Table 1 has PHI and it's encrypted. Table 2 doesn't have PHI, isn't encrypted and has a foreign key to Table 1.
I'd like to recommend the strongest security. If there's a requirement in HIPAA, it's not optional and must be done. If it's part of a standards body like ISO/IEC 27001 then it will need to be done for compliance to that standard. If it's a best a practice, it would be ideal but difficult to persuade for a best practice vs the performance impact.
1) Does HIPAA have any requirements for the foreign key to Table 1 in Table 2?
2) Is there a standard like ISO/IEC 27001 that has a requirement for the foreign key to Table 1 in Table 2?
3) Is there a best practice or anything similar that covers the foreign key to Table 1 in Table 2?
Aucun commentaire:
Enregistrer un commentaire