Chuyển đến nội dung chính

Lesson 1: Healthcare System Overview & Security Requirements — HIPAA, HL7 FHIR

Learn an overview of medical data security: PHI/ePHI concept, international standards HIPAA (Privacy Rule, Security Rule, Breach Notification), HL7 FHIR Security, GDPR for health data, Vietnam Cyber ​​Security Law 2018, Decree 13/2023 on personal data protection, and security frameworks NIST Cybersecurity Framework, ISO 27799 for healthcare.

🏗️ Architecture — Lesson 1 Lesson 1: Overview of Healthcare System & Requirements Security — HIPAA, HL7 FHIR

Building a Microservices Healthcare System — Quarkus, PostgreSQL, Keycloak with HIPAA standards

Part 1: Architecture & Platform

xdev.asia

1. Why is Medical Data Security important?

HIPAA Technical Safeguards Overview — 5 categories of technical security controls

Medical data is one of the most sensitive types of data. A medical record contains personal information, medical history, test results, prescriptions, and insurance information — all of which are highly valuable on the black market.

Worrying statistics

  • Value of medical data: On the dark web, a medical record costs from $250-$1,000, 10-40 times more than credit card information ($5-$25)
  • Average cost of a breach in healthcare: $10.93 million USD (2023, IBM Cost of a Data Breach Report) — highest in any industry
  • Frequency of attacks: 89% of healthcare organizations have experienced data breaches in the last 2 years
  • Detection time: Average 329 days to detect and control a medical breach

Why is medical data an attractive target?

FeaturesReason
Cannot be changedUnlike a credit card, you cannot "cancel" and reissue your medical history
Long-term valueMedical data is valuable for the patient's lifetime
Multi-purposeCan be used for identity theft, insurance fraud, prescription fraud
Legacy systemMany hospitals use old, insecure systems
Operating pressureHospitals must operate 24/7, making it difficult to "shutdown" to patch errors

2. What is Protected Health Information (PHI)?

2.1. Definition of PHI

Protected Health Information (PHI) is any information related to:

  1. Health status (past, present, or future) of an individual
  2. The provision of medical services to an individual
  3. Payment for medical services

AND can identify that individual.

2.2. 18 HIPAA Identifiers

HIPAA identifies 18 types of identifiable information that need to be protected:

#IdentifiersExample
1NameNguyen Van A
2Address (more detailed than province/city)123 Nguyen Hue, District 1, Ho Chi Minh City
3Date (except year) relatedDate of birth, date of admission, date of discharge
4Phone number0901234567
5Fax number(028) 1234567
6Email[email protected]
7Social insurance/health insurance numberHC4012345678
8Medical record numberMRN-2026-001234
9Insurance beneficiary numberBH-2026-5678
10Account number1234567890
11License/certificate numberCCCD: 001234567890
12License plate51A-12345
13Device serial numberPacemaker SN: ABC123
14URLspatient-portal.hospital.vn/patient/123
15IP address192.168.1.100
16Biometric identifiersFingerprint, face
17Portrait photosPatient photo
18Any unique identifierInternal patient code

2.3. Electronic PHI (ePHI)

ePHI is PHI that is created, stored, transmitted, or received electronically. In a microservices system, most PHI exists as ePHI:

  • Data in PostgreSQL databases
  • API requests/responses contains patient information
  • Messages in Kafka topics
  • Cache entries in Redis
  • Log files contain patient identifiers
  • Backup files

3. HIPAA - US Health Information Privacy Act

3.1. HIPAA Overview

Health Insurance Portability and Accountability Act (HIPAA), enacted in 1996, is the world's most widely applied health security standard. Although it is a US law, HIPAA has become the international benchmark for medical data security.

3.2. HIPAA Privacy Rule

Privacy Rule regulates who is allowed to access PHI and under what conditions:

  • Minimum Necessary Standard: Only access the minimum amount of PHI necessary for the job
  • Patient Rights: Patients have the right to view, copy, and request amendments to PHI
  • Authorization: Written patient consent is required for most PHI sharing situations
  • Treatment, Payment, Operations (TPO): 3 cases are allowed to use PHI without authorization

3.3. HIPAA Security Rule

Security Rule sets security requirements for ePHI, divided into 3 types of safeguards:

Administrative Safeguards

  • Security Management Process (Risk Analysis, Risk Management)
  • Assigned Security Responsibility (Security Officer)
  • Workforce Security (Authorization/Supervision, Clearance Procedures)
  • Information Access Management (Access Authorization, Access Establishment)
  • Security Awareness Training
  • Security Incident Procedures
  • Contingency Plan (Data Backup, DR, Emergency Mode)
  • Evaluation (Periodic security assessment)

Physical Safeguards

  • Facility Access Controls
  • Workstation Use & Security
  • Device and Media Controls

Technical Safeguards (main focus of this series)

CategoryControls
Access ControlUnique User Identification (Required), Emergency Access Procedure (Required), Automatic Logoff (Addressable), Encryption & Decryption (Addressable)
Audit ControlsHardware, software, procedural mechanisms to record and examine access to ePHI (Required)
IntegrityMechanism to authenticate ePHI (Addressable)
AuthenticationPerson or Entity Authentication (Required)
Transmission SecurityIntegrity Controls (Addressable), Encryption (Addressable)

Note: "Required" = required implementation. "Addressable" = must be evaluated and implemented if reasonable, or document the reason for not implementing.

