If you are given a file to transmit, then as long as you transmit that file 
intact and without encrypting it to obscure the meaning of the file, then you 
should be safe.

If the customer wants to encrypt the file before giving it to you, that's up to 
them.

If the hams don't encrypt the communications, then everything should be fine!

I wouldn't suggest starting the transmission with "This contains sensitive 
medical information" That's pretty much telling someone to try to read the data.

Now in accordance with the Privacy Act, the Amateur Operators probably 
shouldn't have access to information such as SSN in the first place.

From: [email protected] [mailto:[email protected]] On 
Behalf Of Frank P.
Sent: Tuesday, December 30, 2008 2:25 PM
To: [email protected]
Subject: [DSTAR_DIGITAL] Encryption on Amateur Frequencies


Several months ago the ARRL questioned the FCC concerning the rules
of NO ENCRYPTION versus THE PRIVACY ACT. I don't have the exact
quote handy, but I believe the query had to do with "after a
disaster" communications. Here is a theoretical scenario similar to
the one posed to the FCC:

A group of ARES volunteers at a local shelter are in direct
communication with the Red Cross HQ, or a hospital, or the local
OEM. The shelter has several sick or injured individuals who need
assistance or transportation to a hospital. The shelter emcom hams
prepare a database (Excel spreadsheet, text message, etc.) containing
the names, addresses, SSN's, Health Insurance info, and other data
covered by the federal Privacy Act. How do they send this info
without violating the Privacy Act? They encrypt the data, as per a
prearranged method between the emcom personnel and the receiver{s) of
the data, and transmit it using packet, winlink, D-Star digital data
or other digital means. The non-encrypted header of the message
should state "The data contained herein contains personal health
information and has been encrypted to preserve the privacy of the
individual patients".

Now, the FCC regulations for amateur radio, part 97, rule that
encryption cannot be used to "obscure the meaning" of communications.

So, if you state in the un-encrypted header that only the "substance"
of the message has been encrypted, and the meaning (or reason)for the
encryption is to follow the rules of the Privacy Act, then the
encryption should be allowed.

If any of you on this reflector can find the exact text of the
opinion rendered by the FCC on this matter, please post it for the
edification of our fellow members, and for possible future reference
for ARES / RACES personnel.

73, de Frank Porcaro, N2RSO
Wantagh Long Island NY



[Non-text portions of this message have been removed]

Reply via email to