If you are given a file to transmit, then as long as you transmit that file intact and without encrypting it to obscure the meaning of the file, then you should be safe.
If the customer wants to encrypt the file before giving it to you, that's up to them. If the hams don't encrypt the communications, then everything should be fine! I wouldn't suggest starting the transmission with "This contains sensitive medical information" That's pretty much telling someone to try to read the data. Now in accordance with the Privacy Act, the Amateur Operators probably shouldn't have access to information such as SSN in the first place. From: [email protected] [mailto:[email protected]] On Behalf Of Frank P. Sent: Tuesday, December 30, 2008 2:25 PM To: [email protected] Subject: [DSTAR_DIGITAL] Encryption on Amateur Frequencies Several months ago the ARRL questioned the FCC concerning the rules of NO ENCRYPTION versus THE PRIVACY ACT. I don't have the exact quote handy, but I believe the query had to do with "after a disaster" communications. Here is a theoretical scenario similar to the one posed to the FCC: A group of ARES volunteers at a local shelter are in direct communication with the Red Cross HQ, or a hospital, or the local OEM. The shelter has several sick or injured individuals who need assistance or transportation to a hospital. The shelter emcom hams prepare a database (Excel spreadsheet, text message, etc.) containing the names, addresses, SSN's, Health Insurance info, and other data covered by the federal Privacy Act. How do they send this info without violating the Privacy Act? They encrypt the data, as per a prearranged method between the emcom personnel and the receiver{s) of the data, and transmit it using packet, winlink, D-Star digital data or other digital means. The non-encrypted header of the message should state "The data contained herein contains personal health information and has been encrypted to preserve the privacy of the individual patients". Now, the FCC regulations for amateur radio, part 97, rule that encryption cannot be used to "obscure the meaning" of communications. So, if you state in the un-encrypted header that only the "substance" of the message has been encrypted, and the meaning (or reason)for the encryption is to follow the rules of the Privacy Act, then the encryption should be allowed. If any of you on this reflector can find the exact text of the opinion rendered by the FCC on this matter, please post it for the edification of our fellow members, and for possible future reference for ARES / RACES personnel. 73, de Frank Porcaro, N2RSO Wantagh Long Island NY [Non-text portions of this message have been removed]
