All, I would like to point out the regulation surrounding the obscuration of amateur radio transmissions. Regarding encryption and amateur radio, here is the applicable regulation:
97.309 RTTY and data emission codes. (4) (c) and 97.307(f) of this part, a station may transmit a RTTY or data emission using an unspecified digital code, except to a station in a country with which the United States does not have an agreement permitting the code to be used. RTTY ***and data emissions using unspecified digital codes must not be transmitted for the purpose of obscuring the meaning of any communication***. Note the last phrase, "...and data emissions using unspecified digital codes must NOT be transmitted for the purpose of OBSCURING the MEANING of any communication." The word obscuring is well understood, but what of the word, meaning? Meaning, as defined in the dictionary is defined as, "linguistic content (1)." So, obscuring the linguistic content of any amateur radio transmission is ILLEGAL. Some amateurs of digital data groups contend that encryption of amateur transmissions, within amateur bands, is LEGAL, as long as it meets their flawed criteria and logic. Nowhere in Part 97 does it say encryption usage is legal, despite the facts that the methods and keys used are made known or publicized, such as on the Web. Encryption, which includes WEP, WPA/WPA2 and other encryption methods, is expressly forbidden in Part 97. An example of this flawed logic, as taken from the HSMM description on Wikipedia: "Because the meaning of amateur transmissions may not be obscured, security measures that are implemented must be published. This does not necessarily restrict authentication or login schemes, but it does restrict fully encrypted communications. This leaves the communications vulnerable to various attacks once the authentication has been completed. This makes it very difficult to keep unauthorized users from accessing HSMM networks, although casual eavesdroppers can effectively be deterred. Current schemes include using MAC address <http://en.wikipedia.org/wiki/MAC_address> filtering, WEP <http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy> and WPA <http://en.wikipedia.org/wiki/Wi-Fi_Protected_Access>/WPA2 <http://en.wikipedia.org/wiki/WPA2>. MAC address filtering and WEP are all hackable by using freely available software from the Internet, making them the less secure options. Per FCC rules the encryption keys themselves must be published in a publicly accessible place if using WEP, WPA/WPA2 or any other encryption, thereby undermining the security of their implementation(2)." WEP, WPA, and WPA2 are encryption methods meant to obscure the meaning of transmissions. This descriptive phrase, "WEP uses the stream cipher <http://en.wikipedia.org/wiki/Stream_cipher> RC4 <http://en.wikipedia.org/wiki/RC4> for confidentiality <http://en.wikipedia.org/wiki/Confidentiality>," says it all concerning this early security measure(3). WPA and WPA2 are later and stronger methods of 802.11 wireless encryption. <http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy#cite_note-7> ... As a casual online ham friend, K3UD, says: "If the US government wants the Amateur Radio Service to be a vital part of Homeland security and disaster communications maybe they should put out a call for volunteers within the ham community to commit for homeland security and other disaster communications training. The hams that pass the course and commit to doing this would receive an endorsement on their licenses certifying them as trained in the kind of communications the FCC would require in the event of a disaster or other bonifide emergency. If encrypted communications were required, it would be these amateurs who would have the privileges to use encryption. This seems to satisfy what those who favor encryption say they want to do with it. On the other hand, if any of them were caught using it for personal encrypted communication (IE routine email via W2LK) they would immediately lose their certification and perhaps have their license suspended for a time. On the other hand, do we see anyone at the FCC or Homeland Security beating the drum for Amateur Radio operators to be able to use encryption? Is there a RM pending before the Commission addressing the Subject? Has the ARRL weighed in on it? Is there anyone posting on this topic who is constructing an RM filing to the FCC on this subject? What we have is someone who wrote an article or two expressing the opinion that there is some kind of back door way into legal encryption for Amateur radio. The FCC apparently has its reasons for the encryption ban. Perhaps Homeland security is one of them in that ham radio may become a communications conduit for terrorist activity. It can cut both ways. I somehow do not think that any of this has much to do with Homeland security and everything to do with, as AG4YO illustrates, turning Amateur Radio into a "free" ersatz ISP for those who do not want to look to other options (IE, paid commercial services). If the FCC wanted the ARS to be able to create an exception for encrypted communications originating from licensed hams, it would have already done so. Some here might remember the justifications put forth by those who are pushing digital modes, regulation by bandwidth, and WL2k. Some of those justifications centered around unpublicized back channel communications to the ARRL by the FCC that were said to have the "unofficial" purpose of enlisting the ARRL in an effort to prepare the ARS for drastic changes in the way we communicate. It was also speculated that this included being some kind of auxiliary for Homeland Security and the need for digital communications would hold sway. However, I do not recall anything being said by anyone about the need for encrypted communications originating from licensees in the ARS. So, I pose the question. Why does the Amateur Radio Service need to be able to encrypt its communications?