Skip to content
compliancebase
HIPAA164.312 — Encryption and Decryption

§164.312(a)(2)(iv)

Encryption and Decryption

HIPAA · 45 CFR Part 164 · Last verified August 2026

Objective

Implement a mechanism to encrypt and decrypt ePHI when the risk analysis determines it is reasonable and appropriate, or document an equivalent alternative.

Points of focus

  • Treat addressable as a documented risk decision, not an exemption
  • Encrypt ePHI across primary, replicated, and backup storage
  • Control encryption keys separately from protected data

Implementation notes

Enable managed encryption for databases, object stores, queues, logs, and backups; isolate key administration, monitor decrypt activity, and document compensating safeguards for any legacy exception. Operationalize treat addressable as a documented risk decision, not an exemption in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain storage encryption and key-management configurations with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a database is encrypted while exported support files and snapshots remain plaintext Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample storage encryption and key-management configurations with dates and named reviewers. Be ready to walk through how you detect and correct: a database is encrypted while exported support files and snapshots remain plaintext

Evidence auditors typically request:

  • Storage encryption and key-management configurations
  • Key access, rotation, and revocation records
  • Risk analysis for any unencrypted ePHI location

Common gaps

  • A database is encrypted while exported support files and snapshots remain plaintext
  • The same broad administrator role controls both encrypted data and its keys

Cross-Framework Mapping

FrameworkRequirementImplementation note
HIPAA§164.312(a)(2)(iv)This control
SOC 2CC6.1, CC7.2SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct.
ISO 27001A.5.15, A.8.15ISO controls offer reusable operational evidence without replacing the Security Rule analysis.
GDPRArticle 32Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope.

Primary sources

Frequently Asked Questions

Encryption and Decryption applies to the systems and commitments in your Security Rule scope. Translate the requirement into concrete operating workflows — treat addressable as a documented risk decision, not an exemption — with evidence stored where auditors and customers can sample it.

Lead with storage encryption and key-management configurations and pair it with key access, rotation, and revocation records. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a database is encrypted while exported support files and snapshots remain plaintext Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above