Topic summary
Encrypted

Extracted from the Wikipedia article Encryption.
Regulatory compliance
Encryption plays a central role in meeting regulatory requirements for the protection of sensitive data. Under the HIPAA Security Rule, encryption of electronic protected health information (ePHI) is classified as an "addressable" implementation specification, meaning covered entities must implement it or document why an equivalent alternative measure is reasonable and appropriate. Notably, the HIPAA Breach Notification Rule provides a safe harbor for encrypted data: breaches involving ePHI that has been encrypted in accordance with NIST standards are not considered reportable breaches. A proposed update to the HIPAA Security Rule (NPRM, December 2024) would make encryption of ePHI at rest and in transit a mandatory requirement, removing its current "addressable" status.