1. Why is Medical Data Security important?

Medical data is one of the most sensitive types of data. A medical record contains personal information, medical history, test results, prescriptions, and insurance information — all of which are highly valuable on the black market.
Worrying statistics
- Value of medical data: On the dark web, a medical record costs from $250-$1,000, 10-40 times more than credit card information ($5-$25)
- Average cost of a breach in healthcare: $10.93 million USD (2023, IBM Cost of a Data Breach Report) — highest in any industry
- Frequency of attacks: 89% of healthcare organizations have experienced data breaches in the last 2 years
- Detection time: Average 329 days to detect and control a medical breach
Why is medical data an attractive target?
| Features | Reason |
|---|---|
| Cannot be changed | Unlike a credit card, you cannot "cancel" and reissue your medical history |
| Long-term value | Medical data is valuable for the patient's lifetime |
| Multi-purpose | Can be used for identity theft, insurance fraud, prescription fraud |
| Legacy system | Many hospitals use old, insecure systems |
| Operating pressure | Hospitals must operate 24/7, making it difficult to "shutdown" to patch errors |
2. What is Protected Health Information (PHI)?
2.1. Definition of PHI
Protected Health Information (PHI) is any information related to:
- Health status (past, present, or future) of an individual
- The provision of medical services to an individual
- Payment for medical services
AND can identify that individual.
2.2. 18 HIPAA Identifiers
HIPAA identifies 18 types of identifiable information that need to be protected:
| # | Identifiers | Example |
|---|---|---|
| 1 | Name | Nguyen Van A |
| 2 | Address (more detailed than province/city) | 123 Nguyen Hue, District 1, Ho Chi Minh City |
| 3 | Date (except year) related | Date of birth, date of admission, date of discharge |
| 4 | Phone number | 0901234567 |
| 5 | Fax number | (028) 1234567 |
| 6 | [email protected] | |
| 7 | Social insurance/health insurance number | HC4012345678 |
| 8 | Medical record number | MRN-2026-001234 |
| 9 | Insurance beneficiary number | BH-2026-5678 |
| 10 | Account number | 1234567890 |
| 11 | License/certificate number | CCCD: 001234567890 |
| 12 | License plate | 51A-12345 |
| 13 | Device serial number | Pacemaker SN: ABC123 |
| 14 | URLs | patient-portal.hospital.vn/patient/123 |
| 15 | IP address | 192.168.1.100 |
| 16 | Biometric identifiers | Fingerprint, face |
| 17 | Portrait photos | Patient photo |
| 18 | Any unique identifier | Internal patient code |
2.3. Electronic PHI (ePHI)
ePHI is PHI that is created, stored, transmitted, or received electronically. In a microservices system, most PHI exists as ePHI:
- Data in PostgreSQL databases
- API requests/responses contains patient information
- Messages in Kafka topics
- Cache entries in Redis
- Log files contain patient identifiers
- Backup files
3. HIPAA - US Health Information Privacy Act
3.1. HIPAA Overview
Health Insurance Portability and Accountability Act (HIPAA), enacted in 1996, is the world's most widely applied health security standard. Although it is a US law, HIPAA has become the international benchmark for medical data security.
3.2. HIPAA Privacy Rule
Privacy Rule regulates who is allowed to access PHI and under what conditions:
- Minimum Necessary Standard: Only access the minimum amount of PHI necessary for the job
- Patient Rights: Patients have the right to view, copy, and request amendments to PHI
- Authorization: Written patient consent is required for most PHI sharing situations
- Treatment, Payment, Operations (TPO): 3 cases are allowed to use PHI without authorization
3.3. HIPAA Security Rule
Security Rule sets security requirements for ePHI, divided into 3 types of safeguards:
Administrative Safeguards
- Security Management Process (Risk Analysis, Risk Management)
- Assigned Security Responsibility (Security Officer)
- Workforce Security (Authorization/Supervision, Clearance Procedures)
- Information Access Management (Access Authorization, Access Establishment)
- Security Awareness Training
- Security Incident Procedures
- Contingency Plan (Data Backup, DR, Emergency Mode)
- Evaluation (Periodic security assessment)
Physical Safeguards
- Facility Access Controls
- Workstation Use & Security
- Device and Media Controls
Technical Safeguards (main focus of this series)
| Category | Controls |
|---|---|
| Access Control | Unique User Identification (Required), Emergency Access Procedure (Required), Automatic Logoff (Addressable), Encryption & Decryption (Addressable) |
| Audit Controls | Hardware, software, procedural mechanisms to record and examine access to ePHI (Required) |
| Integrity | Mechanism to authenticate ePHI (Addressable) |
| Authentication | Person or Entity Authentication (Required) |
| Transmission Security | Integrity Controls (Addressable), Encryption (Addressable) |
Note: "Required" = required implementation. "Addressable" = must be evaluated and implemented if reasonable, or document the reason for not implementing.
3.4. HIPAA Breach Notification Rule
When a data breach occurs involving PHI:
- Individual Notification: Notify each affected individual within 60 days
- Media Notification: If the breach affects >500 people in a state/jurisdiction
- HHS Notification: Report to the Department of Health and Human Services
- Penalties: Fines from $100 to $50,000 per violation, maximum $1.5 million/year per category
4. HL7 FHIR Security
4.1. What is FHIR?
Fast Healthcare Interoperability Resources (FHIR) is HL7 International's standard for exchanging healthcare data via API. FHIR uses RESTful APIs, JSON/XML, and OAuth2 — a great fit for microservices architecture.
4.2. FHIR Security Framework
FHIR defines security components:

