← Every path

H2-CHSE · Specialist path

Healthcare

H2 Certified Health Data Security Engineer

Build a system that handles patient data the way the law and the harm both demand. HIPAA and GDPR-special-category handling by design, health interoperability without leaks, consent that patients actually control, an audited access trail, and a breach playbook with a real clock.

6 courses · 19 lessons · ~33 h of guided work

Assumes Foundation + T-Shaped core; CIAE recommended

What you leave with

A patient-data platform in test mode: encrypted PHI storage, a FHIR interoperability layer, a patient consent engine, an immutable access audit trail, and a HIPAA/GDPR breach playbook.

Standards
FHIR / HL7
Identity
Zitadel
Keys
OpenBao
Database
PostgreSQL / CNPG
Audit
Merkle-anchored trail
De-id
Safe-harbor / k-anonymity

Syllabus

6 courses · every lesson graded · minutes are guided work

  1. Course 01

    Handling patient data by design

    PHI and GDPR special-category data as the highest-sensitivity thing you will ever store. Minimization, encryption, and de-identification that actually holds.

    4 lessons · ~7 h

    Tools PostgreSQL, OpenBao transit, de-identification tooling

    1. 01What counts as PHIThe identifiers, the special categories, and why the harm sets the bar, not the checkbox.90 min
    2. 02Minimization and retentionCollect the least, keep it the shortest; retention as code.90 min
    3. 03Field-level encryptionEncrypt PHI at the field, keys from a vault, searchable where it must be without leaking.120 min
    4. 04De-identificationSafe-harbor and k-anonymity; a re-identification attack on a naive export and the fix.120 min

    Course checkBuild a PHI store that resists a re-identification attempt on its de-identified export and leaks nothing in logs.

    You leave withAn encrypted PHI store with field-level encryption, minimized collection, and a de-identified export that survives a re-identification attempt.

  2. Course 02

    The record store and its trail

    A clinical record store where every read and write is provable, so an audit is a query, not an archaeology dig.

    3 lessons · ~6 h

    Tools PostgreSQL, hash-chained audit log, transparency anchoring

    1. 01Records and versionsClinical records with history; amend without overwrite, the medico-legal way.120 min
    2. 02The tamper-evident trailEvery read and write hash-chained and anchored, like the fintech ledger, for access instead of money.120 min
    3. 03Break-glass accessEmergency access that is allowed, logged, and reviewed after the fact.90 min

    Course checkGiven an access log, prove who read a given patient's record and when, from a trail that cannot be edited after the fact.

    You leave withA record store whose every access is written to a Merkle-anchored, tamper-evident trail.

  3. Course 03

    Health interoperability

    Share data with other systems through FHIR and HL7 without turning interoperability into a leak. The standard, and the security the standard leaves to you.

    3 lessons · ~6 h

    Tools FHIR, SMART-on-FHIR, Envoy Gateway

    1. 01FHIR and HL7The resources, the interactions, and where the standard stops and your security starts.120 min
    2. 02SMART-on-FHIRScoped, authorized access to resources; the OAuth profile health uses.120 min
    3. 03Sharing without leakingGranular scopes, and a probe that proves it cannot read past them.90 min

    Course checkExpose and consume FHIR resources across a trust boundary; a probe fails to read data outside the granted scope.

    You leave withA FHIR interoperability layer that shares exactly the granted resources and nothing more, over authenticated, scoped access.

  4. Course 04

    Patient consent

    Consent the patient controls and can withdraw, enforced at every access, not a checkbox at sign-up. Purpose limitation as running code.

    3 lessons · ~5 h

    Tools Cedar / OPA, the consent model, the record store

    1. 01Consent as a first-class objectPurpose, scope, expiry and withdrawal, modeled as data.90 min
    2. 02Enforcement at accessEvery access checked against live consent; withdrawal that takes effect immediately.120 min
    3. 03Purpose limitationData used only for the purpose consented; proven, not promised.90 min

    Course checkA patient withdraws consent for one purpose; prove that purpose is blocked immediately while others continue.

    You leave withA consent engine where a patient grants and withdraws by purpose, enforced at every access in real time.

  5. Course 05

    Audit and access governance

    Who could see what, and who did, answerable at any moment. The access governance a HIPAA audit and a GDPR request both demand.

    3 lessons · ~5 h

    Tools The anchored trail, SIEM, Zitadel

    1. 01Who could access whatLeast privilege across clinical roles; the access review as a query.90 min
    2. 02Who did access whatReading the trail; the report a HIPAA audit asks for.90 min
    3. 03Subject rightsAccess, rectification and erasure under GDPR, and the erasure that keeps the trail intact.120 min

    Course checkAnswer a subject-access request and an auditor's who-accessed-this query from the trail, within the legal window.

    You leave withAccess governance that answers a subject-access request and an audit query from an immutable trail, inside the legal window.

  6. Course 06

    Breach response for health data

    A health-data breach has a legal clock and a human cost. Containment, the notification timeline, and a rebuild that proves the trail held.

    3 lessons · ~5 h

    Tools The anchored trail, incident tooling, notification templates

    1. 01The notification clockHIPAA and GDPR timelines; when the clock starts and what it demands.90 min
    2. 02Containment and scopeContain the breach and prove, from the trail, exactly what was exposed.120 min
    3. 03Notification and aftermathWho you tell, in what order, and the review that follows.90 min

    Course checkA simulated PHI breach: contain it, run the notification clock, and prove from the trail exactly what was and was not exposed.

    You leave withA HIPAA/GDPR breach playbook with notification timelines, a containment you executed, and a trail that proves the scope of exposure.

Certification course

H2 Certified Health Data Security Engineer

$799 · one price · courses + 90-day labs + exam

48-hour practical: a compliance audit, an attack on the PHI store, a consent-violation attempt, and a breach with a notification clock. Graded on the access trail, PHI never exposed, consent enforced, and notifications on time.

Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.

Create an account to enrol