3 ms·
Interesting that they mention medical records. I'm pretty sure that US HIPAA law would preclude storing any medical records from being stored on a network whose
by ph33t 9y ago
Interesting that they mention medical records. I'm pretty sure that US HIPAA law would preclude storing any medical records from being stored on a network whose owner you don't have a BA with. From my readings (see Digital Ocean's various discussions on the topic) this even includes data that is chunked and encrypted before sending off to storage. HIPAA laws are woefully vague and inadequate to deal with many new technologies. I'm not trying to argue for or against storing PHI in this matter, just pointing that they reference it, but I'm not sure it could be implemented in the US and be in compliance with current laws.
- tlrobinson 9y agoThought experiment: if I were to take some medical records and XOR it with a one-time pad, then stored the result somewhere not HIPAA compliant, would that be illegal? How about if instead I stored the one-time pad somewhere not HIPAA compliant? It would seem a little strange if one were illegal but not the other.
- dcdanko 9y agoBoth would be illegal* since your keys are info that could deanonymize patient data. However, you would be allowed to store them on your own PC if you follow proper procedures. This is more important than it might seem from a purely tech perspective. HIPAA is partly designed to guard against 1) improper use of encryption 2) downstream contractors who are malicious or careless The one-time pad is probably fine but it's easy to imagine lesser encryption being broken (especially by bugs). This problem gets much worse once PHI is stored on a medium, like a blockchain, where it can never be taken down. After all you probably wouldn't be happy if your health data was on the internet protected only by SHA1. There are probably better solutions to all of these issues but HIPAA is intentionally conservative. In many respects HIPAA is a financial, not a technical, law. * HIPAA doesn't make improper storage illegal in the sense that you go to jail if you do it wrong. It exposes people who handle data improperly to massive fines, usually when actual breaches occur. This is part of why BAAs are so important.
- dragonwriter 9y ago> I'm pretty sure that US HIPAA law would preclude storing any medical records from being stored on a network whose owner you don't have a BA with. From my readings (see Digital Ocean's various discussions on the topic) this even includes data that is chunked and encrypted before sending off to storage. That's not clear. AFAICT, HIPAA and the security rules adopted under it would not do so, unless one were to interpret receiving, storing, and transmitting encrypted data without the key as equivalent to maintaining (etc.) the source data, which then would make transmitting encrypted PHI over the public internet without BAAs with the infrastructure providers at every network hop a violation of HIPAA.