Standards for health information technology to protect electronic health information created, maintained, and exchanged.

§ 170.210 Standards for health information technology to protect electronic health information created, maintained, and exchanged.

The Secretary adopts the following standards to protect electronic health information created, maintained, and exchanged:

(a) Encryption and decryption of electronic health information. (1) [Reserved]

(2) General. Any encryption algorithm identified by the National Institute of Standards and Technology (NIST) as an approved security function in Annex A of the Federal Information Processing Standards (FIPS) Publication 140–2, October 8, 2014 (incorporated by reference in § 170.299).

(b) [Reserved]

(c) Hashing of electronic health information. (1) [Reserved]

(2) Standard. A hashing algorithm with a security strength equal to or greater than SHA–2 as specified by NIST in FIPS Publication 180–4 (August 2015) (incorporated by reference in § 170.299).

This document is only available to subscribers. Please log in or purchase access.