(4)" ... I would like to point out the following information contained within John's informative link just below: How Hospitals are Complying(5): Hospitals have presented training sessions to their workforces about the circumstances under which patient information may be disclosed, what information may be given, and to whom. Staff members are cautioned to avoid inadvertent disclosure of PHI, overhearing by visitors, access to charts, computer screens, and leaving patient information unattended. In compliance with HIPAA, pharmacies, hospitals, and physician's offices now present handouts on privacy issues to their incoming patients. Besides stating what patient information might be legally disclosed on a day-to-day basis, and how, they also give examples of how this information may be legally transmitted by Amateur Radio when normal transmission methods are not available. Here are some statements from one Orange County hospital's handout: * "We (the hospital) may use and disclose medical information about you for your treatment." * "We may release medical information about you to a family member, friend, or any other person involved with your medical care." * "Unless you (the patient) tell us otherwise, we will list your name, location, general condition, and religious affiliation with the hospital directory. The information may be provided to members of the clergy and to others who ask for you by name, including the media." * "We may use or disclose information to notify or assist in notifying a family member, personal representative, or another person responsible for your care, of your location and general condition." As you can see from this disclosure, an Amateur Radio operator transmitting a name on the air in an emergency at the request of hospital staff for any of these purposes doesn't violate HIPAA/Privacy concerns [I agree with this assessment]. The radio operator is just the communications resource. Anything transmitted via Amateur Radio referencing any patient care is at the request of, and authorized by hospital staff. Some hospitals have become creative at increasing privacy by using "record numbers" instead of names to identify patients when passing information from one unit to another. In preparation for the implementation of the law, Risk Management and HIPAA managers at one hospital here in Orange County, California reviewed Amateur Radio involvement extensively. The conclusion was that "HDSCS would be exempt from HIPAA for disaster purposes, as long as there is no post-incident publishing of patient-identifiable information." Of course, HDSCS doesn't disclose any PHI after an incident. ... My take on HIPAA, encryption usage, and Amateur Radio: *HIPAA regulated information cannot be transfered by Amateur Radio's techniques unless a release to do so is provided by the protected information's owner. All encryption methods expressly designed to obscure, hide, or ensure that information is accessible only to those authorized to have access, are ILLEGAL via Amateur Radio transmissions.* References: 1. http://dictionary.reference.com/browse/meaning 2. http://en.wikipedia.org/wiki/High_speed_multimedia 3. http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy#Encryption_details 4. http://forums.qrz.com/showthread.php?t=99951&page=4 5. http://www.hdscs.org/hipaa.html 73 de Steve, NL7W John D. Hays wrote: > > Here is an interesting read on the topic, for _interested parties_: > http://www.hdscs.org/hipaa.html <http://www.hdscs.org/hipaa.html> > > David B. Toth wrote: > > > > At 02:55 PM 12/30/2008, k7ve wrote: > > >--- In [email protected] > <mailto:dstar_digital%40yahoogroups.com> > > <mailto:dstar_digital%40yahoogroups.com>, "Frank P." <n2...@...> wrote: > > > > > > > > > > > A group of ARES volunteers at a local shelter are in direct > > > > communication with the Red Cross HQ, or a hospital, or the local > > > > OEM. The shelter has several sick or injured individuals who need > > > > assistance or transportation to a hospital. The shelter emcom hams > > > > prepare a database (Excel spreadsheet, text message, etc.) > containing > > > > the names, addresses, SSN's, Health Insurance info, and other data > > > > covered by the federal Privacy Act. How do they send this info > > > > without violating the Privacy Act? > > > > > >I worked for a major healthcare company (Doctors, Hospitals, and > > >Insurance) for 5 years. We dealt with HIPPA (not Federal Privacy Act) > > >every day. Some information is protected, but there are also > > >exceptions and there is certainly needed information verses > > >information that can be collected later. > > > > HIPPA and Privacy are slightly different ... > > HIPPA deals with not sending a person's insurance info to places that > > should not have it. > > There is a cottage industry that has sprung up to screw this around > > to say that it covers all aspects of medical privacy. > > It does not, but that is what Privacy Acts and institutional privacy > > policies are about. > > > > I know this is more than anyone would want or should want to know. > > > > Dr. Dave > > > > -- > John D. Hays > Amateur Radio Station K7VE <http://k7ve.ampr.org <http://k7ve.ampr.org>> > PO Box 1223 > Edmonds, WA 98020-1223 > VOIP/SIP: [email protected] <mailto:john%40hays.org> <sip:[email protected] > <mailto:john%40hays.org>> > Phone: 206-801-0820 > 801-790-0950 > Email: [email protected] <mailto:john%40hays.org> <mailto:[email protected] > <mailto:john%40hays.org>> > > [Non-text portions of this message have been removed] > >
