H2-CHSE · Specialist path
Healthcare
H2 Certified Health Data Security Engineer
Build a system that handles patient data the way the law and the harm both demand. HIPAA and GDPR-special-category handling by design, health interoperability without leaks, consent that patients actually control, an audited access trail, and a breach playbook with a real clock.
6 courses · 19 lessons · ~33 h of guided work
Assumes Foundation + T-Shaped core; CIAE recommended
What you leave with
A patient-data platform in test mode: encrypted PHI storage, a FHIR interoperability layer, a patient consent engine, an immutable access audit trail, and a HIPAA/GDPR breach playbook.
- Standards
- FHIR / HL7
- Identity
- Zitadel
- Keys
- OpenBao
- Database
- PostgreSQL / CNPG
- Audit
- Merkle-anchored trail
- De-id
- Safe-harbor / k-anonymity
Syllabus
6 courses · every lesson graded · minutes are guided work
Course 01
Handling patient data by design
PHI and GDPR special-category data as the highest-sensitivity thing you will ever store. Minimization, encryption, and de-identification that actually holds.
4 lessons · ~7 h
Tools PostgreSQL, OpenBao transit, de-identification tooling
- 01What counts as PHIThe identifiers, the special categories, and why the harm sets the bar, not the checkbox.90 min
- 02Minimization and retentionCollect the least, keep it the shortest; retention as code.90 min
- 03Field-level encryptionEncrypt PHI at the field, keys from a vault, searchable where it must be without leaking.120 min
- 04De-identificationSafe-harbor and k-anonymity; a re-identification attack on a naive export and the fix.120 min
Course checkBuild a PHI store that resists a re-identification attempt on its de-identified export and leaks nothing in logs.
You leave withAn encrypted PHI store with field-level encryption, minimized collection, and a de-identified export that survives a re-identification attempt.
Course 02
The record store and its trail
A clinical record store where every read and write is provable, so an audit is a query, not an archaeology dig.
3 lessons · ~6 h
Tools PostgreSQL, hash-chained audit log, transparency anchoring
- 01Records and versionsClinical records with history; amend without overwrite, the medico-legal way.120 min
- 02The tamper-evident trailEvery read and write hash-chained and anchored, like the fintech ledger, for access instead of money.120 min
- 03Break-glass accessEmergency access that is allowed, logged, and reviewed after the fact.90 min
Course checkGiven an access log, prove who read a given patient's record and when, from a trail that cannot be edited after the fact.
You leave withA record store whose every access is written to a Merkle-anchored, tamper-evident trail.
Course 03
Health interoperability
Share data with other systems through FHIR and HL7 without turning interoperability into a leak. The standard, and the security the standard leaves to you.
3 lessons · ~6 h
Tools FHIR, SMART-on-FHIR, Envoy Gateway
- 01FHIR and HL7The resources, the interactions, and where the standard stops and your security starts.120 min
- 02SMART-on-FHIRScoped, authorized access to resources; the OAuth profile health uses.120 min
- 03Sharing without leakingGranular scopes, and a probe that proves it cannot read past them.90 min
Course checkExpose and consume FHIR resources across a trust boundary; a probe fails to read data outside the granted scope.
You leave withA FHIR interoperability layer that shares exactly the granted resources and nothing more, over authenticated, scoped access.
Course 04
Patient consent
Consent the patient controls and can withdraw, enforced at every access, not a checkbox at sign-up. Purpose limitation as running code.
3 lessons · ~5 h
Tools Cedar / OPA, the consent model, the record store
- 01Consent as a first-class objectPurpose, scope, expiry and withdrawal, modeled as data.90 min
- 02Enforcement at accessEvery access checked against live consent; withdrawal that takes effect immediately.120 min
- 03Purpose limitationData used only for the purpose consented; proven, not promised.90 min
Course checkA patient withdraws consent for one purpose; prove that purpose is blocked immediately while others continue.
You leave withA consent engine where a patient grants and withdraws by purpose, enforced at every access in real time.
Course 05
Audit and access governance
Who could see what, and who did, answerable at any moment. The access governance a HIPAA audit and a GDPR request both demand.
3 lessons · ~5 h
Tools The anchored trail, SIEM, Zitadel
- 01Who could access whatLeast privilege across clinical roles; the access review as a query.90 min
- 02Who did access whatReading the trail; the report a HIPAA audit asks for.90 min
- 03Subject rightsAccess, rectification and erasure under GDPR, and the erasure that keeps the trail intact.120 min
Course checkAnswer a subject-access request and an auditor's who-accessed-this query from the trail, within the legal window.
You leave withAccess governance that answers a subject-access request and an audit query from an immutable trail, inside the legal window.
Course 06
Breach response for health data
A health-data breach has a legal clock and a human cost. Containment, the notification timeline, and a rebuild that proves the trail held.
3 lessons · ~5 h
Tools The anchored trail, incident tooling, notification templates
- 01The notification clockHIPAA and GDPR timelines; when the clock starts and what it demands.90 min
- 02Containment and scopeContain the breach and prove, from the trail, exactly what was exposed.120 min
- 03Notification and aftermathWho you tell, in what order, and the review that follows.90 min
Course checkA simulated PHI breach: contain it, run the notification clock, and prove from the trail exactly what was and was not exposed.
You leave withA HIPAA/GDPR breach playbook with notification timelines, a containment you executed, and a trail that proves the scope of exposure.
Certification course
H2 Certified Health Data Security Engineer
$799 · one price · courses + 90-day labs + exam
48-hour practical: a compliance audit, an attack on the PHI store, a consent-violation attempt, and a breach with a notification clock. Graded on the access trail, PHI never exposed, consent enforced, and notifications on time.
Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.
Create an account to enrol