I'm developing a SaaS in healthcare. Users are trusting my SaaS with their very private medical information.
I expect my platform (LAMP based) to be breached sooner or later and I'm looking for ways to minimize data leakage.
Currently I have
- user passwords hashed and salted
- user real names, phone numbers are in plain text
- user private medical data in plain text
I'm looking for some pointers where to look about this subject. All comments are appreciated!
It sounds like you are in over your head and the expectation of a security breach is unacceptable. Head over to US HHS Web Site - Health Information Privacy and start reading up on data management requirements in the US at least.