Skip to main content
. 2019 Aug 31;21(8):e13592. doi: 10.2196/13592

Table 2.

Health Insurance Portability and Accountability Act of 1996 administrative rule specifications (privacy rule and security rule) and submitted HealthChain components supporting compliance.

Specification Rule: 45 CFRa section 164 HealthChain
Authorization and revocation (PRb) 508, 510 Smart contracts, sign and verify, and encrypt-sign and decrypt-verify: confidential communications and verifiable requests and authorizations
Restriction requests (PR) 522(a)(1) Smart contracts, sign and verify, and encrypt-sign and decrypt-verify: confidential communications and verifiable requests and authorizations
Amendments (PR) 526 Smart contracts, sign and verify, and encrypt-sign and decrypt-verify: confidential communications and verifiable requests and authorizations
Confidential communications (PR) 522(b)(2) Encrypt-sign and decrypt-verify: message integrity, verifiable identity, and encryption
Unique user authentication (SRc) 312(a)(2)(i) Unique encryption and hashing key pairs, sign and verify, and encrypt-sign and decrypt-verify: verifiable identity (key possession and signing) and patient block hashes and patient block encryption
Encryption and decryption (SR) 312(a)(2)(iv) Unique encryption and hashing key pairs, sign and verify, and encrypt-sign and decrypt-verify: verifiable identity (key possession and signing) and patient block hashes and patient block encryption
Integrity (SR) 312(c)(1) Unique encryption and hashing key pairs, sign and verify, and encrypt-sign and decrypt-verify: verifiable identity (key possession and signing) and patient block hashes and patient block encryption
Audit controls (SR) 312(b) Log blocks
Person or entity authentication (SR) 312(d) Sign and verify, encrypt-sign and decrypt-verify, re-encryption key layering, and delegatee re-encryption: verifiable identity (verification algorithms and construction of the delegatee re-encryption process)
Transmission security—integrity controls and encryption (SR) 312(e)(1), (2)(i), and (2)(ii) Patient block encryption, intermediary re-encryption, sign and verify, and encrypt-sign and decrypt-verify (layering): verifiable identity and transfer of encrypted data only by design

aCFR: 45: Code of Federal Regulations.

bPR: privacy rule.

cSR: security rule.