Get Demo
↑

HIPAA Encryption Requirements: Addressable Today, Proposed Required in the NPRM

Encryption at rest and in transit under §164.312 is Addressable today — Jan 2025 NPRM proposed making it required; no final rule yet.

Published: September 2026 Compliance · HIPAA 8–12 min read

Teams search for “HIPAA encryption requirements” expecting a single mandatory cipher mandate. Under the current Security Rule, encryption/decryption (§164.312(a)(2)(iv)) and transmission encryption (§164.312(e)(2)(ii)) are Addressable implementation specifications. The January 2025 NPRM proposed elevating encryption expectations — that proposal is not final.

Related: HIPAA hub · 2025–2026 update · Cloud BAAs.

Required vs Addressable (Security Rule) — 45 CFR 164.306(d): Required implementation specifications must be implemented. Addressable specs: implement if reasonable and appropriate; if not, document why and implement an equivalent alternative measure if reasonable and appropriate. Addressable ≠ optional.

Security Rule NPRM — not final: Jan 6, 2025 NPRM (RIN 0945-AA22, 90 FR 898) proposed MFA, encryption at rest/in transit as required, and related enhancements. No final rule as of September 2026; Unified Agenda projects ~July 2027 (planning estimate). Current rule still governs — encryption at rest/transit remains addressable under §164.312 today.

What Applies Today

Practical Baseline

  1. Encrypt ePHI at rest on servers, databases, endpoints, and backups where feasible.
  2. Encrypt ePHI in transit (TLS for applications/APIs; VPN or equivalent for admin paths).
  3. Manage keys separately from data; restrict and log key-admin access.
  4. Record Addressable decisions in your Security Rule documentation set (6-year retention under 164.316(b)(2)).

How CyberSilo Helps

Document Encryption Decisions Before OCR Asks

Treat Addressable encryption as a risk decision with evidence — and prepare for possible future Required status.

Frequently Asked Questions

Is encryption mandatory under HIPAA?

Under the current Security Rule, relevant encryption specifications are Addressable, not universally Required. The 2025 NPRM proposed making encryption required — not final as of 2026.

What if we cannot encrypt a legacy system?

Document why encryption is not reasonable and appropriate and implement equivalent alternative measures where reasonable and appropriate (164.306(d)).

Does encryption eliminate breach notification?

Strong encryption can reduce risk in a breach analysis, but you must still assess and document; do not assume a blanket exemption without analysis.

HIPAA hub · §164.312 · MFA · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!