zlacker

[parent] [thread] 0 comments
1. junon+(OP)[view] [source] 2020-06-02 13:12:12
> In the process I have found that even HIPAA is not a protocol, it is a largely unspecific set of guidelines for how patient data should be stored and transmitted.

Former HIPAA security officer here; to be abundandly clear, there _are_ very specific guidelines for which information must be anonymized.

I don't think you were saying the alternative, just sounded a little like "anything goes" which is definitely not the case.

As for your point about guidelines, that's entirely true - last time I read the section about encryption, it just specified "state of the art encryption" which is... a poor way to specify that.

[go to top]