"Safe Harbour" Anonymization
De-identification through obfuscation
PHI and more obfuscation
Do you need to process or mask Protected Health Information (PHI) or other Personally Identifiable Information (PII)? And can you do so in a way that:
- secure from hacking or bypass (collecting information from other data)?
- maintains the original column and field layouts (position, size, data type)?
- that makes the anonymized data look real enough for testing purposes?
- comfortable, easy, efficient, and affordable is?
- will meet the HIPAA Safe Harbor rule?
With IRI FieldShield Can you easily classify, find, and remove or otherwise de-identify key identifiers (and quasi-identifiers) in database columns and fields in structured and JSON files. With IRI CellShield Can you do the same in Excel 2010 and newer spreadsheets. And with IRI DarkShield Can you do the same for PHI in unstructured files like HL7 and X12, PDF and Word, Excel and PowerPoint, as well as in image files (including burned-in PHI in DICOM formats)? All of these data masking products are part of IRI Data Protector Suite or free in the IRI Voracity Data Management Platform included.
The de-identification/obfuscation method you chose/Masking from data determines the appearance of the masked results and the probability of restoring the original values. In this article You can find advice on which data masking function to use.
45 CFR 164.312, Technical Safeguards
Implementation of technical guidelines and procedures to restrict ePHI access to „persons or software programs to whom access rights have been granted“. These systems must enable unique user identification, emergency access, automatic logout, and encryption/decryption.
With the column/field layer, you can multiple Encryption libraries and Key Use (passphrases) for field-specific, noteworthy decryption claims.
* Transmission security, including two addressable specifications:
- Integrity checks—security measures to ensure that electronically transmitted PHI is not improperly altered without detection until disposal, and.
- Encryption – Designating encryption as an addressable specification is a significant departure from the proposed rule, which explicitly required encryption when using open networks. Covered entities must now determine how they can protect EPHI „in a manner that is appropriate to the risk posed by the unauthorized access, use, or disclosure of the electronic PHI“.
FieldShield makes the Encryption to another option for field-level protection in tables and files, along with filtering, anonymization, and pseudonymization, while CellShield does the same in Excel. The CoSort SortCL program or various Hadoop masking engines, which on the Voracity platform interchangeable are used, they are also used and even when performing extensive manipulations and reports against massive Data sources.
* Hardware, software, and/or methods for performing audit checks
Optional application statistics and a queryable XMLAudit log document the job script and encryption libraries, showing what, when, how, and by whom the PHI field data was encrypted (and otherwise protected and/or transformed).
Guidelines and procedures for safeguarding EPHI from improper alteration or destruction to ensure data integrity. This integrity standard is coupled with an addressable implementation specification for a mechanism to confirm that EPHI has not been improperly altered or destroyed.
Data that is not decrypted with the correct encryption code indicates that the decrypted field has been corrupted. You can do this through runtime statistics and Audit logs understand, which the IRI software automatically creates. You can see when and how each field was changed.
* Authentication of an individual or legal entity, requiring the covered entity to implement procedures that ensure that a person or legal entity requesting access to EPHI is the one they claim to be.
IRI software users can a number of role-based access controls for data sources and executable files.