Which identifiers are highest risk?

In the context of HIPAA and Spirion data governance, the "highest risk" identifiers are those that provide direct, unambiguous identification of an individual and are most frequently targeted for identity theft or medical fraud.

In Spirion, these should be mapped to your "Restricted" or "Level 3" classification labels and should trigger the most aggressive remediation actions (like automated quarantine or encryption).

1. The "High-Risk Trio" (Direct Identifiers)

These three identifiers are considered the highest risk because they are "hard" identifiers that are difficult to change and provide immediate access to a person's legal and financial identity.

  • Social Security Number (SSN): The single most sensitive identifier. In Spirion, use the AnyFind: Social Security Number with validation enabled.
  • Medical Record Number (MRN): The primary key for a patient's entire clinical history. Exposure of MRNs can lead to large-scale medical identity theft.
  • Health Insurance Claim Number (HICN) / Member ID: These provide direct access to billing and insurance benefits.

2. Clinical Context Identifiers (High Signal)

These are high risk because they reveal the nature of the health condition, which is the core of what HIPAA seeks to protect.

  • ICD-9 / ICD-10 Codes: These codes explicitly define a patient's diagnosis.
  • Health Information (AnyFind): Spirion's built-in detector for clinical terms, medications, and treatment descriptions.

3. Financial Identifiers (Overlapping Risk)

While technically governed by PCI-DSS, these are high risk in a healthcare setting because they are often stored alongside PHI in billing systems.

  • Credit Card Numbers (PAN): High risk for immediate financial fraud.
  • Bank Account Numbers: High risk for unauthorized withdrawals or fraudulent billing.


Risk Ranking Table for Spirion Playbooks

Risk Level

Identifiers

Recommended Spirion Action

CRITICAL

SSN, MRN, ICD-10 Codes, Credit Card #

Quarantine or Shred (if expired)

HIGH

Name + DOB, Insurance ID, Health Info

Encrypt and Classify: Restricted

MEDIUM

Address, Phone, Email, IP Address

Classify: Confidential and Notify Owner


How to Prioritize These in Spirion v13.6

  1. Use SDDs for "Critical" Risk: Create an SDD that triggers only when a Direct Identifier (SSN/MRN) is found NEAR a Clinical Identifier (ICD-10/Health Info). This represents your "True North" for critical risk.
  2. Automate Remediation: For the Critical category, don't wait for manual review. Use an Automatic Playbook to move these files to a secure quarantine location immediately upon discovery.
  3. Monitor via Governance Dashboard: Set up a specific widget in your Governance Dashboard that tracks only these "Critical" identifiers. This allows you to report to leadership on your "Highest Risk Exposure" separately from general PII.
  4. Check Queue Health: Because these are high-priority findings, ensure your shipper_queue is processing correctly in v13.6 so that these critical alerts reach the console without delay.

Summary Recommendation

Focus your initial remediation efforts on SSNs, MRNs, and ICD Codes. These are the "crown jewels" of patient data and represent the highest legal, financial, and reputational risk if exposed.