Skip to main content

#PHI0 人がディスカッション中

Thanks to some help I think I got a grips on HIPAA. Let me know what you think.

 

HIPAA:

Relevant for all data which is PHI & PII: Example: Johann (PII) has a broken leg (PHI).

 

PII: Personally identifiable Information

PHI: Protected Health information

 

PHI relevant data has to be:

  1. Encrypted at rest
  2. Secured in transit
  3. Only accessed by people needing to access the data 

 

Implications:

1. Encrypted at rest:

PHI data needs to be encrypted at rest in all stages and systems.

  • Salesforce:
    • Shield Platform Encryption in SF
      • Not for Big Object / External Object
    • SF Standard field encryption -> Small number of PHI
      • Only certain custom fields
      • Not files
      • Can’t bring your own key
  • Privacy Shield in Heroku
  • DWH needs to be HIPAA compliant
  • Shield for Einstein Analytics, not available for EA plus

2. Secured in transit:

  • Mutual SSL on integrations (e.g. SF to ESB)
  • NOT: Emails (Cannot be encrypted unless specialized tool like Data Motion)
    • Ask cust. to log-in. 

3. Only accessed by people needing to access the data

-> Everything private, only open up what's needed

 

Other implications:

  • Data masking in full copy sandbox needed to protect data from testers .
  • Anonymized/dummy data in Dev Sandboxes
  • Anonymized (global) reporting if necessary/possible
4 件のコメント
  1. 2021年12月1日 19:09

    @Johann Furmann- My biggest concern with HIPAA as an admin is standard fields that need to be "private".  Specifically, Account Name, phone, email.  Do I need to change the ACCOUNT Name (using person Accounts) - to something other than the persons first name / last name? Do you create Custom Fields for each of these standard fields that are used across different record types to keep users from being able to see that data?

0/9000

Upcoming Webinar: Salesforce Multi-Org for Architects - Data Privacy & Security (Register Here)

 

2+ Salesforce Orgs is common in medium-large companies these days, And that brings its own sets of challenges ranging from Delivery, Change Management to Data privacy & security Your #PII, #PHI, #PCI and other sensitive data, With diverse regulations and business policies, Require a re-think of how to manage it securely, That rethinking, STARTS HERE! 

 

Upcoming Webinar: Salesforce Multi-Org for Architects - Data Privacy & Security (Register Here) 2+ Salesforce Orgs is common in medium-large companies these days, And that brings its own sets of chall

0/9000

Upcoming Webinar: Salesforce Multi-Org for Architects - Data Privacy & Security (Register Here)

 

2+ Salesforce Orgs is common in medium-large companies these days, And that brings its own sets of challenges ranging from Delivery, Change Management to Data privacy & security Your #PII, #PHI, #PCI and other sensitive data, With diverse regulations and business policies, Require a re-think of how to manage it securely, That rethinking, STARTS HERE! 

Upcoming Webinar: Salesforce Multi-Org for Architects - Data Privacy & Security (Register Here) 2+ Salesforce Orgs is common in medium-large companies these days, And that brings its own sets of chall

 

 Join our webinar - 𝐒𝐚𝐥𝐞𝐬𝐟𝐨𝐫𝐜𝐞 𝐌𝐮𝐥𝐭𝐢-𝐎𝐫𝐠 𝐟𝐨𝐫 𝐀𝐫𝐜𝐡𝐢𝐭𝐞𝐜𝐭𝐬 - 𝐃𝐚𝐭𝐚 𝐏𝐫𝐢𝐯𝐚𝐜𝐲 & 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲

 

#Data Security #Data Privacy #Salesforce Architect #Compliance #GDPR #CCPA #Data Management

0/9000

I am building a PHI user profile for our Salesforce instance. 

 

This user profile should block visibility based on the 18 identifiers that make health information PHI:

  • Names

  • Dates, except year

  • Telephone numbers

  • Geographic data

  • FAX numbers

  • Social Security numbers

  • Email addresses

  • Medical record numbers

  • Account numbers

  • Health plan beneficiary numbers

  • Certificate/license numbers

  • Vehicle identifiers and serial numbers including license plates

  • Web URLs

  • Device identifiers and serial numbers

  • Internet protocol addresses

  • Full face photos and comparable images

  • Biometric identifiers (i.e. retinal scan, fingerprints)

  • Any unique identifying number or code

 

How have others set up PHI compliant profiles?

 

Looking for advice.

2 件のコメント
0/9000

I am building a PHI user profile for our Salesforce instance. 

 

This user profile should block visibility based on the 18 identifiers that make health information PHI:

  • Names

  • Dates, except year

  • Telephone numbers

  • Geographic data

  • FAX numbers

  • Social Security numbers

  • Email addresses

  • Medical record numbers

  • Account numbers

  • Health plan beneficiary numbers

  • Certificate/license numbers

  • Vehicle identifiers and serial numbers including license plates

  • Web URLs

  • Device identifiers and serial numbers

  • Internet protocol addresses

  • Full face photos and comparable images

  • Biometric identifiers (i.e. retinal scan, fingerprints)

  • Any unique identifying number or code

 

How have others set up PHI compliant profiles?

 

Looking for advice.

0/9000