Encryption of ePHI
Encryption is "addressable", not optional: you either encrypt ePHI at rest and in transit, or document why not and use an equivalent safeguard. For email and cloud tools, encrypting is almost always the reasonable choice.
Encryption of ePHI at a glance
Under the HIPAA Security Rule, encryption of electronic protected health information is an addressable implementation specification, not an optional one. Covered entities and business associates must encrypt ePHI at rest and in transit, or document why encryption is not reasonable and appropriate and implement an equivalent safeguard. Properly encrypted PHI is also not "unsecured", which can remove breach-notification duties if a device or mailbox is lost.
| Rule | HIPAA Security Rule, 45 CFR 164.312(a)(2)(iv) and (e)(2)(ii) |
|---|---|
| Status | Addressable — implement, or document why not and use an equivalent measure |
| Applies to | Covered entities and business associates |
| Covers | ePHI at rest and in transit |
| Breach impact | Encrypted PHI per HHS guidance is not unsecured PHI |
The Security Rule names encryption twice: for data stored in your systems (“encryption and decryption”, 164.312(a)(2)(iv)) and for data sent over a network (“encryption”, 164.312(e)(2)(ii)). Both are addressable implementation specifications.
What “addressable” actually means
Addressable does not mean optional. Under 164.306(d)(3) you must assess whether encryption is reasonable and appropriate in your environment, and then either:
- implement it, or
- document why it is not reasonable and appropriate, and implement an equivalent alternative measure where that is reasonable.
For a practice sending patient information by email or storing it in a cloud service, it is hard to document a credible reason not to encrypt — encryption is built into most business-grade tools at no extra cost.
Why it matters beyond compliance
Encryption is also your best protection when something goes wrong. The Breach Notification Rule applies to unsecured PHI — information that has not been rendered unusable, unreadable or indecipherable using methods specified by HHS. If a properly encrypted laptop or mailbox is lost and the key is not compromised, notification obligations may not apply. An unencrypted one almost always means a breach analysis and, often, letters to patients.
What to check when choosing a tool
- At rest: is stored data encrypted by default, and does that include backups and attachments?
- In transit: does the service enforce TLS between servers, and what happens when the recipient’s server does not support it?
- To patients: if you email patients, can they read an encrypted message without installing software or creating an account?
- Keys: who holds the encryption keys, and is that covered by the vendor’s BAA?
Record the answers in your risk analysis — that is where the decision to encrypt (or the alternative you chose) should be documented.
Tools and services where this matters
- Cloud storage and file sharing →Tool
- HIPAA email services →Tool
- HIPAA hosting and cloud platforms →Tool
- Telehealth and video visits →Tool
Guides
Scenarios
Related requirements
Frequently asked questions
Is encryption required by HIPAA?
Encryption is an addressable specification: you must implement it if it is reasonable and appropriate, or document why not and implement an equivalent alternative. For email and cloud tools that handle PHI, encrypting is almost always the reasonable choice.
Does encryption help after a breach?
Yes. Breach notification duties apply to unsecured PHI. PHI encrypted in line with HHS guidance, with the key not compromised, is not unsecured.