Skip to content

HIPAA encryption requirements

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA

"Addressable" does not mean optional. With ePHI it means: encrypt it, or write a very good explanation of why you did not — and there rarely is one.

Addressable, not optional

HIPAA labels some specifications "required" and others "addressable." Encryption of ePHI is addressable — which many teams misread as "optional." It actually means: implement the control, or document why it is not reasonable and what equivalent measure you use instead. Skipping it without justification is non-compliant.

Why you should just encrypt

For ePHI, the bar to justify not encrypting is very high — modern cloud platforms make encryption at rest and in transit nearly free, so "it was not reasonable" is hard to argue. Treat encryption of ePHI as expected: TLS in transit, encryption at rest on databases, storage, and backups.

The breach safe harbour

Encryption does double duty: properly encrypted PHI is generally not "unsecured," so a breach of it typically does not trigger the notification rule. That makes encryption not just a safeguard but a direct reducer of your breach exposure — a strong second reason to do it everywhere ePHI lives.

Key management still applies

As always, encryption is only as strong as key management — keys in a managed service, access-controlled, rotated. SentinelPanda tracks the encryption controls over ePHI and links them to the configuration evidence.

Encryption at rest and in transit The HIPAA Breach Notification Rule HIPAA technical safeguards

Run your compliance program in one workspace.