Data Encryption
CentriCare implement End-to-End Encryption (E2EE) to information that considered as part of PHI. Encryption are done in two ways, Deterministic Encryption and Random Encryption.
This because there are two types of information (queryable and non-queryable) we want to conceal as describe here.
graph TD
subgraph C[Client]
PHI[Protected Information]
P[Presentation]
E[Encryption]
PHI -->|encrypt| E
E -->|decrypt| P
end
S[Server]
DB[Database]
E <-->|exchange| S
S -->|store encrypted data| DB
Configuration
Encryption and decryption must be consistent across the CentriCare ecosystem to maintain data integrity. That's why you need to follow these standard configuration.
- Use AES-256-CBC algorithm with IV derived from the plain text (using HMAC) for deterministic encryption
- Use AES-256-GCM algorithm with random IV in this format
{iv}:{authTag}:{encryption}(each part use hex encoding) for random encryption - Every organization will get their own secret key to encrypt and decrypt information. Changing these key must be followed by re-encryption process using the new key
- Use deterministic encryption for queryable data or data that will be used as query parameter. And use random encryption for data that will never be used as query parameter
- Only specific part of data or document need protection that will be encrypted (Selective Field-Level Encryption)
In specific case like integration with SatuSehat or BPJS encrypted data will be handled by Trusted Bridging Gateway that has the ability to decrypt the data using the organization secret key.
Trusted Bridging Gateway are a proprietary gateway that are trusted to decrypt encrypted data before serving it to external service or system.