A method for securing patient medical information for communication over a
potentially vulnerable system includes separating patient's medical file
into a demographics layer and a data layer, separately encrypting the
demographic layer and data layer using different encryption keys, and
providing servers in a communication and processing system with a
decryption key for the layer processed by such server. Medical file data
may be separated into more than two layers. Users accessing the system
are authenticated using standard techniques. By separately encrypting
different parts of a patient medical record, processing and communication
of patient medical files by intermediary servers is enabled without
risking disclosure of sensitive patient information if such servers are
compromised.