A front-desk workstation goes missing over a holiday weekend. It held a downloaded schedule export with 1,400 patient names, dates of birth, and appointment reasons. Whether you spend the next 60 days drafting individual notification letters, notifying HHS, and fielding a local news call comes down to one question: was that drive encrypted, and can you prove it? That is the practical weight behind the HIPAA encryption requirements, and it is why practice owners, privacy officers, and compliance leads need more than a vague sense that "IT handles encryption." This article covers exactly which regulatory provisions apply, what "addressable" obligates you to do, where the breach safe harbor kicks in, and what your documentation file needs to contain when a regulator asks.

The Two Citations Behind HIPAA Encryption Requirements

The Security Rule mentions encryption in exactly two implementation specifications, and both are labeled addressable.

45 CFR § 164.312(a)(2)(iv) sits under the Access Control standard. It asks you to "implement a mechanism to encrypt and decrypt electronic protected health information." In plain terms: data at rest, on servers, laptops, workstations, phones, tablets, backup drives, and thumb drives.

45 CFR § 164.312(e)(2)(ii) sits under the Transmission Security standard. It asks you to "implement a mechanism to encrypt electronic protected health information whenever deemed appropriate." That is data in motion: email, portal traffic, file transfers to your billing company, remote access sessions, and API calls to a clearinghouse.

You can read both in context in the HHS Security Rule text and guidance library. Notice what the rule does not say: it names no algorithm, no key length, and no product.

"Addressable" Is Not "Optional" — Here Is the Actual Obligation

This is the single most misread word in the Security Rule. Addressable means you must assess whether the specification is reasonable and appropriate for your environment, given your size, technical infrastructure, and the risks you identified in your risk analysis.

After that assessment, you have exactly three lawful paths:

  1. Implement the specification as written.
  2. Implement an equivalent alternative measure that achieves the same protective purpose, and document why the substitution is reasonable.
  3. Document that neither is reasonable and appropriate, and document why the standard is still satisfied without it.

Path three is nearly impossible to defend in 2025 for portable devices and internet transmission. Full-disk encryption ships free with current operating systems. TLS is the default for every mainstream email and web service. When encryption costs nothing and takes an afternoon, "not reasonable and appropriate" reads as "we never got around to it."

If you choose path two or three, the documentation is the deliverable. A one-line note in a policy binder is not enough. You need a dated memo signed by your Security Official that names the asset class, states the risk, describes the alternative control, and explains the reasoning.

Does Encryption Prevent a HIPAA Breach Notification? The Safe Harbor, Precisely

Yes, under specific conditions. Breach notification obligations under 45 CFR Part 164 Subpart D attach only to unsecured protected health information. HHS defines "unsecured" as PHI not rendered unusable, unreadable, or indecipherable to unauthorized individuals through a technology or methodology specified in its guidance.

The HHS guidance on rendering PHI unusable, unreadable, or indecipherable points to two approaches: encryption and destruction. For encryption, it points to NIST:

  • Data at rest — encryption consistent with NIST Special Publication 800-111, guide to storage encryption technologies for end user devices.
  • Data in motion — encryption that complies with FIPS 140-validated processes, including the NIST guidance on TLS implementations and IPsec/VPN configurations.

Two conditions matter enormously. First, the decryption key must not have been compromised in the same incident. A laptop with full-disk encryption and the passphrase on a sticky note under the keyboard is not protected PHI. Second, the encryption must have been active at the moment of the incident — a device that was powered on and unlocked when it was stolen may not qualify.

The safe harbor also does nothing against credentialed intrusion. If an attacker phishes a staff login and reads charts through your EHR interface, the data was decrypted for that session by design. Encryption is a control against lost, stolen, and intercepted data, not against stolen identity.

Build the Asset Inventory Before You Buy Anything

You cannot encrypt what you have not located. Before any technical work, your privacy officer and IT contact should walk the building and the vendor list together and produce a written inventory. Give it a column for each of these:

  • Asset name and owner
  • Does it create, receive, maintain, or transmit ePHI?
  • Encryption at rest: yes/no, method, date verified
  • Encryption in transit: yes/no, protocol, date verified
  • Where the key or recovery credential lives

The assets practices consistently miss: the scanner that drops PDFs to a network share, the digital X-ray or ultrasound console running an unsupported OS, the practice manager's personal laptop used for after-hours billing, the USB backup drive in the safe, the fax server, voicemail-to-email, and the old server sitting in a closet that nobody has powered down because "we might need the old records."

Encryption at Rest: What Good Looks Like by Asset Class

Workstations and Laptops

Enable native full-disk encryption on every machine that touches ePHI. Escrow recovery keys centrally — not in a spreadsheet on the same machine. Then generate a compliance report showing encryption status per device and save it with a date stamp. That report is your evidence.

Mobile Devices

Any phone or tablet with email, a chart app, or secure messaging needs device encryption, a passcode, screen-lock timeout, and remote wipe. If staff use personal devices, your BYOD policy needs to say so in writing and staff need to sign it. Enrollment records in your device management console are the evidence.

