Table 2.
Health Insurance Portability and Accountability Act of 1996 administrative rule specifications (privacy rule and security rule) and submitted HealthChain components supporting compliance.
| Specification | Rule: 45 CFRa section 164 | HealthChain |
| Authorization and revocation (PRb) | 508, 510 | Smart contracts, sign and verify, and encrypt-sign and decrypt-verify: confidential communications and verifiable requests and authorizations |
| Restriction requests (PR) | 522(a)(1) | Smart contracts, sign and verify, and encrypt-sign and decrypt-verify: confidential communications and verifiable requests and authorizations |
| Amendments (PR) | 526 | Smart contracts, sign and verify, and encrypt-sign and decrypt-verify: confidential communications and verifiable requests and authorizations |
| Confidential communications (PR) | 522(b)(2) | Encrypt-sign and decrypt-verify: message integrity, verifiable identity, and encryption |
| Unique user authentication (SRc) | 312(a)(2)(i) | Unique encryption and hashing key pairs, sign and verify, and encrypt-sign and decrypt-verify: verifiable identity (key possession and signing) and patient block hashes and patient block encryption |
| Encryption and decryption (SR) | 312(a)(2)(iv) | Unique encryption and hashing key pairs, sign and verify, and encrypt-sign and decrypt-verify: verifiable identity (key possession and signing) and patient block hashes and patient block encryption |
| Integrity (SR) | 312(c)(1) | Unique encryption and hashing key pairs, sign and verify, and encrypt-sign and decrypt-verify: verifiable identity (key possession and signing) and patient block hashes and patient block encryption |
| Audit controls (SR) | 312(b) | Log blocks |
| Person or entity authentication (SR) | 312(d) | Sign and verify, encrypt-sign and decrypt-verify, re-encryption key layering, and delegatee re-encryption: verifiable identity (verification algorithms and construction of the delegatee re-encryption process) |
| Transmission security—integrity controls and encryption (SR) | 312(e)(1), (2)(i), and (2)(ii) | Patient block encryption, intermediary re-encryption, sign and verify, and encrypt-sign and decrypt-verify (layering): verifiable identity and transfer of encrypted data only by design |
aCFR: 45: Code of Federal Regulations.
bPR: privacy rule.
cSR: security rule.