What exactly is an "internal audit" and how can it be determined that the SSNs weren't "accessed" by anyone? Once something is on the web, I assumed it was accessible. What am I missing??? Also, since these were people from 7 years ago, can we assume many have moved and USM is getting the so called "letters of notification" returned to sender?? Still can't quite understand how ANYONE (unless a workstudy??) would have posted SSNs anywhere let alone the web.
An audit of what was looked at is very possible. Web servers keeps logs of everything that is accessed. The ip address (and other info) is logged for every page, picture, script, ect. It is quite simple (for a system administrator) to go through the logs and see if anyone has looked at a certain web page and if so, who was looking at it (at least where the people are from).
If you have a personal web page, there are many free scripts that you can download that will give you exactly this type of information. It can tell you if people from Australia or Austria are looking at your page, or if someone is still using Windows 3.1, even what screen resolutions people have their monitor set at.