What provides safe harbor from HIPAA breach rules?

Properly encrypted PHI is not unsecured, so losing it is not a reportable breach.

Start playing free

  1. Properly encrypted PHI ✔
  2. PHI stored only on paper
  3. PHI with just the names crossed out

Why: Breach notices are only required for unsecured PHI. PHI made unusable, unreadable or indecipherable using HHS-approved methods, such as proper encryption, is not unsecured.

Huh, didn't know that: HHS guidance names two methods that secure PHI: encryption and destruction.

The dad joke
Why was the encrypted laptop so relaxed? It knew nobody could read its mind.
Like this card?
Play the game

References

Answer: Properly encrypted PHI. Breach notices are only required for unsecured PHI. PHI made unusable, unreadable or indecipherable using HHS-approved methods, such as proper encryption, is not unsecured.

  1. 45 CFR 164.402 (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402
    Unsecured protected health information means protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons
    Checked 2026-10-10.
  2. HHS Breach Notification Rule www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
    specifies encryption and destruction as the technologies and methodologies for rendering protected health information unusable, unreadable, or indecipherable
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game