HIPAA encryption requirements are not absolute. The Security Rule labels encryption “addressable,” which means a practice must assess it and either use it or document a reasonable alternative, while audit controls are required outright. Encryption still carries a payoff that no other safeguard does, because under 45 CFR 164.402, protected health information (PHI) encrypted to the standard HHS describes is not “unsecured,” so its loss or theft does not trigger breach notification. This guide covers both points for small and specialty practices that send PHI by email and share files with other providers, payers and business associates (vendors that handle PHI on the practice’s behalf).

Does HIPAA require encryption of email and files?

No provision of the HIPAA Security Rule requires encryption in every case. Encryption of stored electronic PHI (164.312(a)(2)(iv)) and of transmitted electronic PHI (164.312(e)(2)(ii)) are both addressable implementation specifications. A practice has to assess whether encryption is reasonable and appropriate, then implement it or document why not and adopt an equivalent alternative.

Addressable does not mean optional. Section 164.306(d)(3) requires a practice to assess each addressable specification. If the practice decides not to implement one, it must “document why it would not be reasonable and appropriate to implement the implementation specification” and “implement an equivalent alternative measure if reasonable and appropriate.” For PHI that leaves the practice by email, over networks the practice does not control, that documentation is difficult to write.

What is the difference between required and addressable safeguards?

A required implementation specification must be implemented as written. An addressable one must be assessed against the practice’s own risks, size and costs, then implemented, replaced with an equivalent measure, or documented as not reasonable. Section 164.306(d) sets this out, and each specification in the rule carries one of the two labels.

Section 164.306(b)(2) lists what a practice may weigh when choosing security measures: its size, complexity and capabilities; its technical infrastructure; “the costs of security measures”; and “the probability and criticality of potential risks to electronic protected health information.” That flexibility is why a three-chair dental office and a hospital can meet the same standard in different ways.

The technical safeguards in 164.312 that matter most for email and file sharing are below.

RequirementCitationRequired/addressableHow PreVeil supports it
Access control164.312(a)(1)Standard (required)Only users holding the right keys can decrypt message contents, attachments and files
Unique user identification164.312(a)(2)(i)RequiredEach user has an individual account, with keys generated on that user’s devices
Encryption and decryption (stored electronic PHI)164.312(a)(2)(iv)AddressableMail and PreVeil Drive files are stored encrypted end to end, with FIPS 140-3 validated cryptographic modules
Audit controls164.312(b)Required (a standard with no implementation specifications)Admin console and system logs on the Business plan record user and administrator activity
Person or entity authentication164.312(d)Standard (required)Decryption requires the private key held on the user’s own devices
Transmission security: encryption164.312(e)(2)(ii)AddressableMessages are encrypted on the sender’s device and stay encrypted in transit and in the recipient’s mailbox
Business associate contracts164.308(b)(1), (b)(3)Written contract requiredPreVeil signs a business associate agreement (BAA)

Which safeguards are required rather than addressable?

Audit controls under 164.312(b) are required. The standard has no implementation specifications, so a practice must “implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.” Unique user identification and emergency access procedures under 164.312(a)(2) are also required.

Audit controls pair with information system activity review, a required specification under 164.308(a)(1)(ii)(D) that calls for regular review of “audit logs, access reports, and security incident tracking reports.” PreVeil’s admin console and system logs, available on the Business plan, give a practice’s security official that record, supporting both requirements.

What is the breach notification safe harbor for encrypted PHI?

The HIPAA Breach Notification Rule applies only to “unsecured protected health information.” Section 164.402 defines that as PHI “not rendered unusable, unreadable, or indecipherable to unauthorized persons” through a technology or method named in HHS guidance, and that guidance names encryption and destruction. PHI encrypted to that guidance is not unsecured, so its loss is not a notifiable breach.

Flow diagram: if lost PHI was encrypted per HHS guidance with keys kept separate, it is not unsecured PHI under 45 CFR 164.402 and no breach notification is required; otherwise individuals are notified within 60 days and HHS is notified under 164.408.

HHS states the effect directly on its Breach Notification Rule page: entities “that secure information as specified by the guidance are relieved from providing notifications following the breach of such information.”

The guidance itself is titled “Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals.” For data at rest, it points to NIST Special Publication 800-111. For data in motion, it points to NIST Special Publications 800-52, 800-77 and 800-113, or others that are FIPS 140-2 validated. It also says decryption tools “should be stored on a device or at a location separate from the data they are used to encrypt or decrypt.”

