit numeric (for example, 123456789)

Enabled (by default)

Primary detection target

Canada

Canadian passport number pattern

Available as opt-in

Can be used independently or alongside US/UK

How matching works:

  • The AnyFind scans for nine-digit numeric patterns
  • A contextual keyword (for example, "Passport") must be found near the candidate number for it to be counted as a valid match
  • Without a recognized keyword nearby, candidates are not reported — even if they are valid passport numbers
  • In structured data (for example, spreadsheets), a column header containing a keyword like "Passport Number" serves as the contextual validator

Keyword Validation Behavior (Critical Detail)

The Passport AnyFind's keyword behavior is a key accuracy/sensitivity tradeoff:

  • Default mode (no advanced options): Only the word "Passport" (and close variants) is used for contextual validation. A nine-digit number near "Passport" = match. Without the keyword nearby = no match.
  • FindAllNumbersinLocationwithPassportKeyword enabled: If the location (file) contains a passport keyword anywhere, then every nine-digit number in that location is reported as a match. This dramatically increases results and can introduce false positives (e.g., bank account numbers, other 9-digit values get swept in). https://spirion.atlassian.net/wiki/spaces/SE/pages/3375824902
  • UseAdditionalKeywords enabled: Expands the set of validation keywords beyond just "Passport".
  • UseCustomKeywords + CustomKeywords: Allows user-defined terms. However, there is a known behavioral issue where custom keywords alone may not produce matches unless the word "Passport" itself is also present in the location. https://spirion.atlassian.net/browse/AL-19786

How It Fits Into the Platform

  • Can be used standalone in playbook decision logic (for example, IF Data Type = Passport Number)
  • Can be combined with other AnyFinds or custom Data Types in Sensitive Data Definitions (SDDs) for context-aware detection
  • A companion Machine Readable Passport RegEx pattern exists separately in the Spirion RegEx library to detect Machine Readable Zone (MRZ) codes on passport images — this is not part of the Passport AnyFind but can complement it. Common Regex patterns for testing and data sample


Best Practice Notes

  • Default configuration is conservative — keyword proximity reduces false positives but can miss legitimate passport numbers when no keyword context exists
  • FindAllNumbersinLocationwithPassportKeyword should be used cautiously: in datasets with multiple 9-digit numeric columns (bank accounts, phone numbers, etc.), it will produce significant cross-contamination of results. AT&T testing showed this setting matched all 9-digit numbers across columns, polluting results. AT&T Planted Synthetic Data Tests Project
  • For next-generation US passports (post-2021), the AnyFind cannot detect these in v13.6.2 — the fix is in 13.7. As a workaround, a custom RegEx Data Type can be created to match the [A-Z][0-9]{8} pattern with keyword proximity
  • In unstructured data testing, the AnyFind's keyword proximity requirement significantly limits recall — AT&T synthetic data tests found only 1 passport match in unstructured format compared to 25,028 in structured format with column-header validation

PII

Personally Identifiable Information. Custom data type. This data type must be created by you, the user.

See PII

Social Security Numbers

Spirion data type (AnyFind). This data type is provided by default.

What is a Social Security Number Used for?

  • A US Social Security Number (SSN) is a unique, 9-digit number issued by the Social Security Administration (SSA) to citizens, permanent residents, and eligible temporary workers for tracking earnings, benefits, and taxes, effectively acting as a primary national ID for work, finance, and government services, applied for using Form SS-5.
  • A security and privacy risk because Social Security numbers can be used to open credit card accounts and bank accounts on someone's behalf.

Social Security Number AnyFind

  • Method: AnyFind (built-in detector)
  • Application: United States Social Security Numbers

Purpose

The Social Security Number AnyFind discovers US Social Security Numbers (SSNs) — 9-digit numbers issued by the Social Security Administration (SSA) — in scanned data.

It supports 2 distinct detection modes:

  • Formatted SSNs (delimited, for example, 123-45-6789)
  • Unformatted SSNs (plain 9-digit strings, for example, 123456789), each with their own accuracy controls.

