Cross-posted from Bill of Health

Given the increasing numbers of health data breaches, including this week’s announcement from Anthem (potentially exposing 80m records, mine included) a brief review of the subject may be appropriate.

At the federal level both the Security Rule and the Breach Notification Rule are in play. In large part the Security Rule requires covered entities and their business associates to base their security precautions on risk assessment. Required precautions include administrative, physical, and technical safeguards. Many of these are required, for example unique user identities for access and tracking. Some precautions, however, are only “addressable.”

This latter is the case with data encryption, defined in the Security Rule as “the use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a confidential process or key.” In practical terms data may need to be encrypted end-to-end (during transmittal) or while stored (at rest). Being only ‘addressable,’ the question whether to encrypt stored data depends on the data custodian’s assessment whether that technology “is a reasonable and appropriate safeguard in its environment, when analyzed with reference to the likely contribution to protecting electronic protected health information.” If the risk assessment goes against encryption that decision must be documented and a reasonable and appropriate alternative safeguard implemented.