3.4. HIPAA Breach Notification Rule

When a data breach occurs involving PHI:

  • Individual Notification: Notify each affected individual within 60 days
  • Media Notification: If the breach affects >500 people in a state/jurisdiction
  • HHS Notification: Report to the Department of Health and Human Services
  • Penalties: Fines from $100 to $50,000 per violation, maximum $1.5 million/year per category

4. HL7 FHIR Security

4.1. What is FHIR?

Fast Healthcare Interoperability Resources (FHIR) is HL7 International's standard for exchanging healthcare data via API. FHIR uses RESTful APIs, JSON/XML, and OAuth2 — a great fit for microservices architecture.

4.2. FHIR Security Framework

FHIR defines security components:

Security layers in the FHIR architecture — from Communication Security to Consent Management

  • Communication Security: HTTPS/TLS
  • Authentication: OAuth2, SMART on FHIR
  • Authorization: Scopes, Consent
  • Audit: AuditEvent resource
  • Digital Signatures: Provenance
  • Consent Management: Consent resource

4.3. SMART on FHIR

SMART (Substitutable Medical Applications, Reusable Technologies) is a framework that allows third-party applications to securely access medical data:

Patient/Clinician → SMART App → Authorization Server (Keycloak)
                                        ↓
                               FHIR Resource Server (Quarkus)
                                        ↓
                               Database (PostgreSQL)
  • EHR Launch: App is launched from within the EHR, receiving context (patient, encounter)
  • Standalone Launch: App runs independently, user chooses patient
  • Backend Services: Service-to-service authorization (no user interaction)

5. Law on Cyber Security and Data Protection in Vietnam

5.1. Law on Cyber Security 2018 (Law No. 24/2018/QH14)

Important points regarding medical data:

  • Article 26: Requirement to store data in Vietnam for Vietnamese user data collection and exploitation services
  • Article 16: Preventing and handling acts of violating network security
  • Article 17: Preventing and combating cyber attacks

5.2. Decree 13/2023/ND-CP on Personal Data Protection

The Decree takes effect from July 1, 2023, directly applying to medical data:

  • Sensitive personal data (Article 2): Includes data about health, sex life, genes, biometrics
  • Consent to processing (Article 11): There must be explicit consent from the data subject
  • Rights of the subject (Article 9): Right to know, right to consent, right to access, right to withdraw consent, right to delete
  • Impact assessment (Article 24): Mandatory implementation of personal data processing impact assessment
  • Cross-border data transfer (Article 25): Impact assessment documents must be prepared

5.3. Circular 46/2018/TT-BYT

Regulations on electronic medical records:

  • Require digital signatures for electronic medical records
  • Regulations on security and access authorization
  • Requires storage and backup

6. Security Frameworks and Standards

6.1. NIST Cybersecurity Framework

NIST Cybersecurity Framework lifecycle — 5 functions: Identify, Protect, Detect, Respond, Recover

  • IDENTIFY: Asset Management, Risk Assessment
  • PROTECT: Access Control, Data Security, Training
  • DETECT: Anomalies, Monitoring, Detection Processes
  • RESPOND: Response Planning, Communications, Mitigation
  • RECOVER: Recovery Planning, Improvements, Communications

6.2. ISO 27799 - Health Informatics Security

ISO 27799 provides guidance on implementing ISO 27001/27002 for the healthcare sector:

  • Additional controls specific to healthcare
  • Access control based on clinical role
  • Consent management for patient data
  • Audit trail for all PHI access

6.3. HITRUST CSF

Health Information Trust Alliance Common Security Framework incorporates the following standards:

  • HIPAA
  • ISO 27001/27002
  • NIST SP 800-53
  • PCI DSS
  • COBIT

7. Mapping Standards into Technology Stack

Security requirementsHIPAA ReferenceImplementation
Unique User ID§164.312(a)(2)(i)Keycloak User Management
Emergency Access§164.312(a)(2)(ii)Keycloak Break-the-glass flow
Auto Logoff§164.312(a)(2)(iii)Keycloak Session Timeout
Encryption§164.312(a)(2)(iv)PostgreSQL TDE + pgcrypto
Audit Controls§164.312(b)pgAudit + OpenTelemetry
Integrity§164.312(c)(1)Digital signatures, checksums
Authentication§164.312(d)Keycloak MFA/Passkeys
Transmission Security§164.312(e)(1)TLS 1.3 + mTLS

8. Summary

In this lesson, we learned:

  • What is PHI/ePHI and why does it need special protection?
  • HIPAA with 3 main Rules: Privacy, Security, Breach Notification
  • HL7 FHIR Security and SMART on FHIR for healthcare APIs
  • Vietnam Law: Law on Cyber Security 2018, Decree 13/2023, Circular 46/2018
  • Security frameworks: NIST CSF, ISO 27799, HITRUST CSF
  • Mapping security standards into Quarkus, PostgreSQL, Keycloak

Exercises

  1. List all types of data in your HIS/EMR system and classify what is PHI
  2. Determine how many % of HIPAA Technical Safeguards the current system meets
  3. Read Decree 13/2023 and map the requirements into the microservices system


Next article: Lesson 2: Safe Microservices Architecture for Healthcare with Quarkus Stack ▶