HIPAA encryption requirements are not absolute. The Security Rule labels encryption “addressable,” which means a practice must assess it and either use it or document a reasonable alternative, while audit controls are required outright. Encryption still carries a payoff that no other safeguard does, because under 45 CFR 164.402, protected health information (PHI) encrypted to the standard HHS describes is not “unsecured,” so its loss or theft does not trigger breach notification. This guide covers both points for small and specialty practices that send PHI by email and share files with other providers, payers and business associates (vendors that handle PHI on the practice’s behalf).
Does HIPAA require encryption of email and files?
No provision of the HIPAA Security Rule requires encryption in every case. Encryption of stored electronic PHI (164.312(a)(2)(iv)) and of transmitted electronic PHI (164.312(e)(2)(ii)) are both addressable implementation specifications. A practice has to assess whether encryption is reasonable and appropriate, then implement it or document why not and adopt an equivalent alternative.
Addressable does not mean optional. Section 164.306(d)(3) requires a practice to assess each addressable specification. If the practice decides not to implement one, it must “document why it would not be reasonable and appropriate to implement the implementation specification” and “implement an equivalent alternative measure if reasonable and appropriate.” For PHI that leaves the practice by email, over networks the practice does not control, that documentation is difficult to write.
What is the difference between required and addressable safeguards?
A required implementation specification must be implemented as written. An addressable one must be assessed against the practice’s own risks, size and costs, then implemented, replaced with an equivalent measure, or documented as not reasonable. Section 164.306(d) sets this out, and each specification in the rule carries one of the two labels.
Section 164.306(b)(2) lists what a practice may weigh when choosing security measures: its size, complexity and capabilities; its technical infrastructure; “the costs of security measures”; and “the probability and criticality of potential risks to electronic protected health information.” That flexibility is why a three-chair dental office and a hospital can meet the same standard in different ways.
The technical safeguards in 164.312 that matter most for email and file sharing are below.
| Requirement | Citation | Required/addressable | How PreVeil supports it |
|---|---|---|---|
| Access control | 164.312(a)(1) | Standard (required) | Only users holding the right keys can decrypt message contents, attachments and files |
| Unique user identification | 164.312(a)(2)(i) | Required | Each user has an individual account, with keys generated on that user’s devices |
| Encryption and decryption (stored electronic PHI) | 164.312(a)(2)(iv) | Addressable | Mail and PreVeil Drive files are stored encrypted end to end, with FIPS 140-3 validated cryptographic modules |
| Audit controls | 164.312(b) | Required (a standard with no implementation specifications) | Admin console and system logs on the Business plan record user and administrator activity |
| Person or entity authentication | 164.312(d) | Standard (required) | Decryption requires the private key held on the user’s own devices |
| Transmission security: encryption | 164.312(e)(2)(ii) | Addressable | Messages are encrypted on the sender’s device and stay encrypted in transit and in the recipient’s mailbox |
| Business associate contracts | 164.308(b)(1), (b)(3) | Written contract required | PreVeil signs a business associate agreement (BAA) |
Which safeguards are required rather than addressable?
Audit controls under 164.312(b) are required. The standard has no implementation specifications, so a practice must “implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.” Unique user identification and emergency access procedures under 164.312(a)(2) are also required.
Audit controls pair with information system activity review, a required specification under 164.308(a)(1)(ii)(D) that calls for regular review of “audit logs, access reports, and security incident tracking reports.” PreVeil’s admin console and system logs, available on the Business plan, give a practice’s security official that record, supporting both requirements.
What is the breach notification safe harbor for encrypted PHI?
The HIPAA Breach Notification Rule applies only to “unsecured protected health information.” Section 164.402 defines that as PHI “not rendered unusable, unreadable, or indecipherable to unauthorized persons” through a technology or method named in HHS guidance, and that guidance names encryption and destruction. PHI encrypted to that guidance is not unsecured, so its loss is not a notifiable breach.

HHS states the effect directly on its Breach Notification Rule page: entities “that secure information as specified by the guidance are relieved from providing notifications following the breach of such information.”
The guidance itself is titled “Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals.” For data at rest, it points to NIST Special Publication 800-111. For data in motion, it points to NIST Special Publications 800-52, 800-77 and 800-113, or others that are FIPS 140-2 validated. It also says decryption tools “should be stored on a device or at a location separate from the data they are used to encrypt or decrypt.”
Without the safe harbor, the obligations are substantial for a small practice:
- Each affected individual must be notified “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach” (164.404(b)).
- Breaches affecting 500 or more individuals are reported to HHS at the same time (164.408(b)). Smaller breaches go in a log reported to HHS within 60 days after the end of the calendar year (164.408(c)).
- A breach affecting more than 500 residents of a state or jurisdiction also requires notice to prominent media outlets there.
Email is where this matters most for many practices: email was the breach location in about a quarter of the 710 healthcare breaches reported to the HHS Office for Civil Rights in 2025.
