HIPAA Encryption Requirements & Standards For 2022
April 30, 2020
The Yes or No Question: Have you encrypted your ePHI data at rest and in transit?
Have you encrypted your electronic protected health information (ePHI) data at rest (being stored in persistent storage) and in transit (flowing from one point to another, whether it be over the internet or a private network)?
If your answer is “Yes”, you’re compliant with the HIPAA encryption standard and therefore covered by the Safe Harbor Rule in case of a breach. This means you’re not required to report the breach should one occur.
This post tells you what you need to know about successfully complying with HIPAA encryption requirements to protect ePHI.
Is the HIPAA Encryption Standard Required?
Currently, under HIPAA, the encryption standardis classified as an addressable implementation, not a required implementation. The question you may be asking yourself is, “Does this really mean ePHI data must be encrypted at rest and in transit?”
The answer is yes.
According to Deven McGraw, former Deputy Director of Health Information Privacy at the Department of Human and Health Services (HHS), an addressable specification does not mean it is optional.
“Addressable does not mean, 'well, maybe if I can get around to it,'” said McGraw. “'Addressable' means we expect you to do this. You must address encryption of data at rest and in transit."1
With that question answered, let’s move to what is required for successfully complying with HIPAA encryption standards.
Encrypting ePHI at rest and in transit can be expensive; however, it serves two purposes:
You’ll be compliant with the HIPAA encryption standard.
You’ll be protected under the Safe Harbor Rule in the event of a data breach.
This is because the Breach Notification Rule only applies to unsecured protected health information. As a result, by encrypting ePHI, protected health information becomes secure.
The best method to ensure you’re compliant with the HIPAA encryption standard is by following these steps:
Implement encryption on all devices that store or have access to ePHI.
Implement encryption for the transmission of ePHI when using unsecure methods such as email and removable media (USB flash drives, external hard drives, etc.).
Implement encryption for ePHI data at rest and in transit.
Stay up to date with current Federal and state legislation regarding breach notification requirements including encrypted patient data.
Maintain proper response and reporting for employees who are sending unencrypted ePHI.
Know and follow your corporate policies and procedures.
The Office for Civil Rights (OCR) does not specify HIPAA encryption requirements, but covered entities can find out more about encryption from the National Institute of Standards and Technology (NIST) – See SP 800-45 Version 2. NIST recommends the use of Advanced Encryption Standard (AES) 128, 192, or 256-bit encryption
When it comes to HIPAA, “addressable” does not mean “optional”. While the encryption standard is classified as an addressable implementation, HIPAA fully expects it to be done.
With Avertium, you get more rigor, more relevance, and more responsiveness. Don’t just comply, download our guide to HIPAA compliance today and show no weakness.