All,

I would like to point out the regulation surrounding the obscuration of 
amateur radio transmissions.  Regarding encryption and amateur radio, 
here is the applicable regulation:

97.309 RTTY and data emission codes.

(4) (c) and 97.307(f) of this part, a station may transmit a RTTY or 
data emission using an unspecified digital code, except to a station in 
a country with which the United States does not have an agreement 
permitting the code to be used. RTTY ***and data emissions using 
unspecified digital codes must not be transmitted for the purpose of 
obscuring the meaning of any communication***.


Note the last phrase, "...and data emissions using unspecified digital 
codes must NOT be transmitted for the purpose of OBSCURING the MEANING 
of any communication."  The word obscuring is well understood, but what 
of the word, meaning?  Meaning, as defined in the dictionary is defined 
as, "linguistic content (1)."  So, obscuring the linguistic content of 
any amateur radio transmission is ILLEGAL. 

Some amateurs of digital data groups contend that encryption of amateur 
transmissions, within amateur bands, is LEGAL, as long as it meets their 
flawed criteria and logic.  Nowhere in Part 97 does it say encryption 
usage is legal, despite the facts that the methods and keys used are 
made known or publicized, such as on the Web.  Encryption, which 
includes WEP, WPA/WPA2 and other encryption methods, is expressly 
forbidden in Part 97.  An example of this flawed logic, as taken from 
the HSMM description on Wikipedia:


"Because the meaning of amateur transmissions may not be obscured, 
security measures that are implemented must be published. This does not 
necessarily restrict authentication or login schemes, but it does 
restrict fully encrypted communications. This leaves the communications 
vulnerable to various attacks once the authentication has been 
completed. This makes it very difficult to keep unauthorized users from 
accessing HSMM networks, although casual eavesdroppers can effectively 
be deterred. Current schemes include using MAC address 
<http://en.wikipedia.org/wiki/MAC_address> filtering, WEP 
<http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy> and WPA 
<http://en.wikipedia.org/wiki/Wi-Fi_Protected_Access>/WPA2 
<http://en.wikipedia.org/wiki/WPA2>. MAC address filtering and WEP are 
all hackable by using freely available software from the Internet, 
making them the less secure options. Per FCC rules the encryption keys 
themselves must be published in a publicly accessible place if using 
WEP, WPA/WPA2 or any other encryption, thereby undermining the security 
of their implementation(2)."


WEP, WPA, and WPA2 are encryption methods meant to obscure the meaning 
of transmissions.  This descriptive phrase, "WEP uses the stream cipher 
<http://en.wikipedia.org/wiki/Stream_cipher> RC4 
<http://en.wikipedia.org/wiki/RC4> for confidentiality 
<http://en.wikipedia.org/wiki/Confidentiality>," says it all concerning 
this early security measure(3).  WPA and WPA2 are later and stronger 
methods of 802.11 wireless encryption.  
<http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy#cite_note-7>


...


As a casual online ham friend, K3UD, says:


"If the US government wants the Amateur Radio Service to be a vital part 
of Homeland security and disaster communications maybe they should put 
out a call for volunteers within the ham community to commit for 
homeland security and other disaster communications training. The hams 
that pass the course and commit to doing this would receive an 
endorsement on their licenses certifying them as trained in the kind of 
communications the FCC would require in the event of a disaster or other 
bonifide emergency.

If encrypted communications were required, it would be these amateurs 
who would have the privileges to use encryption. This seems to satisfy 
what those who favor encryption say they want to do with it. On the 
other hand, if any of them were caught using it for personal encrypted 
communication (IE routine email via W2LK) they would immediately lose 
their certification and perhaps have their license suspended for a time.

On the other hand, do we see anyone at the FCC or Homeland Security 
beating the drum for Amateur Radio operators to be able to use 
encryption? Is there a RM pending before the Commission addressing the 
Subject? Has the ARRL weighed in on it? Is there anyone posting on this 
topic who is constructing an RM filing to the FCC on this subject?

What we have is someone who wrote an article or two expressing the 
opinion that there is some kind of back door way into legal encryption 
for Amateur radio. The FCC apparently has its reasons for the encryption 
ban. Perhaps Homeland security is one of them in that ham radio may 
become a communications conduit for terrorist activity. It can cut both 
ways.

I somehow do not think that any of this has much to do with Homeland 
security and everything to do with, as AG4YO illustrates, turning 
Amateur Radio into a "free" ersatz ISP for those who do not want to look 
to other options (IE, paid commercial services). If the FCC wanted the 
ARS to be able to create an exception for encrypted communications 
originating from licensed hams, it would have already done so.

Some here might remember the justifications put forth by those who are 
pushing digital modes, regulation by bandwidth, and WL2k. Some of those 
justifications centered around unpublicized back channel communications 
to the ARRL by the FCC that were said to have the "unofficial" purpose 
of enlisting the ARRL in an effort to prepare the ARS for drastic 
changes in the way we communicate.

It was also speculated that this included being some kind of auxiliary 
for Homeland Security and the need for digital communications would hold 
sway. However, I do not recall anything being said by anyone about the 
need for encrypted communications originating from licensees in the ARS.

