Re: SQL Server 2005, HIPAA and File Encryption



Hello Jubal,

I have an application with uses SQL Server 2005 for data storage and a
customer is asking me if we encrypt our stored data to comply with
HIPAA. I can find almost no information about addressing this
requirement for systems using SQL Server 2005 so I'm wondering how
vendors are handling this aspect of HIPAA. Or is my customer
misinterpreting the requirement? The database server is stored in a
data center and is not accessible from the Internet (of course) so
encrypting the files seems to be of little, if any value.

The question to ask in case like this is "what does your HIPAA compliance officer define the requirement as."

Yes, there are probably things you want to take steps to assure access to, but since I'm not a lawyer, it is absolutely best to talk your client's experts on the topic.

Thanks!
Kent Tegels
DevelopMentor
http://staff.develop.com/ktegels/


.



Relevant Pages

  • SQL Server 2005, HIPAA and File Encryption
    ... customer is asking me if we encrypt our stored data to comply with HIPAA. ... using SQL Server 2005 so I'm wondering how vendors are handling this aspect ...
    (microsoft.public.sqlserver.security)
  • Re: E-mail, S/MIME, Digital Signatures & Encryption - HELP!
    ... The software is required to digitally sign and encrypt ... (And I wonder what your customer ... Safe handling of keys - and knowing which key belongs ...
    (comp.security.misc)
  • Re: E-mail, S/MIME, Digital Signatures & Encryption - HELP!
    ... The software is required to digitally sign and encrypt ... (And I wonder what your customer ... Safe handling of keys - and knowing which key belongs ...
    (comp.security.unix)
  • Re: Web.config encryption in shared hosting scenario
    ... I just begin to search for a solution because the customer does not allow ... like to encrypt the database connection string located in the web.config. ... I am connecting to the SQL ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Search feature in an encrypted database
    ... form my program has to show to authenticated users some sort of information ... and to let them perform search to the stored data. ... When I need to validate a user I encrypt his typed username and password and ... a matching sting in the database but in a search where the criteria are just ...
    (microsoft.public.dotnet.security)