3 ms·
Although at-rest encryption of health data is an addressable part of US health regulations, not a required one, it's almost always done because it's easy and ef
by sterwill 8y ago
Although at-rest encryption of health data is an addressable part of US health regulations, not a required one, it's almost always done because it's easy and effective. Most electronic health records are encrypted at-rest.
- specialist 8y agoI should have been more clear. I'm advocating Translucent Database techniques, where patient data is encrypted at the field and row (document) level. Much like a salted password file. System level encryption still means the admins can still see the data. Therefore, breaches remain inevitable.