The HR department at the company that I am currently working for has requested that I provide a system for storing employee social security numbers in our company database. The
Social Security numbers fall under "PII" (Personally Identifiable Information)... and you should encrypt them, but it's not required. So, yes AES is perfectly fine... really, anything you do is a plus.
Credit Card numbers fall under "PCI" (Payment Card Industry) compliance, and that is a mess. But in your case, you're ok.
BTW: AES 128 is considered perfectly good enough for Visa, Amex, Discover, etc (PCI).