Secure E-Mail Gateway (SEG) Service Administrative Guides
Email Filtering Service
HIPAA Compliance Features
AT&T Secure E-Mail Gateway includes five HIPAA compliance rule selections for outbound e-mail content to help the customer manage their email filtering policies as they relate to Health Insurance Portability and Accountability Act of 1996.
1. Credit Card Numbers and Medical Terms
The “HIPAA Compliance - Credit Card Numbers and Medical Terms” rule uses a combination of keywords and regular expressions to detect the following Credit Cards: American Express, MasterCard, Visa, Diner Club, and Discover are used in conjunction with medical terms within an e-mail.
This means there must be match for a credit card content keyword, credit card number and medical terms to produce a violation.
The details for each card type are listed below. American Express
Match on any of the following keywords and keyword combinations: cc number credit card ccn account number amex american express
The Credit card number is evaluated as follows:
The check evaluates the first two numbers in string to determine if it matches American Express predefined numbers.
The remainder of the number string is evaluated for correct length.
A violation will occur when the number string is either 15 numbers with no spaces or spaces are present after the 4th and 11th digits.
American Express uses 15 digits in their credit card number is normally given in a format of XXXX XXXXXX XXXXX.
MasterCard
Match on any of the following keywords and keyword combinations: cc number credit card ccn account number master
The Credit card number is evaluated as follows:
The check evaluates the first two numbers in string to determine if it matches MasterCard predefined numbers.
The remainder of the number string is evaluated for correct length.
A violation will occur when the number string is either 16 numbers with no spaces or spaces are present after the 4th, 8th and 12th digits.
MasterCard uses 16 digits in their credit card number is normally given in a format of XXXX XXXX XXXX XXXX.
Visa
Match on any of the following keywords and keyword combinations: cc number credit card ccn account number visa
The Credit card number is evaluated as follows:
The check evaluates the first number in string to determine if it matches Visa predefined numbers.
The remainder of the number string is evaluated for correct length.
A violation will occur when the number string is either 16 numbers with no spaces or spaces are present after the 4th, 8th and 12th digits.
Visa uses 16 digits in their credit card number is normally given in a format of XXXX XXXX XXXX XXXX
Diner Club
Match on any of the following keywords and keyword combinations: cc number credit card ccn account number diners
The Credit card number is evaluated as follows:
The check evaluates the first three numbers in string to determine if it matches Diners Club predefined numbers.
The remainder of the number string is evaluated for correct length.
A violation will occur when the number string is either 14 numbers with no spaces or spaces are present after the 4th and 10th digits.
Diners Club uses 14 digits in their credit card number is normally given in a format of XXXX XXXXXX XXXX.
Discover
Match on any of the following keywords and keyword combinations: cc number
credit card
ccn
account number discover
The Credit card number is evaluated as follows:
The check evaluates the first four numbers in string to determine if it matches Discover predefined numbers.
The remainder of the number string is evaluated for correct length.
A violation will occur when the number string is either 16 numbers with no spaces or spaces are present after the 4th, 8th and 12 digits.
Discover uses 16 digits in their credit card number is normally given in a format of XXXX XXXX XXXX XXXX.
Medical Terms
The medical terms consist of commonly used terms in the healthcare industry and are proprietary.
2. Social Security Numbers and Medical Terms
The “HIPAA Compliance – Social Security Numbers and Medical Terms” rule use a
combination of keywords and regular expressions to detect when a social security number is used in conjunction with medical terms within an e-mail.
This means there must be match for a social security content keyword, social security number and medical terms to produce a violation.
Keyword Violations
Match on any of the following keywords and keyword combinations: social
soc sec ssn ssn#
The Social Security Number is evaluated as follows:
The check looks for strings of 9 numbers that match valid social security numbers. It will detect the following formats:
123456789 123-45-6789 123 45 6789 Medical Terms
The medical terms consist of commonly used terms in the healthcare industry and are proprietary.
3. Personal Health Info- Contains Social Security Numbers
The “HIPAA Compliance - Personal Health Info- Contains Social Security Numbers” rule use a combination of keywords and regular expressions to detect when a social security number is used in conjunction with Personal Health Information within an e-mail.
This means there must be match for a social security content keyword, social security number and personal health information to produce a violation.
Keyword Violations
Match on any of the following keywords and keyword combinations: social
soc sec ssn ssn#
The Social Security Number is evaluated as follows:
The check looks for strings of 9 numbers that match valid social security numbers. It will detect the following formats:
123456789 123-45-6789 123 45 6789
Personal Health Information
The Personal Health Information consists of commonly used terms in the healthcare industry and is proprietary.
4. Personal Health Info- Admission/Discharge Data
The “HIPAA Compliance - Personal Health Info- Admission/Discharge Data” rule use a combination of keywords to detect when Admission/Discharge data is used in an e-mail. There must be a combination of medical record and admission discharge terms to produce a violation.
Personal Health Info- Admission/Discharge Data
The Personal Health Information Admission/Discharge Data consists of commonly used terms in the healthcare industry and are proprietary.
5. Personal Health Info- Diagnosis Data
The “HIPAA Compliance - Personal Health Info- Diagnosis Data- Admission/Discharge Data” rule use a combination of keywords to detect when medical diagnosis data is used in an e-mail.
There must be a combination of medical diagnosis terms to produce a violation.
Personal Health Info- Diagnosis Data
The Personal Health Info- Diagnosis Data consists of commonly used terms in the healthcare industry and are proprietary.