2.2 Job-File Security, Equipment Protection, and HIPAA
Key Takeaways
- Security controls should match the court, agency, contract, and sensitivity rather than an invented universal technology mandate.
- HIPAA applies to covered entities and business associates; handling medical testimony does not automatically make every reporter a business associate.
- A business-associate relationship can arise when services for a covered entity involve creating, receiving, maintaining, or transmitting protected health information.
- Loss, theft, or suspected tampering requires preservation of evidence and prompt incident escalation through the authorized plan.
Protect the entire job, not just the audio
A CER handles a collection of related assets: recording files, channel data, annotations, case information, appearance sheets, exhibits, credentials, correspondence, and backups. An attacker or careless recipient can cause harm without altering the master audio. Security therefore combines physical, administrative, and technical controls.
| Control area | Reporter practice |
|---|---|
| Physical | Maintain custody, lock unattended equipment, use privacy screens where appropriate, and control removable media |
| Account | Use unique credentials, approved multifactor authentication, least privilege, and prompt access removal |
| Device | Apply authorized updates, endpoint protection, encryption required by policy, and secure configuration |
| Transfer | Verify recipients and use approved portals or encrypted channels |
| Backup | Keep authorized redundant copies, test recovery, and protect backup access |
| Audit | Preserve logs showing creation, access, transfer, correction, and disposition when the system provides them |
Avoid universal claims such as “all court audio must use AES-256” or “every reporter needs a federal fingerprint clearance.” A federal, state, local, or contractual environment may impose specific standards, but the requirement must come from the applicable authority. The CER exam tests judgment: know the assignment's security plan, protect against loss and tampering, and escalate when a control fails.
Tampering, loss, and theft
Before a job, minimize exposure: carry only required files, verify device encryption and login controls required by the assignment, and know whom to contact. During a job, keep equipment within controlled custody and prevent unauthorized connection of drives or peripherals. Afterward, transfer through the approved workflow and confirm receipt before disposing of a working copy under policy.
If a laptop or drive is missing, do not quietly substitute a backup and ignore the event. Report the loss promptly, identify the data and time window involved, preserve relevant logs, and follow remote-lock, credential-reset, notification, and evidence-preservation procedures. If a hash or system warning suggests alteration, preserve both the questioned and known reference files. A hash can help detect a difference; by itself it does not prove who changed a file, when it changed, or that the original content was accurate.
HIPAA: apply the definitions
The Health Insurance Portability and Accountability Act rules apply to covered entities and business associates. The U.S. Department of Health and Human Services explains that an entity outside those definitions does not have to comply with the HIPAA Rules merely because it encounters health information. A business associate generally performs specified functions or services for a covered entity that involve creating, receiving, maintaining, or transmitting protected health information (PHI). Legal and transcription services can qualify depending on the relationship.
For a reporter, the correct analysis is contextual:
- Is the client or party a HIPAA covered entity, such as a covered health provider or plan?
- Is the reporter or reporting firm performing a function or service for that entity involving PHI?
- Is the work instead part of a court process, independent litigation service, or relationship that does not meet the business-associate definition?
- What contract, protective order, privacy rule, or state law applies even if HIPAA does not?
If the reporting firm is a business associate, a written business-associate contract or arrangement generally defines permitted uses and required safeguards. Subcontractors handling PHI on behalf of a business associate may also have duties. But do not assume that every personal-injury deposition automatically requires the reporter to sign a BAA with every lawyer. Route classification and contract questions to authorized privacy or legal personnel.
Safeguard first while status is resolved
Even when HIPAA applicability is uncertain, AAERT confidentiality duties and case orders still require protection. Limit access, avoid medical details in filenames or subject lines, use the designated platform, and do not place real case data into unapproved speech-recognition or generative-AI services. Consumer service terms may permit retention or model training that conflicts with the assignment.
Relevant primary guidance includes the HHS business-associate guidance and HHS covered-entity overview. Sources checked September 15, 2026.
Exam application
Compare two medical matters. A hospital hires a reporting vendor to perform services involving its patients' PHI; that relationship may support business-associate duties and a written agreement. In a separate public hearing, testimony happens to mention a diagnosis, but the reporter is not performing a HIPAA-regulated function for a covered entity. HIPAA status may differ, yet AAERT confidentiality and the hearing's rules still require careful handling in both. On the exam, reject both extremes: medical words always trigger HIPAA, and court reporting can never involve HIPAA.
Which statement best describes HIPAA for an electronic reporter?