Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Phi Encryption topic
No spam. Unsubscribe anytime.
Deputy chief raises need for encrypted delivery of fire records containing PHI
Summary
Fire division staff said the department lacks an encrypted method to send records containing protected health information, prompting discussion about Office 365 licensing, Laserfiche links and HIPAA compliance.
Get email alerts on the Phi Encryption topic
No spam. Unsubscribe anytime.
Deputy Chief (Fire Division) told the Moraine Records Commission that many fire-related public-records requests include protected health information (PHI) and that the department currently lacks an encrypted method to deliver those records by email, causing delays and extra staff time.
"A lot of them involve protected health information. Currently we do not have a way to encrypt those files to send them through email, which causes us to delay the process of fulfilling these requests and also taking up more man hours," the Deputy Chief said, asking whether the city will be able to provide encrypted fulfillment going forward.
City IT staff said they are evaluating a citywide solution that would include updating Microsoft 365 licensing to provide end‑to‑end encryption for email but that the project is dependent on budget and a citywide procurement. "We are looking into that, so we're just stuck with a timetable on that," IT staff said.
Martinez, the city law director, advised that any provider or technical solution be familiar with HIPAA requirements. "I would make sure that whoever you're dealing with on that has experience and is familiar with those requirements so we make sure we don't run afoul of the HIPAA regulations," Martinez said, adding that encryption must be maintained through the entire transfer and that written authorization from requesters is commonly required.
Martinez and staff also noted an immediately available option: use Laserfiche to upload PHI records and send a password‑protected direct link to the requester, which is already HIPAA‑compliant in some configurations. Martinez described this approach as workable but more cumbersome than a simple encrypted email attachment.
Commissioners discussed staffing: the Deputy Chief said they currently assign one person in the fire division to handle these requests. Commissioners asked staff to share vendor‑evaluation materials and recommended that only trained, designated staff send PHI to minimize human error.
No formal action was taken; commissioners asked staff to continue exploring solutions and to provide additional information to the law director and IT staff.

