HIPAA encryption requirements
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
"Addressable" does not mean optional. With ePHI it means: encrypt it, or write a very good explanation of why you did not — and there rarely is one.
Addressable, not optional
HIPAA labels some specifications "required" and others "addressable." Encryption of ePHI is addressable — which many teams misread as "optional." It actually means: implement the control, or document why it is not reasonable and what equivalent measure you use instead. Skipping it without justification is non-compliant.
Why you should just encrypt
For ePHI, the bar to justify not encrypting is very high — modern cloud platforms make encryption at rest and in transit nearly free, so "it was not reasonable" is hard to argue. Treat encryption of ePHI as expected: TLS in transit, encryption at rest on databases, storage, and backups.
The breach safe harbour
Encryption does double duty: properly encrypted PHI is generally not "unsecured," so a breach of it typically does not trigger the notification rule. That makes encryption not just a safeguard but a direct reducer of your breach exposure — a strong second reason to do it everywhere ePHI lives.
Key management still applies
As always, encryption is only as strong as key management — keys in a managed service, access-controlled, rotated. SentinelPanda tracks the encryption controls over ePHI and links them to the configuration evidence.