Social Security Administration AnyFind Validation

By default, the AnyFind validates candidates against Social Security Administration rules.

SSNs are considered invalid when they meet any of the following criteria:

  • All zeros (000000000)
  • All ones (111111111)
  • All threes (333333333)
  • Consecutive digits in numerical order (123456789)
  • First 3 digits (area number) are 000, 666, or in the range 900–999
  • First 3 digits outside the range specified/published by the SSA

This validation can be disabled via the DisableSSAValidation setting when broader matching is desired.

Advanced Configuration Settings — Unformatted SSN (USSN) Controls

These settings apply specifically to the detection of unformatted (non-delimited) SSNs and are critical for managing false-positive rates:

Setting

Default

Description

SearchOption

Always

When to search for unformatted SSNs: Never/In Excel and CSV files only/Always

RequireKeyword

Allow anywhere in the location

Require an SSN keyword for unformatted SSNs: Disable/Allow anywhere in location/Require to be near the SSN

UseCustomKeywords

Disabled

Use custom keywords when finding unformatted SSNs

CustomKeywords

(empty)

Additional keywords for finding unformatted SSNs

UseNegativeKeywords

Disabled

Use negative keywords to eliminate unformatted SSN false positives

CustomNegativeKeywords

(empty)

Negative keywords for eliminating unformatted SSNs

ApplyNegativeKeywordsToUSSNsOnly

Disabled

Only apply the negative keyword list to unformatted SSNs (vs. all SSNs)

EnableZipCodeTest

Apply zip code test

Test unformatted SSNs for zip+4 context (eliminates candidates that look like zip+4 codes)

MinimumRequired

1

Minimum number of unformatted SSNs required in a location for a match

MinimumRequiredPDF

1

Minimum number of unformatted SSNs required in a PDF file for a match

How It Fits Into the Platform

  • Can be used standalone in playbook decision logic (for example, IF Data Type = Social Security Number)
  • Can be combined with other AnyFinds or custom Data Types in Sensitive Data Definitions (SDDs) for context-aware detection (for example, "Credit Card Number NEAR Social Security Number")
  • The Health Information AnyFind can optionally require SSN presence as one of its validators (EnableValidatorforSSNNumber), linking SSN detection into healthcare-specific workflows
  • Formatted SSNs are reliable without keywords; tuning unformatted SSN settings is the primary lever for controlling false-positive rates

Best Practice Notes

  • Default configuration tends to produce a high volume of results. Applying best-practice SSN configuration settings can reduce results by ~76% by eliminating false positives.
  • For environments with high false-positive rates, the most impactful controls are:
    • RequireKeyword — require near the SSN (strictest)
    • EnableZipCodeTest — eliminates zip+4 false positives
    • SearchOption — restrict unformatted SSN searching to Excel/CSV only or disable entirely
    • Negative keywords — Eliminate known non-SSN patterns

Telephone Numbers

Spirion data type (AnyFind). This data type is provided by default.

  • telephone number is a sequence of digits used as an address for a telecommunication endpoint, such as a phone.
  • Often used to confirm identity, such as sending an SMS message to the phone number on file.

Telephone Number AnyFind

  • Method: AnyFind (built-in detector)
  • Application: US Telephone Numbers

Purpose

The Telephone Number AnyFind discovers US telephone numbers in scanned data.

  • It detects standard North American phone number formats — typically 10-digit numbers with a 3-digit area code and 7-digit local number — in various delimited presentations
    • For example, (555) 123-4567, 555-123-4567, 555.123.4567
    • The AnyFind also validates the US +1 country code, so US numbers prefixed with +1 are matched.

Important scope limitation:

  • This AnyFind is US-only.
  • International telephone numbers are not detected by this AnyFind.
  • For international number detection, create a custom RegEx Data Type
  • When using both the AnyFind and a custom international RegEx, US numbers with the +1 country code will result in duplicate matches.

Detection Behavior

Unlike some AnyFinds (SSN, Bank Account), the Telephone Number AnyFind does not require a contextual keyword by default.

