Products

Solutions

Resources

Partners

Community

About

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...HIPAA - Encrypting Registration FieldsHIPAA - Encrypting Registration Fields
Previous
 
Next
New Post
10/2/2009 7:11 AM
 

All,

I have an interesting dilemma. I have what I believe to be a pretty good idea for a health care site. My custom modules are pretty close to spot-on, and I have nearly everything ready for my soft launch. I have one problem. HIPAA requires there be absolutely no user-attributable data, and it would help me immensely to have the backing of the medical and insurance communities. My design is pretty secure, but I need to be able to encrypt all name fields and email in the database.

Does anyone have any suggestions on how to do this ether in code or with a third party module?

Any and all help is greatly appreciated!

Thanks,
B

 
New Post
10/2/2009 7:35 AM
 

problem is, that you need to encrypt data in two tables (ASPNET membership and DNN Users) and add encrytion to both (see http://blogs.iis.net/rakkimk/archive/2008/04/11/asp-net-using-the-same-encryption-method-used-by-activedirectorymembershipprovider-to-encrypt-secret-password-answer-and-store-it-in-ad.aspx for example)


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
10/2/2009 10:45 AM
 

Hi Sebastian

Thanks for your reply. I was thinking of that approach, and it really wouldn't be terribly difficult to pull off. My only concern there is the whole thing blows up if I ever decide to upgrade DNN. Not very scalable. It is too bad there is not a group of settings allowing the admins to encrypt additional fields (hint hint B-) )

I have looked into entire database or column level encryption, and since I am on SQL 2005, it would be an extremely pricey proposition.

I am also thinking that OpenId or similar might be the way to go. If my system ever gets corrupted, the user info isn't even there. Not sure though.

Thanks,

Bruce

 
New Post
10/3/2009 4:44 AM
 

Bruce, 

please be aware, that DNN uses MS Membership component, which is integrated using a provider, i.e. you would need to create your own membership provider implementation. Since provider interfaces are not subject to change, this should be a safe way for upgrades.

Simply using a different authentication provider (like OpenID, LiveID) will not solve your issue, becuase users still need a DNN account to set it up.


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...HIPAA - Encrypting Registration FieldsHIPAA - Encrypting Registration Fields


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out