The Health Insurance Portability and Accountability Act (HIPAA) has been around for many years with the main purpose of governing the use and disclosure of individuals’ health information. The recent dramatic trend of healthcare-driven companies to migrate to cloud computing requires a cloud-specific security approach for HIPAA and the cloud. In this article, I will touch on some of the major HIPAA requirements as they relate to the cloud, and will highlight points to consider when securing patient data in the cloud.
HIPAA cloud requirement #1: Access control
According to HIPAA, a covered entity must implement technical policies and procedures that allow only authorized persons to access electronic protected health information – this is highly relevant for HIPAA and the cloud. Once operating within the cloud, healthcare data can be potentially accessed from within the cloud by a snooping employee (one of many examples of possible breaches). To adhere to this requirement in cloud environments, address the following points:
A. Automate:
Make sure your cloud key management system [which manages the cryptographic keys in an encryption system] can be automated so that administrators cannot access or see key values used for encrypting healthcare data.
Read more ›



