dr. maury pinsk frcpc university of alberta division of pediatric nephrology

22
Shouting from the Rooftops: Improving Email Security Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Upload: natara

Post on 13-Jan-2016

108 views

Category:

Documents


1 download

DESCRIPTION

Shouting from the Rooftops: Improving Email Security. Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology. Dr. V. Uses email to correspond with patients Answers questions Gives test results Changes medications - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Shouting from the Rooftops:

Improving Email Security

Dr. Maury Pinsk FRCPCUniversity of Alberta

Division of Pediatric Nephrology

Page 2: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Dr. V

Uses email to correspond with patients Answers questions Gives test results Changes medications

All emails are signed with disclaimer for confidentiality

Patient A asks how secure her medical information is

Page 3: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

How secure is email?

Depends : Where it is being sent What you choose to use it for How it is being sent

Page 4: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Email - the basics

Your email program is a “mail user agent” Produces a text file Sends the file through the internet

using a set of instructions that allow commuters to communicate – a “Protocol”

E.g.: SMTP or simple message transfer protocol

Page 5: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Email - the basics

SMTP guides the email to final recipients server Can route through several servers if

necessary Once it reaches its final destination

server, it is stored to disk The recipient accesses the email using

a Post office protocol (POP)

Page 6: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

So what are the security issues Sending an email is like sending a

postcard Any server through which it passes

is an opportunity for eyes to read For the keen individual, it

represents an opportunity to alter the contents of the email as well.

Page 7: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

So what factors alter the security of the email?

Page 8: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Where is it being sent?

Data that stays on a server is less likely to fall into the wrong hands More so for dedicated service providers

(e.g.: intrauniversity, intrahospital) Less so for data that leaves a server

(e.g.: interhospital or interuniversity)

Page 9: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

How is it being sent?

Data that is sent unprocessed is vulnerable to breach of confidentiality or integrity

What do I mean by processed? Encryption Digital signatures

Page 10: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Encryption

Key a large number used by encryption algorithm to

generate cipher code Public key owner can send you

encrypted email securely, but cannot decrypt it

Private key owner can decrypt the email.

The two keys are related, but through very complex algorithms that are difficult to crack

Page 11: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology
Page 12: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Encryption

Keys are stored, encrypted, on your computer, and used by your email software

Keys can be distributed by owner on disk, by email or via access to repository (key server)

Page 13: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

PGP encryption: an extra layer of security for encryption

Page 14: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

PGP – decryption – the same in reverse

Page 15: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Encryption, but for whom?

Encryption: keeps on-looking eyes away from sensitive data, but doesn’t verify the source

Authentication and integrity is verified by a digital signature

Page 16: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Digital Signature

Page 17: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Digital signatures

Page 18: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

But how do you know the key is from the right person?

Key “forgery” is possible, hence the need for security certificates

Security certificate = digital signature + authentication from another user + public encryption key + user identification

Page 19: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

What is being sent?

The best means of preserving data integrity and confidentiality is to decide if it is absolutely necessary to send it the data by email.

Page 20: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Return to Dr. V

Patients informed: Patient information continues to be

transferred over the internet, but patients sign a consent allowing this to happen

Information kept confidential: Public keys are issued to patients via key

server Patients encouraged to obtain own personal

key and distribute public key to Dr. V

Page 21: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Integrity of information confirmed: Security certificates issued with public

key All correspondence with digital

signature.

Page 22: Dr. Maury Pinsk FRCPC University of Alberta Division of Pediatric Nephrology

Further resources

Encryption and digital signature freeware Pretty Good Privacy (PGP)

http://www.pgpi.org

Guidelines for Patient Privacy HIPAA Privacy regulations

http://www.hhs.gov/ocr/hipaa