The Secretary says in the proposed rule that "and ensuring
encryption keys are not breached, we clarify that covered entities and business associates should keep encryption keys on a separate device from the data that they encrypt or decrypt". You need to change "should" to "must". Storing keys along with the encrypted media is effectively the same as not using encryption.
Comment on FR Doc # E9-20169
This is comment on Rule
Breach Notification for Unsecured Protected Health Information
View Comment
Related Comments
View AllPublic Submission Posted: 08/25/2009 ID: HHS-OCR-2009-0010-0002
Oct 23,2009 11:59 PM ET
Public Submission Posted: 08/25/2009 ID: HHS-OCR-2009-0010-0003
Oct 23,2009 11:59 PM ET
Public Submission Posted: 08/26/2009 ID: HHS-OCR-2009-0010-0004
Oct 23,2009 11:59 PM ET
Public Submission Posted: 08/26/2009 ID: HHS-OCR-2009-0010-0005
Oct 23,2009 11:59 PM ET
Public Submission Posted: 08/31/2009 ID: HHS-OCR-2009-0010-0008
Oct 23,2009 11:59 PM ET