- Communication Security: HTTPS/TLS
- Authentication: OAuth2, SMART on FHIR
- Authorization: Scopes, Consent
- Audit: AuditEvent resource
- Digital Signatures: Provenance
- Consent Management: Consent resource
4.3. SMART on FHIR
SMART (Substitutable Medical Applications, Reusable Technologies) is a framework that allows third-party applications to securely access medical data:
Patient/Clinician → SMART App → Authorization Server (Keycloak)
↓
FHIR Resource Server (Quarkus)
↓
Database (PostgreSQL)
- EHR Launch: App is launched from within the EHR, receiving context (patient, encounter)
- Standalone Launch: App runs independently, user chooses patient
- Backend Services: Service-to-service authorization (no user interaction)
5. Law on Cyber Security and Data Protection in Vietnam
5.1. Law on Cyber Security 2018 (Law No. 24/2018/QH14)
Important points regarding medical data:
- Article 26: Requirement to store data in Vietnam for Vietnamese user data collection and exploitation services
- Article 16: Preventing and handling acts of violating network security
- Article 17: Preventing and combating cyber attacks
5.2. Decree 13/2023/ND-CP on Personal Data Protection
The Decree takes effect from July 1, 2023, directly applying to medical data:
- Sensitive personal data (Article 2): Includes data about health, sex life, genes, biometrics
- Consent to processing (Article 11): There must be explicit consent from the data subject
- Rights of the subject (Article 9): Right to know, right to consent, right to access, right to withdraw consent, right to delete
- Impact assessment (Article 24): Mandatory implementation of personal data processing impact assessment
- Cross-border data transfer (Article 25): Impact assessment documents must be prepared
5.3. Circular 46/2018/TT-BYT
Regulations on electronic medical records:
- Require digital signatures for electronic medical records
- Regulations on security and access authorization
- Requires storage and backup
6. Security Frameworks and Standards
6.1. NIST Cybersecurity Framework

- IDENTIFY: Asset Management, Risk Assessment
- PROTECT: Access Control, Data Security, Training
- DETECT: Anomalies, Monitoring, Detection Processes
- RESPOND: Response Planning, Communications, Mitigation
- RECOVER: Recovery Planning, Improvements, Communications
6.2. ISO 27799 - Health Informatics Security
ISO 27799 provides guidance on implementing ISO 27001/27002 for the healthcare sector:
- Additional controls specific to healthcare
- Access control based on clinical role
- Consent management for patient data
- Audit trail for all PHI access
6.3. HITRUST CSF
Health Information Trust Alliance Common Security Framework incorporates the following standards:
- HIPAA
- ISO 27001/27002
- NIST SP 800-53
- PCI DSS
- COBIT
7. Mapping Standards into Technology Stack
| Security requirements | HIPAA Reference | Implementation |
|---|---|---|
| Unique User ID | §164.312(a)(2)(i) | Keycloak User Management |
| Emergency Access | §164.312(a)(2)(ii) | Keycloak Break-the-glass flow |
| Auto Logoff | §164.312(a)(2)(iii) | Keycloak Session Timeout |
| Encryption | §164.312(a)(2)(iv) | PostgreSQL TDE + pgcrypto |
| Audit Controls | §164.312(b) | pgAudit + OpenTelemetry |
| Integrity | §164.312(c)(1) | Digital signatures, checksums |
| Authentication | §164.312(d) | Keycloak MFA/Passkeys |
| Transmission Security | §164.312(e)(1) | TLS 1.3 + mTLS |
8. Summary
In this lesson, we learned:
- What is PHI/ePHI and why does it need special protection?
- HIPAA with 3 main Rules: Privacy, Security, Breach Notification
- HL7 FHIR Security and SMART on FHIR for healthcare APIs
- Vietnam Law: Law on Cyber Security 2018, Decree 13/2023, Circular 46/2018
- Security frameworks: NIST CSF, ISO 27799, HITRUST CSF
- Mapping security standards into Quarkus, PostgreSQL, Keycloak
Exercises
- List all types of data in your HIS/EMR system and classify what is PHI
- Determine how many % of HIPAA Technical Safeguards the current system meets
- Read Decree 13/2023 and map the requirements into the microservices system
Next article: Lesson 2: Safe Microservices Architecture for Healthcare with Quarkus Stack ▶