Servers, NAS, and On-Prem Backups

Encrypt backup media and offsite copies. This is where practices get burned: the production server is encrypted, and the backup drive rotating to the office manager's house is not. Ransomware response also depends on backups being both encrypted and offline.

Removable Media

The cleanest policy is a prohibition on unencrypted removable media, enforced technically through endpoint policy rather than trust. If clinicians need to hand imaging to a specialist, define the encrypted method and train to it.

Encryption in Transit: Email, Portals, and Everything Else

Email is where most practices have an unresolved gap. Opportunistic TLS between mail servers is common but not guaranteed for every recipient domain, and it does not protect the message once delivered. If your practice emails ePHI outside the organization, you need either enforced TLS to known partners or a secure message delivery mechanism with documented settings.

One nuance worth knowing: HHS has stated that a patient may request unencrypted email communication after being warned of the risk. That is the patient's right to receive communications in the manner they choose. Document the request and the warning. That accommodation does not extend to provider-to-provider or provider-to-vendor traffic.

For everything else — patient portal, telehealth, remote desktop, VPN, SFTP to the billing company, clearinghouse connections — confirm current TLS versions, disable legacy protocols, and record the configuration date. Traditional analog fax over the phone network is not encrypted and never has been; fax-to-email services introduce an internet leg that must be.

The Proposed Security Rule Update Would Remove the Addressable Escape Hatch

In January 2025, HHS published a Notice of Proposed Rulemaking to overhaul the Security Rule for the first time in over a decade. Among the proposals: eliminating the required/addressable distinction entirely and mandating encryption of ePHI at rest and in transit, with narrow, documented exceptions. The comment period closed in spring 2025, and as of this writing the rule is not final.

Do not wait for finalization to act. Every practice that treats encryption as mandatory today will need to do close to nothing when a final rule lands. Every practice still leaning on "it's only addressable" will be doing an emergency project on someone else's timeline.

What OCR Actually Asks For

In an investigation triggered by a breach report or a complaint, requests are documentary and specific. Expect to be asked to produce:

  • Your most recent risk analysis, dated, covering all systems that create, receive, maintain, or transmit ePHI — including the encryption determination for each asset class.
  • Your risk management plan showing what you did about identified encryption gaps and when.
  • Policies and procedures on device and media controls, transmission security, and encryption.
  • Evidence of implementation: encryption status reports, device management exports, TLS configuration records.
  • For any addressable specification you declined, the written justification and the equivalent alternative.

Insufficient or absent risk analysis remains one of the most frequently cited failures in OCR's enforcement work, and it is the finding that turns a small incident into a corrective action plan. Browse the HHS breach portal and you will see how many reported incidents in the 500+ category involve theft or loss of devices — a category encryption largely eliminates.

If your risk analysis is a spreadsheet someone started in 2019, it is time to rebuild it. Tools that generate a full HIPAA risk analysis and policy set will get you to a defensible dated document faster than a from-scratch effort.

Your Vendors Hold Your Keys — Put It in the BAA

Encryption at your perimeter means nothing if your transcription service stores audio on unencrypted volumes, or your billing company emails claim files in the clear. Under the Security Rule, business associates owe direct compliance, but you owe satisfactory assurances in writing.

When you refresh agreements, be specific. Your BAA should address encryption of ePHI at rest and in transit, who controls encryption keys, breach notification timelines to you (not just the outer statutory limit), subcontractor flow-down, and return or destruction of ePHI at termination.

If you are onboarding a vendor this month and do not have counsel on retainer for a one-page agreement, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, not a subscription — useful when the answer to "do we have a signed BAA on file?" needs to be yes before Friday.

A 30-Day Encryption Sprint You Can Actually Run

Days 1–7 — Inventory. Privacy officer and IT contact walk every location. Produce the asset table described above. Pull the vendor list from accounts payable and mark which ones touch ePHI.

Days 8–14 — Close the easy gaps. Turn on full-disk encryption everywhere it is off. Escrow keys. Enroll mobile devices. Verify backup encryption. Each change gets a date and an owner in the inventory.

Days 15–21 — Transit. Confirm TLS settings for email, portal, VPN, and file transfer. Document the secure method staff must use to send ePHI externally, and retrain the front desk on it. Ten minutes at a staff meeting, with a sign-in sheet.

Days 22–30 — Paper. Update the risk analysis with encryption findings. Write the justification memo for anything you could not encrypt — legacy imaging consoles are the usual candidate — and name the compensating controls: network segmentation, physical access restriction, no internet routing. Have the Security Official sign and date it. File it where you can find it in ten minutes.

The HIPAA encryption requirements do not demand perfection. They demand that you looked, decided deliberately, acted, and wrote it down. A practice that can produce a dated inventory, an encryption status report, and a signed justification memo is in a fundamentally different position than one relying on memory.

Next Step

Start with the inventory this week — it costs nothing and it tells you the size of the problem. Then make sure every vendor on that list has a current, encryption-specific agreement on file. If any are missing, build and export a signature-ready BAA and get it signed before the next chart leaves your network.