Encrypting Regulated Data | |
Regulations that cover personal, medical or financial data - HIPAA, GDPR, PCI DSS - do not certify file formats or libraries. Where they ask for encryption they point to current guidance, which names AES (NIST SP 800-111 for stored data). This topic says how to produce pdf documents that meet that bar, and what pdf encryption does and does not protect.
Setting a password is enough: the document is encrypted with AES and a 256-bit key (revision 6 of the pdf security handler, EncryptKey256BitRevision6 with AES). This applies to a new document and to the html to pdf converter's SecurityOptions.
Every current pdf viewer opens these documents. Viewers older than Adobe Acrobat X (2010) do not; if you must support them, choose AES with a 128-bit key rather than RC4.
RC4, with a 40-bit or a 128-bit key. It is broken and is supported only for old viewers.
An owner password without a user password. Anyone can then open the document; the permissions (printing, copying, editing) are honoured by compliant viewers, but they are not what keeps the content confidential. The user password is.
Passwords written into source code or configuration files in plain text.
AES-256-GCM (AESGCM) is available as well. It is defined by PDF 2.0, so choosing it writes the document as PDF 2.0, which only recent viewers open.
By default everything is encrypted. Set EncryptMetadata (or EncryptMetadata for a conversion) to false to leave the document's XMP metadata packet readable - by a search index or a document management system - while the content stays encrypted. Leave it true when the metadata itself identifies a person: a title such as a patient's name is personal data too. The document information entries (title, author, keywords) are encrypted either way.
PDF/A does not allow encryption, and a PDF/A document with a password is refused. Protect an archived document at the storage level instead.
// html to pdf: a password is enough for AES-256 HtmlToPdf converter = new HtmlToPdf(); converter.Options.SecurityOptions.UserPassword = userPassword; converter.Options.SecurityOptions.OwnerPassword = ownerPassword; converter.Options.SecurityOptions.CanCopyContent = false; PdfDocument doc = converter.ConvertUrl(url); doc.Save(file); doc.Close();