Data Loss Prevention

 View Only
  • 1.  HIPAA/HITECH Policy Question

    Posted Mar 15, 2012 11:07 AM

    We have had the network solution in place for some time.  We are reviewing the HIPAA/HITECH policy.  We currently use what Symantec provides .I was wondering if anyone had extended the policy to cover other data elements such as date of birth or healthcare claim number or healthcare membership numbers as examples.  I'd be most interested if anyone would be willing to share their approaches to protecting this type of data.



  • 2.  RE: HIPAA/HITECH Policy Question

    Posted Mar 15, 2012 02:52 PM
    I'd suggest you explore the feasibility of doing a Exact Data Match (EDM) profile for this type of matching. That said, Date-of-Birth is going to be an issue regardless of how you try to detect on it. If I understand enough based on the information you give, I'd imagine you could build two EDMs. (1) Member Data - include Member Last Name, Member ID, Member SSN, and Member HICN. (2) Claims Data - include Member Last Name, Member ID, and Claim #. Then, rather than using just the data identifiers for SSN in conjunction with those keywords included in the out-of-the-box HIPAA rule, use your EDM profiles to look for the member name and any one of those other elements. Your detection accuracy will then be close to 100% (based on the data that you have indexed in those EDMs), and your match counts will reflect the true number of unique matches, which will help you separate the cases where a single claim form is sent, for example, from ones where this data is being sent in bulk. That allows you to do much more with regards to automated incident remediation (i.e. blocking) with a higher confidence. It may take some convincing across several levels to allow you to even access this data for the purpose of building the EDM. I'd suggest, if that's the case, that you prototype this in your environment and show the results, which will usually go very far with regards to convincing folks of the merit of this approach. Hope that helps! Regards, ~Keith


  • 3.  RE: HIPAA/HITECH Policy Question

    Posted Mar 24, 2012 11:30 AM

    Hi carry,

    You can define new data identifier using buit in template. You can customize those temeplete as per regular expression and you requirement. As Syamntec DLP has some bultin standard template like Card data , customer data and othrs. still ther is facilty to customize it.

    Implementing custom data identifiers are attached image of the same.