Is encryption always required for stored ePHI?

No, encryption is addressable for stored ePHI.

Start playing free

  1. Encryption is always required
  2. Encryption is prohibited
  3. Encryption is addressable for stored ePHI ✔

Why: Encryption and decryption is an addressable access control. Covered entities must assess it for reasonableness and implement or document an equivalent.

Huh, didn't know that: The rule asks for a mechanism to encrypt and decrypt but does not name a specific method.

The dad joke
Why did the stored ePHI feel secure? It was encrypted and had a secret identity.
Like this card?
Play the game

References

Answer: Encryption is addressable for stored ePHI. Encryption and decryption is an addressable access control. Covered entities must assess it for reasonableness and implement or document an equivalent.

  1. 45 CFR 164.312(a)(2)(iv) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
    Encryption and decryption (Addressable). Implement a mechanism to encrypt and decrypt electronic protected health information.
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game