It relies on pattern recognition and format validation — the presence of a recognizable phone number structure (area code + exchange + subscriber number in standard delimited formats) is sufficient for a match.

The primary accuracy controls are:

  • Phone range filtering — Restrict matches to specific area codes and exchanges
  • Negative keywords — Eliminate false positives by excluding candidates that appear near certain terms
  • Custom delimiters — Expand or modify what separators are recognized between number segments

How It Fits Into the Platform

  • Can be used standalone in playbook decision logic (for example, IF Data Type = Telephone Number)
  • Can be combined with other AnyFinds or custom Data Types in Sensitive Data Definitions (SDDs) for context-aware detection (for example, "Telephone Number NEAR Personal Address")
  • The Health Information AnyFind does not include a Telephone Number validator (unlike SSN), so phone numbers are not used in healthcare-specific validation workflows
  • Results are reported to the console under the Telephone Numbers match type

Best Practice Notes

  • Phone range filtering (EnablePhoneRanges) is the most powerful precision control for this AnyFind. Organizations that only care about specific geographic regions can restrict detection to known area codes, dramatically reducing false positives.
  • Include vs. Exclude list logic: With IncludePhoneRanges set to "Include List" (default), only numbers matching the specified area codes/exchanges are reported. Switching to an exclude list inverts the logic — all numbers are matched except those in the specified ranges.
  • International numbers: If your organization needs to detect non-US phone numbers, create a custom RegEx Data Type using the international telephone pattern. Be aware that US numbers with +1 will be duplicated across both detectors.
  • False-positive rate is generally lower than more ambiguous AnyFinds (like unformatted SSN) because phone numbers have a distinctive delimited structure. However, in datasets with many numeric sequences (serial numbers, order IDs), negative keywords can help filter noise.

United Kingdom National Insurance Numbers (NINO)

Spirion data type (AnyFind). This data type is provided by default.

  • National Insurance number is a unique identifier used in the United Kingdom to record your taxes and National Insurance contributions. It ensures these payments are credited to your personal record, which determines your eligibility for the State Pension and other benefits.
  • National Insurance Numbers can be used to open credit cards and bank accounts on your behalf, so searching for this Data Type is of critical importance to prevent identity theft.
  • Format: National Insurance numbers consist of 2 letters, 6 numbers, and a final letter (example: QQ 12 34 56 A).
  • Duration: The number stays the same for your entire life, even if you move abroad and return.
  • Not ID: While unique, National Insurance numbers are not a form of legal identification and does not prove your right to work in the UK. 
  • Employment: Employers require a National Insurance number to process payroll and deduct taxes correctly.
  • Government Benefits: Necessary to claim Universal Credit, Jobseeker’s Allowance, or maternity allowance.
  • Financial Services: A National Insurance number is required for opening an Individual Savings Account (ISA) or applying for a student loan.
  • Voting: Used to verify your identity when registering to vote. 
  • Automatic Issuance: UK residents are usually issued their National Insurance number automatically 3 months before their 16th birthday if their parents claimed Child Benefit for them.

United Kingdom National Health Service Numbers (NHS)

Spirion data type (AnyFind). This data type is provided by default.

  • The National Health Service (NHS) Number is a unique 10-digit identifier for individuals in England, Wales, and the Isle of Man, used to access healthcare;
  • Found on official letters, prescriptions, test results, or by contacting your GP or using the online service,
  • National Health Service Numbers are used in the United Kingdom and can be used to open credit cards and bank accounts on your behalf, so searching for this Data Type is of critical importance to prevent identity theft.

Here's a comprehensive definition of the Spirion AnyFind "United Kingdom: NHS" for v13.6.2, compiled from your internal documentation:


United Kingdom: NHS (National Health Service Number) AnyFind

  • Method: AnyFind (built-in detector)
  • Application: United Kingdom — England, Wales, and the Isle of Man
  • Default Ordinal Value: 100
  • Default Dollar Value: $165

Purpose

  • The NHS AnyFind discovers UK National Health Service Numbers in scanned data.
  • An NHS number is a unique 10-digit numeric identifier assigned to every individual registered with the NHS in England, Wales, and the Isle of Man.
  • It is used by healthcare staff and service providers to correctly identify patients and match them to their health records.
  • NHS numbers appear on prescriptions, test results, appointment letters, and other NHS correspondence.

