I would disagree. First, passwd(5) is a venerable and rigidly-defined format. Can we please stop abusing poor GECOS for everything?
Second, storing PII in a world-readable file is unacceptable. Linux is multi-user so the administration needs to be responsible about sensitive data like that! Find somewhere else to stash it!