Help Me With HIPAA

Episode 23: If it moves - encrypt it.


Listen Later

Description

We explained the concepts of encryption in Episode 2: Let’s Talk Encryption but people continue to ask more about what they really need to do with encryption.

Links

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Episode 2: Let’s Talk Encryption

The government and privacy advocates can’t agree on what ‘strong’ encryption even means

Notes

First, what can encryption do for you and what it can't do for you.

  1. VPN, HTTPS, SSL, SFTP, etc. Protect communications from prying eyes.
  2. Everything else is about encrypting data on the devices themselves.

If you encrypt data on a device but you are hacked when you are logged into the device, encryption isn't too helpful. Encryption is helpful when someone tries to access the data on the device without your key (or password).

Strong Encryption is also subjective - there is no solid authority on what is really strong encryption because law enforcement wants a back door.

What does HIPAA say about encryption? Encryption (Addressable). Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.

Not very helpful.......

What does OCR say about it? At NIST / OCR HIPAA 2015 conference: If it moves it should be encrypted.

Now that's a line that can be drawn.

  • Encryption of your files stored in the cloud (certainly something that moves)
  • File encryption by an app on the computer over specific files like 7Zip
  • Windows built in encryption - Bitlocker, EFS
  • NAS and Flash drives with built-in encryption
  • Encryption on your phone built-in
  • Cloud based encryption management - MDM - Alertboot, MaaS360, Manage Engine https://www.manageengine.com/mobile-device-management/

Create an encryption plan:

  • Includes all devices - laptops, phones, external drives, etc.
  • Specs required like AES 128 or FIPS should be written down
  • Methods used for implementation on all types of devices
  • Encryption key management plan
  • Audits and verification plans
...more
View all episodesView all episodes
Download on the App Store

Help Me With HIPAABy Donna Grindle and David Sims

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

61 ratings


More shows like Help Me With HIPAA

View all
The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

228,777 Listeners

The Ben Shapiro Show by The Daily Wire

The Ben Shapiro Show

153,461 Listeners

REAL AF with Andy Frisella by Andy Frisella

REAL AF with Andy Frisella

386 Listeners

The Sporkful by Dan Pashman

The Sporkful

3,945 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,020 Listeners

In The Dark by The New Yorker

In The Dark

28,355 Listeners

Pod Save America by Crooked Media

Pod Save America

87,160 Listeners

The Daily by The New York Times

The Daily

112,027 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

This Podcast Will Kill You by Exactly Right and iHeartPodcasts

This Podcast Will Kill You

16,951 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

All-In with Chamath, Jason, Sacks & Friedberg

9,946 Listeners

The MeidasTouch Podcast by MeidasTouch Network

The MeidasTouch Podcast

50,210 Listeners

SmartLess by Jason Bateman, Sean Hayes, Will Arnett

SmartLess

57,836 Listeners

The Tucker Carlson Show by Tucker Carlson Network

The Tucker Carlson Show

16,924 Listeners