Without the safe harbor, the obligations are substantial for a small practice:

  • Each affected individual must be notified “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach” (164.404(b)).
  • Breaches affecting 500 or more individuals are reported to HHS at the same time (164.408(b)). Smaller breaches go in a log reported to HHS within 60 days after the end of the calendar year (164.408(c)).
  • A breach affecting more than 500 residents of a state or jurisdiction also requires notice to prominent media outlets there.

Email is where this matters most for many practices: email was the breach location in about a quarter of the 710 healthcare breaches reported to the HHS Office for Civil Rights in 2025.

Why does it matter who holds the encryption keys?

The safe harbor depends on PHI staying unreadable to unauthorized persons, and HHS says decryption tools belong on a device or at a location separate from the data. When the provider that stores a mailbox also manages its keys, a compromise at that provider can reach both. Keys held only on user devices keep them apart.

PreVeil uses the latter design: encryption keys stay on users’ devices, so PreVeil cannot access or decrypt a practice’s data. Message contents and attachments are encrypted end to end on the sender’s device, and files in PreVeil Drive are encrypted the same way.

Transport encryption such as TLS protects a message only while it moves between mail servers. End-to-end encryption keeps the message encrypted in the inbox as well. PreVeil works inside Outlook, Gmail and Apple Mail, and other providers, payers and business associates read and reply for free from their browser, with replies encrypted end to end.

Is an encrypted email vendor still a business associate?

Yes. HHS guidance on cloud computing says a provider that stores electronic PHI is a business associate “even if it does not hold a decryption key and therefore cannot view the information.” The narrow conduit exception covers transmission-only services, not storage. A practice needs a BAA with its encrypted email vendor, and PreVeil signs one.

A BAA must set out permitted uses and disclosures, require the vendor to comply with the Security Rule for electronic PHI, require reporting of breaches of unsecured PHI, and flow the same terms down to subcontractors (164.504(e)(2) and 164.314(a)(2)(i)). A vendor that cannot read PHI has less PHI it can expose, but the practice still owns its own vendor oversight under 164.308(b).

How does this apply to behavioral health and substance use treatment programs?

Substance use disorder treatment records covered by 42 CFR Part 2 now follow the HIPAA breach notification rules. Section 2.16(b) applies them to Part 2 programs “with respect to breaches of unsecured records,” so the encryption safe harbor carries over. Like HIPAA, Part 2 itself does not require encryption; it requires formal security policies and procedures.

Section 2.16(a) requires a Part 2 program to have “formal policies and procedures to reasonably protect against unauthorized uses and disclosures of patient identifying information.” The companion post on 42 CFR Part 2 and HIPAA covers the disclosure notice, consent and redisclosure rules for records sent by email.

Is HHS changing the encryption rules?

HHS has proposed to, but the change is a proposal only. HHS’s notice of proposed rulemaking published January 6, 2025 (90 FR 898) would make encryption of electronic PHI at rest and in transit required, with limited exceptions. It is not a final rule, and the current HIPAA Security Rule, which treats encryption as addressable, applies today.

Frequently asked questions

Is encryption required under HIPAA?

Encryption is addressable, not required. Sections 164.312(a)(2)(iv) and 164.312(e)(2)(ii) are both labeled addressable. A practice must assess encryption and either implement it or document why it is not reasonable and appropriate and adopt an equivalent alternative (164.306(d)(3)).

What counts as unsecured PHI?

Under 45 CFR 164.402, unsecured PHI is PHI not rendered unusable, unreadable or indecipherable to unauthorized persons through a technology or method named in HHS guidance. HHS names encryption, consistent with NIST standards, and destruction of the media.

Does a practice have to report a lost laptop or compromised mailbox if the PHI was encrypted?

If the PHI was encrypted consistent with HHS guidance and the decryption keys were kept separate from the data, it is not unsecured PHI, and HHS says entities that secure information this way are relieved from providing breach notifications.

Are audit logs required under HIPAA?

Yes. Audit controls under 164.312(b) are a required standard. Information system activity review under 164.308(a)(1)(ii)(D) is a required implementation specification that calls for regular review of records such as audit logs and access reports.

Does PreVeil sign a BAA?

Yes. PreVeil signs a business associate agreement with healthcare practices. HHS treats a cloud provider that stores electronic PHI as a business associate even when it cannot view the data.

Can PreVeil read a practice’s email or files?

No. PreVeil cannot access or decrypt message contents, attachments or files, because the encryption keys stay on users’ devices.

Sources

How can a practice see how PreVeil maps to the HIPAA Security Rule?

A demo with PreVeil covers how it fits the practice’s email and file sharing.