§164.312(a)(2)(iv)
Encryption and Decryption
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Implement a mechanism to encrypt and decrypt ePHI when the risk analysis determines it is reasonable and appropriate, or document an equivalent alternative.
Points of focus
- Treat addressable as a documented risk decision, not an exemption
- Encrypt ePHI across primary, replicated, and backup storage
- Control encryption keys separately from protected data
Implementation notes
Enable managed encryption for databases, object stores, queues, logs, and backups; isolate key administration, monitor decrypt activity, and document compensating safeguards for any legacy exception. Operationalize treat addressable as a documented risk decision, not an exemption in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain storage encryption and key-management configurations with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a database is encrypted while exported support files and snapshots remain plaintext Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample storage encryption and key-management configurations with dates and named reviewers. Be ready to walk through how you detect and correct: a database is encrypted while exported support files and snapshots remain plaintext
Evidence auditors typically request:
- Storage encryption and key-management configurations
- Key access, rotation, and revocation records
- Risk analysis for any unencrypted ePHI location
Common gaps
- A database is encrypted while exported support files and snapshots remain plaintext
- The same broad administrator role controls both encrypted data and its keys
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | §164.312(a)(2)(iv) | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: §164.312(a)(2)(iv)