Hacker News new | ask | show | jobs
by scdc 4289 days ago
Curious-- do you define a running database system (e.g. MySQL) to contain "data at rest", "data in transit" or neither?

My reading says "neither". Conservative move is "encrypt everything" but curious if others have passed/failed a HIPAA audit with a standard MySQL or SQL Server system (assuming you have individual ID access & logging).