{"id":29101,"date":"2015-02-08T14:43:44","date_gmt":"2015-02-08T19:43:44","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/lack-of-encryption-standards-raises-health-data-privacy-questions.php"},"modified":"2015-02-08T14:43:44","modified_gmt":"2015-02-08T19:43:44","slug":"lack-of-encryption-standards-raises-health-data-privacy-questions","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/lack-of-encryption-standards-raises-health-data-privacy-questions.php","title":{"rendered":"Lack of encryption standards raises health data privacy questions"},"content":{"rendered":"<p><p>      The office building of health insurer Anthem is seen in Los      Angeles, California February 5, 2015. This week, a data      breach at Anthem compromised the data of 80 million people,      prompting calls for cybersecurity standards for health care      companies. Photo by Gus Ruelas\/Reuters    <\/p>\n<p>    WASHINGTON  Insurers arent required to encrypt consumers    data under a 1990s federal law that remains the foundation for    health care privacy in the Internet age  an omission that    seems striking in light of the major cyberattack against    Anthem.  <\/p>\n<p>    Encryption uses mathematical formulas to scramble data,    converting sensitive details coveted by intruders into    gibberish. Anthem, the second-largest U.S. health insurer, has    said the data stolen from a company database that stored    information on 80 million people was not encrypted.  <\/p>\n<p>    The main federal health privacy law  the Health Insurance    Portability and Accountability Act, or HIPAA  encourages    encryption, but doesnt require it.  <\/p>\n<p>    The lack of a clear encryption standard undermines public    confidence, some experts say, even as the government plows    ahead to spread the use of computerized medical records and    promote electronic information sharing among hospitals, doctors    and insurers.  <\/p>\n<p>    We need a whole new look at HIPAA, said David Kibbe, CEO of    DirectTrust, a nonprofit working to create a national framework    for secure electronic exchange of personal health information.  <\/p>\n<p>    Any identifying information relevant to a patient  should be    encrypted, said Kibbe. It should make no difference, he says,    whether that information is being transmitted on the Internet    or sitting in a company database, as was the case with Anthem.  <\/p>\n<p>    Late Friday, the Senate Health, Education, Labor and Pensions    committee said its planning to examine encryption requirements    as part of a bipartisan review of health information security.    We will consider whether there are ways to strengthen current    protections, said Jim Jeffries, spokesman for chairman Lamar    Alexander, R-Tenn.  <\/p>\n<p>    The agency charged with enforcing the privacy rules is a small    unit of the federal Health and Human Services Department,    called the Office for Civil Rights.  <\/p>\n<p>    The office said in a statement Friday that it has yet to    receive formal notification of the hack from Anthem, but    nonetheless is treating the case as a privacy law matter.    Although Anthem alerted mainline law enforcement agencies, the    law allows 60 days for notifying HHS.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Go here to read the rest:<br \/>\n<a target=\"_blank\" href=\"http:\/\/www.pbs.org\/newshour\/rundown\/lack-health-care-cyber-security-standards-raises-questions\" title=\"Lack of encryption standards raises health data privacy questions\">Lack of encryption standards raises health data privacy questions<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The office building of health insurer Anthem is seen in Los Angeles, California February 5, 2015. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-29101","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/29101"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=29101"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/29101\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=29101"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=29101"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=29101"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}