FaceTime calls are encrypted; and HIPAA compliant when using proper encryption
Summary: Apple gear is HIPAA compliant when using WPA2 Enterprise security. It's arguable that WPA and WPA/Personal connections are also compliant, but it's debatable.
Back in July 2010 Apple responded to a rumor that FaceTime calls were unencrypted saying that the entire FaceTime conversation stream is encrypted.
This raised an interesting question from an IT professional in local County government who wondered about the type of encryption Apple uses in FaceTime calls.
The reader wanted to know if Apple gear like the iPad and iPhone were HIPPA compliant, and eligible for government funds.
Government grants in the healthcare industry require HIPAA compliance. The section on Access Control requires systems ensuring that only authorized users are granted access to Electronic Protected Health Information (EPHI). While somewhat vaguely worded, strong encryption is the only practical means of meeting the government "authorized users" requirement.
An Apple representative involved with the iPad emailed me this response:
iPad supports WPA2 Enterprise to provide authenticated access to your enterprise wireless network. WPA2 Enterprise uses 128-bit AES encryption, giving users the highest level of assurance that their data will remain protected when they send and receive communications over a Wi-Fi network connection. In addition to your existing infrastructure each FaceTime session is encrypted end to end with unique session keys. Apple creates a unique ID for each FaceTime user, ensuring FaceTime calls are routed and connected properly.
Simply put, Apple gear is HIPPA compliant -- if your wireless connections use WPA2 Enterprise security. Some interpret the HHS requirement to include WPA and WPA2 Personal as compliant, but HIPAA is a big complex hairy monster and, well, it depends on several variables.
One thing's for sure: WEP is out, and you should avoid mentioning that swiss cheese security protocol around your friends at the U.S. Department of Health and Human Services -- if you want a check from the Feds, that is.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
RE: FaceTime calls are encrypted; and HIPPA compliant when using proper encryption
RE: FaceTime calls are encrypted; and HIPPA compliant when using proper encryption
fixed. thanks!
- Jason
RE: FaceTime calls are encrypted; and HIPPA compliant when using proper encryption
You still have a couple places where it is spelled wrong.
FaceTime on desktops also compliant
Apple's answer doesn't really resolve the question
To come to a conclusion about HIPAA, you need some information about the encryption strength provided by the FaceTime application for data passing across the internet (not just across your living room).
If Facetime's security depends on the WiFi encryption, then it's not adequately encrypted once the data is passing over the network beyond your access point. If FaceTime does not depend on the encryption of the WiFi network, then why bother including the WiFi information in the response -- tell us about the encryption strength provided by FaceTime itself.
RE: FaceTime calls are encrypted; and HIPPA compliant when using proper encryption
agreed.. it's the end to end encryption that matters most for hipaa...
What about FaceTime on iPhone?
RE: FaceTime calls are encrypted; and HIPPA compliant when using proper encryption
If you only use FaceTime internally I fail to see how HIPPA would even be involved.
I'm not a HIPPA expert but Apple has totally avoided the question. From the text of the response I suspect the call isn't encrypted to a level anyone other than Apple would find acceptable.
WPA2 May Not Be Enough
TKIP is also broken, so do not use it. But it's still available in WPA2, so it's not enough to specify WPA2, you must say WPA2 with AES encryption.
Also you should stick with AES-128. Some have been using AES-256, but weaknesses have been found with that.
RE: FaceTime calls are encrypted; and HIPPA compliant when using proper encryption
RE: FaceTime calls are encrypted; and HIPPA compliant when using proper encryption
RE: FaceTime calls are encrypted; and HIPPA compliant when using proper encryption
Hmmm
So really??
"Tech blog ZDNet also recently reported on a Health and Human Services update that requires all healthcare providers looking for government funds to be HIPAA compliant. In order to gain compliance, health care providers must update wifi security if they plan to use FaceTime. The HIPAA statute declares that, while WPA and WPA Personal may be acceptable depending on the circumstances, WEP security is not allowed."
Sounds to me like it really isnt the above are from 9/2011
FaceTime And HiPAA compliance
In mental health there are a lot of technologies that do abide by the HIPAA compliance policies. There is an independent comparison of them at this site www.telementalhealthcomparisons.com.