Definition
Encryption is a technical safeguard that can reduce the risk of unauthorized access to ePHI, while HIPAA requires a documented, risk-based analysis of appropriate measures.
In practice
- Transport encryption protects an API connection, while access control and logging still govern who can retrieve the response.
- A laptop control can combine full-disk encryption, device management, screen lock, and remote wipe.
Who this applies to
- Organizations storing or transmitting ePHI
- Cloud, SaaS, messaging, and backup providers
- Security and compliance teams documenting addressable specifications
What the rule asks for
- Assess encryption for relevant storage, transport, devices, backups, and interfaces.
- Document implementation decisions and alternatives when a specification is not implemented.
- Protect keys, credentials, and cryptographic configuration as part of the control.
How teams put it into practice
- Map where plaintext can exist, including memory, logs, exports, and support tools.
- Define key ownership, rotation, access, recovery, and revocation.
- Test encrypted backups and restore procedures rather than assuming encryption proves recoverability.
Common mistakes
- Claiming encryption makes an application HIPAA compliant.
- Encrypting a database while leaving exports or logs unprotected.
- Losing access to encrypted backups because key recovery was never tested.
Questions that come up
Is encryption required by HIPAA?
Encryption is an addressable implementation specification in the Security Rule. An organization must assess whether and how it should be implemented and document its decision.
References
- Security Rule technical safeguards HHS Office for Civil Rights