CREATE TABLE #myTable( num int, name varchar(max) ) CREATE TABLE #protectedData( ssn varchar(max) ) INSERT INTO #myTable (num, name) VALUES (1, 'Foo') INSERT INTO #protectedData (ssn) VALUES('xxx-xx-xxxx') SELECT * FROM #myTable SELECT * FROM #protectedData --Your intended query. The user tyes foo SELECT * FROM #myTable WHERE name = 'foo' Result: --Now instead of foo the user types ' SELECT * FROM #protectedData -- SELECT * FROM #myTable WHERE name = 'foo ' SELECT * FROM #protectedData--' A much scarier result: