Creighton University: Researchers Comply with HIPAA Using PKZIP

Creighton University is consistently recognized as one of the top private universities in the country for medicine, pharmacy, physical therapy, occupational therapy, dentistry, and nursing. In addition to teaching, research is an important aspect of the school's programs. Faculty members and graduate students conduct research in many areas, including ethics, clinical drug studies, innovative educational techniques, among others.

HIPAA Implications
As part of their ongoing research, professors, doctors, graduate students, and others exchange a wide range of confidential patient data. To maintain the integrity and privacy of such data, the U.S. Government introduced the Health Insurance Portability and Accountability Act (HIPAA) in 1996 and established April 2003 as the deadline for compliance. In 1999, Creighton set up a working group to look at the implications of HIPAA as it related to its medical centers. In 2002, the school began to consider the ramifications of HIPAA on its research efforts.

"We knew that the time was drawing near when we would have to have a standard HIPAA procedure in place to adequately protect subject identifiers from improper use and disclosure," says Dr. Phillip Vuchetich, assistant professor of Pharmacy Sciences.

Meeting Requirements
The university was already using PKZIP to compress large files, so it was familiar with the product and its capabilities. However, the school wanted to determine if the newest version of PKZIP, which provided strong encryption, could meet the tough security and privacy standards set forth by HIPAA. Alternative solutions Creighton could have implemented included S/MIME and PGP, however, these methods would have required greater investment, are more complex, and raise interoperability issues.

Because PKZIP integrates with both PKI and non-PKI environments, the cost was much less for deploying internally as a security solution as well as for interoperating with external recipients.

"Our goal was to assess PKZIP's capabilities with regard to protecting health-related data as well as the integrity of our research," says Dr. Vuchetich.

To determine if PKZIP could meet HIPAA requirements, Dr. Vuchetich, along with Dr. Vasant Raval, chair of the department of Accounting in the College of Business Administration, launched a formal PKZIP study in June 2002. The researchers implemented PKZIP in a Microsoft Windows environment made up of more than 110 researchers, and then began testing in two browser environments, Microsoft Internet Explorer and Netscape Navigator.

"The implementation of PKZIP was swift and relatively easy," explains Dr. Raval. "We found the product performed data encryption well, and integrated smoothly with externally supplied digital certificates. Plus, once we equipped a few users, PKZIP scaled quickly and easily to our remaining researchers."

Seamless Integration
Today, more than 300 researchers associated with the Creighton University Medical Center rely on PKZIP to exchange confidential patient data and other research-related information. By relying on PKZIP's seamless e-mail integration with Microsoft Outlook, researchers now have an easy-to-use solution for sending e-mail attachments compactly and securely.

Phillip J. Vuchetich, Ph.D. (philv@creighton. edu), is assistant professor of Pharmacy Sciences, and Vasant Raval, Ph.D. (vraval@ creighton.edu), is professor and chair, Accounting, both at Creighton University.

Featured

  • person signing a bill at a desk with a faint glow around the document. A tablet and laptop are subtly visible in the background, with soft colors and minimal digital elements

    California Governor Signs AI Content Safeguards into Law

    California Governor Gavin Newsom has officially signed off on a series of landmark artificial intelligence bills, signaling the state’s latest efforts to regulate the burgeoning technology, particularly in response to the misuse of sexually explicit deepfakes. The legislation is aimed at mitigating the risks posed by AI-generated content, as concerns grow over the technology's potential to manipulate images, videos, and voices in ways that could cause significant harm.

  • glowing AI brain composed of geometric lines and nodes, encased within a protective shield of circuit patterns

    NIST's U.S. AI Safety Institute Announces Research Collaboration with Anthropic and OpenAI

    The U.S. AI Safety Institute, part of the National Institute of Standards and Technology (NIST), has formalized agreements with AI companies Anthropic and OpenAI to collaborate on AI safety research, testing, and evaluation.

  • a glowing gaming controller, a digital tree structure, and an open book

    Report: Use of Game Engines Expands Beyond Gaming

    Game development technology is increasingly being utilized beyond its traditional gaming roots, according to the recently released annual "State of Game Development" report from development and DevOps solutions provider Perforce Software.

  • translucent lock composed of interconnected nodes and circuits at the center

    Cloud Security Alliance: Best Practices for Securing AI Systems

    The Cloud Security Alliance (CSA), a not-for-profit organization whose mission statement is defining and raising awareness of best practices to help ensure a secure cloud computing environment, has released a new report offering guidance on securing systems that leverage large language models (LLMs) to address business challenges.