I had a discussion recently with a state IT administrator who scoffed at using Skype video for telemedicine connections because it was “insecure”. Since we’re doing exactly that for family connections and proposing it for (at least), connections for health-care interventions other than direct physician-to-patient conversations, I thought it would be helpful to do some more research; I found an interesting 3 part thread about using Skype, particularly for psychiatric consultations.
Skype hasn’t made all the details of its security system known, but it does have a lot of information online, and, assuming that they are telling the truth, it sounds like Skype is at least a secure as a cellphone conversation, and, as far as I know, every psychiatrist I know talks to people on cell phones without worrying that much about HIPAA violations.
Skype and modern cellphones use the same basic protocol to communicate (packet switching), but basically what happens is that when you make a call, Skype or your cellphone operator sets up a connection between you and the person you are calling and then steps out of the way, leaving you and that person to talk as if you had your own circuit. Both Skype and cellphones encrypt the data they send. If anything, the AES encryption method used by Skype is probably more secure than the 30-year old A5/1 encryption method used in most cellphones. AES is approved by the government for top secret information while A5/1 has already been partially broken.
I think that the real security issues with Skype (or with cellphones) are probably more with things like whether the government can compel Skype or your cellphone operator to tap into your conversations than with details of encryption or firewalls.
Until then, I think that doctors should give up talking to patients on cellphones before they get worried about whether Skype is secure.
Give up talking on cellphones?
The Telehealth.net discussion cited above is a little more nuanced…
On one end of the spectrum are professionals, both licensed and unlicensed who claim that HIPAA is not relevant to telecommunication video interactions with clients or patients. Some of these people state that even if HIPAA compliance is an issue, public VoIP platforms already have met HIPAA compliance requirements by being more than 128-bit encrypted. They consider themselves safe or safe enough, and many of them are already practicing on the open, public Internet, using systems such as Oovoo, Google Talk, Skype or any of a number of other VoIP video platforms.
At the other end of the spectrum are professionals who are more conservative. They seem to be choosing to either wait for more secure systems to be developed, or work in institutional settings where using equipment with stated HIPAA complaint technologies.
So … “It depends”. My guess is my IT manager friend is of the more conservative persuasion and that we would need to come up with some kind “compliance certification” to satisfy him.
May I suggest that Skype does secure calls (256-bit AES last I looked) but also clearly has the encryption keys because they do expose calls to law enforcement. The issue of business associate relationships arise from that. They might still qualify as a conduit, and I would generally argue that they do. The January final rule may have put the kaibosh on that, however.
All that aside, the existence of VSee makes it somewhat moot. With Skype being a very soft choice for telehealth, it makes sense to choose a more solid on that is in the same field in terms of price and usability but has much more solid security and adresses telehealth needs. I’m sure it won’t be the only one, either. Developers who want to address this market are popping up all over the place.