Compliance with HIPAA security regulations

Identifying and de-identifying health information (PHI) in any source

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is now routinely enforced nationwide, and the consequences of breaches involving protected health information (PHI) remain consistent and damaging. If you are a HIPAA-covered entity, what steps are you and your business partners taking to ensure HIPAA compliance when it comes to protecting PHI?
The pages in this section of our website provide an in-depth look at the key U.S. healthcare data security regulations and explain how you can comply with them (and demonstrate your compliance). If you would like more information or need assistance, please contact us to learn how we have helped others and how we can help you.
PHI, which is the HIPAA Safe Harbor-Data subject to the security policy must be encrypted or hashed using an 18-key hash function (direct, unique identifiers) in accordance with 45 CFR 164.312 and 170.210. The IRI software supports this requirement with its HIPAA data masking tools and the numerous PHI-Concealment functions.
In particular, the built-in data detection, classification, and masking features in the IRI FieldShield-, DarkShield– and CellShield-products or the IRI Voracity platform The solutions they offer help you automatically identify, catalog, and de-identify PHI in both structured and unstructured data sources. These sources (whether on your local network or in your cloud infrastructure) include relational and NoSQL databases, flat files, Excel, PDF, and Word documents, PowerPoint presentations, HL7, X12, and FHIR EDI files, DICOM studies, and other image file formats.
Alternatively, the HIPAA Expert Determination Method Rule compliance through certified reduction of the re-identification risk. The technology integrated into the IRI data masking software for assessing the Re-identification risk and Anonymization measures this risk statistically and anonymizes quasi-identifiers to comply with this regulation as well.



IRI can also provide professional services and refer you to experienced statisticians, HIPAA consultants, and regulatory attorneys with whom we collaborate. You can leverage these tools and teams as needed to obtain compliance certification and cybersecurity insurance, and to defend yourself against fines or claims related to violations. View our free course details below.

De-identification refers to processes that remove personally identifiable information (PII) from protected health information (PHI) and other "sensitive data.".

PHI de-identification is a specific requirement in Healthcare, where they for example are included in both the „Safe Harbor“ and the „Expert Determination Methodology“used in medical research (to remove patient identities from study data). De-identification is also a general term for the anonymization or masking of PII in many other industries.”.

The latest Safety Rules in the HIPAA-Regulations (45 CFR Parts 160 and 164) establish the compliance requirements for organizations that handle PHI. The HIPAA rules apply to 18 specific identifiers:

Name

Address

Date of birth

Phone number

Fax number

Email Address

Social security number

Medical Record

Health insurance policyholder

Account number

Certificates

Auto-ID

Device ID

Personal URL

IP Address

Biometric ID

Face

Another unique ID code

Each of the data masking software products in the IRI Data Protection Suite helps you with PII, PAN, PHI, etc. in multiple data sources to find, to classify and then to protect, to ensure compliance with Safe Harbor rules. They also work hand-in-hand with a free, advanced re-ID Risk Assessment Technology to comply with the rule of the expert determination method. For more information on what PHI is, see in this article I am the HIPAA Journal.

  HIPAA compliance requires both:

  Editorial – Safe Haven

Manipulation, masking, or removal of these key identifiers, making it difficult or impossible to identify a person or recover the original data.

  De-identification – Expert Determination Method

The removal of identifiers and the generalization of quasi-identifiers until an expert determines the statistical risk of re-identification is very low.

Here Learn about our three-hour online HIPAA compliance course that covers de-identification of PHI and masking of structured, semi-structured, and unstructured data sources on-premises and in the cloud, as well as re-ID risk assessment processes for structured data. The course also includes information on regulatory compliance certification, data breach insurance, and defending against data breach claims.