SESK: Stuff Everyone Should Know · sesk.info/hipaa-encrypted-safe-harbor
What provides safe harbor from HIPAA breach rules?
Properly encrypted PHI is not unsecured, so losing it is not a reportable breach.
- Properly encrypted PHI ✔
- PHI stored only on paper
- PHI with just the names crossed out
Why: Breach notices are only required for unsecured PHI. PHI made unusable, unreadable or indecipherable using HHS-approved methods, such as proper encryption, is not unsecured.
Huh, didn't know that: HHS guidance names two methods that secure PHI: encryption and destruction.
Why was the encrypted laptop so relaxed? It knew nobody could read its mind.
Like this card?
References
Answer: Properly encrypted PHI. Breach notices are only required for unsecured PHI. PHI made unusable, unreadable or indecipherable using HHS-approved methods, such as proper encryption, is not unsecured.
- 45 CFR 164.402 (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402
Unsecured protected health information means protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons
Checked 2026-10-10. - HHS Breach Notification Rule www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
specifies encryption and destruction as the technologies and methodologies for rendering protected health information unusable, unreadable, or indecipherable
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.