So, I pose the question. Why does the Amateur Radio Service need to be 
able to encrypt its communications?(4)"


...


I would like to point out the following information contained within 
John's informative link just below:

How Hospitals are Complying(5):

Hospitals have presented training sessions to their workforces about the 
circumstances under which patient information may be disclosed, what 
information may be given, and to whom. Staff members are cautioned to 
avoid inadvertent disclosure of PHI, overhearing by visitors, access to 
charts, computer screens, and leaving patient information unattended.

In compliance with HIPAA, pharmacies, hospitals, and physician's offices 
now present handouts on privacy issues to their incoming patients. 
Besides stating what patient information might be legally disclosed on a 
day-to-day basis, and how, they also give examples of how this 
information may be legally transmitted by Amateur Radio when normal 
transmission methods are not available. Here are some statements from 
one Orange County hospital's handout:

    * "We (the hospital) may use and disclose medical information about
      you for your treatment."

    * "We may release medical information about you to a family member,
      friend, or any other person involved with your medical care."

    * "Unless you (the patient) tell us otherwise, we will list your
      name, location, general condition, and religious affiliation with
      the hospital directory. The information may be provided to members
      of the clergy and to others who ask for you by name, including the
      media."

    * "We may use or disclose information to notify or assist in
      notifying a family member, personal representative, or another
      person responsible for your care, of your location and general
      condition."

As you can see from this disclosure, an Amateur Radio operator 
transmitting a name on the air in an emergency at the request of 
hospital staff for any of these purposes doesn't violate HIPAA/Privacy 
concerns [I agree with this assessment]. The radio operator is just the 
communications resource. Anything transmitted via Amateur Radio 
referencing any patient care is at the request of, and authorized by 
hospital staff.

Some hospitals have become creative at increasing privacy by using 
"record numbers" instead of names to identify patients when passing 
information from one unit to another.

In preparation for the implementation of the law, Risk Management and 
HIPAA managers at one hospital here in Orange County, California 
reviewed Amateur Radio involvement extensively. The conclusion was that 
"HDSCS would be exempt from HIPAA for disaster purposes, as long as 
there is no post-incident publishing of patient-identifiable 
information." Of course, HDSCS doesn't disclose any PHI after an incident.

...


My take on HIPAA, encryption usage, and Amateur Radio:

*HIPAA regulated information cannot be transfered by Amateur Radio's 
techniques unless a release to do so is provided by the protected 
information's owner.  All encryption methods expressly designed to 
obscure, hide, or ensure that information is accessible only to those 
authorized to have access, are ILLEGAL via Amateur Radio transmissions.*


References:
1. http://dictionary.reference.com/browse/meaning
2. http://en.wikipedia.org/wiki/High_speed_multimedia

3. http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy#Encryption_details

4. http://forums.qrz.com/showthread.php?t=99951&page=4

5. http://www.hdscs.org/hipaa.html




73 de Steve, NL7W



John D. Hays wrote:
>
> Here is an interesting read on the topic, for _interested parties_:
> http://www.hdscs.org/hipaa.html <http://www.hdscs.org/hipaa.html>
>
> David B. Toth wrote:
> >
> > At 02:55 PM 12/30/2008, k7ve wrote:
> > >--- In [email protected] 
> <mailto:dstar_digital%40yahoogroups.com>
> > <mailto:dstar_digital%40yahoogroups.com>, "Frank P." <n2...@...> wrote:
> > >
> > > >
> > > > A group of ARES volunteers at a local shelter are in direct
> > > > communication with the Red Cross HQ, or a hospital, or the local
> > > > OEM. The shelter has several sick or injured individuals who need
> > > > assistance or transportation to a hospital. The shelter emcom hams
> > > > prepare a database (Excel spreadsheet, text message, etc.) 
> containing
> > > > the names, addresses, SSN's, Health Insurance info, and other data
> > > > covered by the federal Privacy Act. How do they send this info
> > > > without violating the Privacy Act?
> > >
> > >I worked for a major healthcare company (Doctors, Hospitals, and
> > >Insurance) for 5 years. We dealt with HIPPA (not Federal Privacy Act)
> > >every day. Some information is protected, but there are also
> > >exceptions and there is certainly needed information verses
> > >information that can be collected later.
> >
> > HIPPA and Privacy are slightly different ...
> > HIPPA deals with not sending a person's insurance info to places that
> > should not have it.
> > There is a cottage industry that has sprung up to screw this around
> > to say that it covers all aspects of medical privacy.
> > It does not, but that is what Privacy Acts and institutional privacy
> > policies are about.
> >
> > I know this is more than anyone would want or should want to know.
> >
> > Dr. Dave
> >
>
> -- 
> John D. Hays
> Amateur Radio Station K7VE <http://k7ve.ampr.org <http://k7ve.ampr.org>>
> PO Box 1223
> Edmonds, WA 98020-1223
> VOIP/SIP: [email protected] <mailto:john%40hays.org> <sip:[email protected] 
> <mailto:john%40hays.org>>
> Phone: 206-801-0820
> 801-790-0950
> Email: [email protected] <mailto:john%40hays.org> <mailto:[email protected] 
> <mailto:john%40hays.org>>
>
> [Non-text portions of this message have been removed]
>
> 

Reply via email to