SESK: Stuff Everyone Should Know · sesk.info/hipaa-encryption-stored-addressable
Is encryption always required for stored ePHI?
No, encryption is addressable for stored ePHI.
- Encryption is always required
- Encryption is prohibited
- Encryption is addressable for stored ePHI ✔
Why: Encryption and decryption is an addressable access control. Covered entities must assess it for reasonableness and implement or document an equivalent.
Huh, didn't know that: The rule asks for a mechanism to encrypt and decrypt but does not name a specific method.
Why did the stored ePHI feel secure? It was encrypted and had a secret identity.
Like this card?
References
Answer: Encryption is addressable for stored ePHI. Encryption and decryption is an addressable access control. Covered entities must assess it for reasonableness and implement or document an equivalent.
- 45 CFR 164.312(a)(2)(iv) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
Encryption and decryption (Addressable). Implement a mechanism to encrypt and decrypt electronic protected health information.
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.