Why does it matter who holds the encryption keys?
The safe harbor depends on PHI staying unreadable to unauthorized persons, and HHS says decryption tools belong on a device or at a location separate from the data. When the provider that stores a mailbox also manages its keys, a compromise at that provider can reach both. Keys held only on user devices keep them apart.
PreVeil uses the latter design: encryption keys stay on users’ devices, so PreVeil cannot access or decrypt a practice’s data. Message contents and attachments are encrypted end to end on the sender’s device, and files in PreVeil Drive are encrypted the same way.
Transport encryption such as TLS protects a message only while it moves between mail servers. End-to-end encryption keeps the message encrypted in the inbox as well. PreVeil works inside Outlook, Gmail and Apple Mail, and other providers, payers and business associates read and reply for free from their browser, with replies encrypted end to end.
Is an encrypted email vendor still a business associate?
Yes. HHS guidance on cloud computing says a provider that stores electronic PHI is a business associate “even if it does not hold a decryption key and therefore cannot view the information.” The narrow conduit exception covers transmission-only services, not storage. A practice needs a BAA with its encrypted email vendor, and PreVeil signs one.
A BAA must set out permitted uses and disclosures, require the vendor to comply with the Security Rule for electronic PHI, require reporting of breaches of unsecured PHI, and flow the same terms down to subcontractors (164.504(e)(2) and 164.314(a)(2)(i)). A vendor that cannot read PHI has less PHI it can expose, but the practice still owns its own vendor oversight under 164.308(b).
How does this apply to behavioral health and substance use treatment programs?
Substance use disorder treatment records covered by 42 CFR Part 2 now follow the HIPAA breach notification rules. Section 2.16(b) applies them to Part 2 programs “with respect to breaches of unsecured records,” so the encryption safe harbor carries over. Like HIPAA, Part 2 itself does not require encryption; it requires formal security policies and procedures.
Section 2.16(a) requires a Part 2 program to have “formal policies and procedures to reasonably protect against unauthorized uses and disclosures of patient identifying information.” The companion post on 42 CFR Part 2 and HIPAA covers the disclosure notice, consent and redisclosure rules for records sent by email.
Is HHS changing the encryption rules?
HHS has proposed to, but the change is a proposal only. HHS’s notice of proposed rulemaking published January 6, 2025 (90 FR 898) would make encryption of electronic PHI at rest and in transit required, with limited exceptions. It is not a final rule, and the current HIPAA Security Rule, which treats encryption as addressable, applies today.
Frequently asked questions
Is encryption required under HIPAA?
Encryption is addressable, not required. Sections 164.312(a)(2)(iv) and 164.312(e)(2)(ii) are both labeled addressable. A practice must assess encryption and either implement it or document why it is not reasonable and appropriate and adopt an equivalent alternative (164.306(d)(3)).
What counts as unsecured PHI?
Under 45 CFR 164.402, unsecured PHI is PHI not rendered unusable, unreadable or indecipherable to unauthorized persons through a technology or method named in HHS guidance. HHS names encryption, consistent with NIST standards, and destruction of the media.
Does a practice have to report a lost laptop or compromised mailbox if the PHI was encrypted?
If the PHI was encrypted consistent with HHS guidance and the decryption keys were kept separate from the data, it is not unsecured PHI, and HHS says entities that secure information this way are relieved from providing breach notifications.
Are audit logs required under HIPAA?
Yes. Audit controls under 164.312(b) are a required standard. Information system activity review under 164.308(a)(1)(ii)(D) is a required implementation specification that calls for regular review of records such as audit logs and access reports.
Does PreVeil sign a BAA?
Yes. PreVeil signs a business associate agreement with healthcare practices. HHS treats a cloud provider that stores electronic PHI as a business associate even when it cannot view the data.
Can PreVeil read a practice’s email or files?
No. PreVeil cannot access or decrypt message contents, attachments or files, because the encryption keys stay on users’ devices.
Sources
- 45 CFR 164.402, definitions (eCFR)
- HHS, Guidance to Render Unsecured PHI Unusable, Unreadable, or Indecipherable
- HHS, Breach Notification Rule
- 45 CFR 164.312, technical safeguards (eCFR)
- 45 CFR 164.306, security standards: general rules (eCFR)
- 45 CFR 164.308, administrative safeguards (eCFR)
- 45 CFR 164.404, notification to individuals (eCFR)
- 45 CFR 164.408, notification to the Secretary (eCFR)
- 45 CFR 164.504, business associate contracts (eCFR)
- HHS, Guidance on HIPAA and cloud computing
- 42 CFR 2.16, security for records (eCFR)
- Federal Register, HIPAA Security Rule NPRM, 90 FR 898 (Jan 6, 2025)
- U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal: Notice to the Secretary of HHS of Breach of Unsecured Protected Health Information, 2025 reports
How can a practice see how PreVeil maps to the HIPAA Security Rule?
A demo with PreVeil covers how it fits the practice’s email and file sharing.