
As healthcare organizations prepare for the proposed updates to the HIPAA Security Rule, one area receiving significant attention is encryption.
While the rule has not yet been finalized and may change before publication, the proposal makes the overall direction clear: encryption is expected to become a foundational safeguard for protecting electronic protected health information (ePHI), rather than an addressable implementation specification.
For many healthcare organizations, this is an opportunity to evaluate whether their current security practices align with where HIPAA expectations are heading.
Protecting ePHI at Rest and in Transit
If the proposed rule is finalized as written, organizations should expect encryption to be applied much more broadly to ePHI at rest, meaning data stored on devices or systems.
This includes:
- Laptops, desktops, tablets, and smartphones that store or access ePHI
- Servers and databases containing ePHI
- Backup media, including external hard drives and cloud backups
- Portable storage devices such as USB drives
The proposal also reinforces the importance of protecting ePHI while it is in transit, or moving between locations or systems.
Examples include:
- Encrypted email solutions
- Secure web connections
- Virtual Private Networks (VPNs) for remote access
- Encrypted communications between healthcare applications and cloud services
These safeguards help reduce the risk of unauthorized access while sensitive patient information is being stored, shared, or transmitted.
Start Preparing Now
Healthcare organizations do not need to wait for the final rule before evaluating their encryption posture.
A practical first step is creating or updating a technology asset inventory to identify every device, application, and system that creates, receives, maintains, or transmits ePHI. From there, organizations can confirm encryption is enabled where appropriate, document current encryption standards, and identify any legacy systems that may not support modern encryption practices.
Taking these steps now can help reduce future implementation costs while strengthening your organization’s overall cybersecurity posture.
HIPAA Secure Now Is Here to Help
Although the final rule may differ from the current proposal, the direction is becoming increasingly clear. Strong encryption is quickly becoming an expected safeguard for protecting patient data.
HIPAA Secure Now is here to help healthcare organizations understand what may be changing, evaluate their current security posture, and prepare before the compliance clock starts. If you have questions about encryption, asset inventories, or your organization’s HIPAA readiness, our compliance team is ready to help.

Leave a Reply