Number Format & Validation

Property

Detail

Length

Exactly 10 numeric digits

Display Format

3 3 4 — three digits, three digits, four digits separated by spaces (e.g., 485 777 3456)

Structure

First 9 digits are the identifier; the 10th digit is a check digit used to confirm validity

Check Digit Algorithm

Modulus 11 weighted check — validates the 10th digit against the first 9

Characters

Numeric only — no alphabetical characters

How matching works:

  • The AnyFind scans for 10-digit numeric patterns that conform to the NHS number structure
  • The modulus 11 check digit validation is applied to eliminate candidates that don't pass algorithmic verification
  • Keyword requirement status is listed as "unknown" in the internationalization documentation — the NHS AnyFind does not expose keyword proximity settings, suggesting it relies on pattern + check digit validation rather than contextual keywords for accuracy

Configuration Settings

The NHS AnyFind has a notably minimal configuration surface compared to other AnyFinds (like SSN or Passport). There are no keyword proximity, custom delimiter, or trailing punctuation controls — only negative keywords for eliminating false positives.

Basic Settings

Setting

Default

Description

EnableAnyFind

Disabled

Master toggle — enable AnyFind searching for National Health Service Numbers (United Kingdom)

EnableOnlyFind

Disabled

Enable OnlyFind searching for National Health Service Numbers (United Kingdom) (Spirion-defined, not customer-configurable)

Advanced Settings

Setting

Default

Description

UseNegativeKeywords

Disabled

Use negative keywords to eliminate National Health Service Numbers (United Kingdom)

CustomNegativeKeywords

(empty)

Negative keywords for eliminating National Health Service Numbers (United Kingdom)

Why the Configuration Is So Minimal

The NHS AnyFind relies heavily on its algorithmic validation (modulus 11 check digit) to maintain accuracy, which significantly reduces the need for keyword-based or format-based tuning controls that other AnyFinds require. The 10-digit length combined with the check digit algorithm is sufficiently distinctive to produce reliable matches without requiring contextual keyword proximity. The only customer-facing tuning control is negative keywords — useful for eliminating false positives in environments where other 10-digit numeric identifiers exist.

Category

In the Spirion agent architecture, the NHS AnyFind is classified under "Worldwide Types" alongside:

  • Canada: SIN (Social Insurance Number)
  • United Kingdom: NINO (National Insurance Number)
  • Australia: TFN (Tax File Number)

These are separate from the US-focused core AnyFinds (SSN, CCN, etc.) and represent Spirion's international sensitive data detection capabilities. Agent Functional Areas

How It Fits Into the Platform

  • Can be used standalone in playbook decision logic (e.g., IF Data Type = United Kingdom: NHS)
  • Can be combined with other AnyFinds or custom Data Types in Sensitive Data Definitions (SDDs) for context-aware detection
  • Results are reported to the console under the National Health Service Number (United Kingdom) match type
  • The internal match type key is united_kingdom_nhs
  • When used in Subject Request workflows (Compliance Manager), the value must be entered in 10-digit numeric format and is displayed as XXX XXX XXXX

Best Practice Notes

  • Enabling is straightforward. Because the NHS AnyFind has minimal tuning controls and relies on algorithmic validation, enabling it is lower-risk than enabling more ambiguous AnyFinds (like unformatted SSN or Bank Account). Toggle EnableAnyFind on and it will begin detecting valid NHS numbers.
  • Negative keywords are the primary lever for reducing false positives. In environments with other 10-digit numeric identifiers (phone numbers, account numbers), configuring negative keywords can help suppress unwanted matches.
  • GDPR relevance. NHS numbers are classified as health-related personal data under GDPR and the UK Data Protection Act 2018, making their detection and remediation a compliance priority for UK-facing organizations.