---
title: Staying Compliant by Protecting Patient Data
description: Staying Compliant by Protecting Patient Data
---

[Skip to the main content.](https://ontimetech.valeonetworks.com/blog/staying-compliant-by-protecting-patient-data#main-content)

[![OTT powerd by VN big](https://ontimetech.valeonetworks.com/hs-fs/hubfs/OTT%20powerd%20by%20VN%20big.png?width=500&height=175&name=OTT%20powerd%20by%20VN%20big.png "OTT powerd by VN big")](https://ontimetech.valeonetworks.com)

[![OTT powerd by VN big](https://ontimetech.valeonetworks.com/hs-fs/hubfs/OTT%20powerd%20by%20VN%20big.png?width=500&height=175&name=OTT%20powerd%20by%20VN%20big.png "OTT powerd by VN big")](https://ontimetech.valeonetworks.com)

- [Services](https://ontimetech.valeonetworks.com/our-services/) 
    - [Managed It Services](https://ontimetech.valeonetworks.com/our-services/managed-it/)
    - [Cybersecurity](https://ontimetech.valeonetworks.com/our-services/cybersecurity/)
    - [Cloud Solutions](https://ontimetech.valeonetworks.com/our-services/cloud-solutions/)
    - [Compliance](https://ontimetech.valeonetworks.com/our-services/compliance/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources](https://ontimetech.valeonetworks.com/resources/) 
    - [Blog](https://ontimetech.valeonetworks.com/blog)
- [About](https://ontimetech.valeonetworks.com/about/) 
    - [Client Testimonials](https://ontimetech.valeonetworks.com/testimonials/)

[415-294-5250](tel:4152945250) [Client Portal](https://portal.Valeonetworks.com)

Toggle Menu

Toggle Menu

[415-294-5250](tel:4152945250) [Client Portal](https://portal.Valeonetworks.com)

- [Services *Toggle Menu*](https://ontimetech.valeonetworks.com/our-services/) 
    - [Managed It Services](https://ontimetech.valeonetworks.com/our-services/managed-it/)
    - [Cybersecurity](https://ontimetech.valeonetworks.com/our-services/cybersecurity/)
    - [Cloud Solutions](https://ontimetech.valeonetworks.com/our-services/cloud-solutions/)
    - [Compliance](https://ontimetech.valeonetworks.com/our-services/compliance/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources *Toggle Menu*](https://ontimetech.valeonetworks.com/resources/) 
    - [Blog](https://ontimetech.valeonetworks.com/blog)
- [About *Toggle Menu*](https://ontimetech.valeonetworks.com/about/) 
    - [Client Testimonials](https://ontimetech.valeonetworks.com/testimonials/)

- Example Link
- Example Link
- Example Link

[*Facebook*](https://ontimetech.valeonetworks.com/blog/staying-compliant-by-protecting-patient-data#0) [*Instagram*](https://ontimetech.valeonetworks.com/blog/staying-compliant-by-protecting-patient-data#0) [*LinkedIn*](https://ontimetech.valeonetworks.com/blog/staying-compliant-by-protecting-patient-data#0) [*Twitter*](https://ontimetech.valeonetworks.com/blog/staying-compliant-by-protecting-patient-data#0) [*Youtube*](https://ontimetech.valeonetworks.com/blog/staying-compliant-by-protecting-patient-data#0) [*Medium*](https://ontimetech.valeonetworks.com/blog/staying-compliant-by-protecting-patient-data#0)

 3 min read

# Staying Compliant by Protecting Patient Data

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) :  May 16, 2017, 11:00:17 AM

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services)

## Is data encryption required under HIPAA privacy regulations?

**HIPAA and Email Encryption**

HIPAA may be one of the most complex healthcare laws in the last decade. The law is supposed to regulate privacy rules and communication of patient information. But the legislation is still widely misinterpreted by healthcare providers.

The confusion made headlines last year after the terrible Orlando nightclub shooting that left 49 dead and 53 injured. The Orlando Mayor said HIPAA should be waived so hospital officials could share information with families. According to *[Becker’s Health IT & CIO Review](http://www.beckershospitalreview.com/healthcare-information-technology/hipaa-waived-after-orlando-shooting-did-it-have-to-be.html),* at least one hospital CEO stated their facility refused to release information to families during the crisis.

But HIPAA does allow the release of patient information in the event of emergencies. So, the families and loved ones of these injured patients in Orlando should not have had the added stress of fighting to discover their status after the tragedy occurred.

But what about more common, less crisis-oriented forms of communication that healthcare providers might use, such as email? Does HIPAA regulate the security of email communication on the Internet? Staying true to the convoluted language in HIPAA, the answer is both yes – and no.

**HIPAA Background**

In 1996, the U.S. Health Insurance Portability Accountability Act was passed. The law was originally intended to protect the right to insurance if you had a pre-existing condition after you lost your job. Security amendments were added until the bill became a patchwork of confusing policies that healthcare providers and patients are still struggling to understand.

The benefit of HIPAA was that the law sought to establish consistency between the states related to patient privacy rules. HIPAA was passed during a time when healthcare providers were moving to electronic medical records (EMRs) with information transmitted via the cloud. It attempted to standardize how healthcare providers handled Protected Health Information (PHI) including technical, administrative, and physical rules in medical facilities.

Some of those rules affected the technology hospitals and healthcare providers use, including how they protect data from prying eyes when using the Internet.

**What is Encryption and Why Does it Matter?**

Encryption takes regular message text and encodes it through a computer algorithm. It is one of the best methods for ensuring only the person intended to receive the message will be able to read it.

Encryption works via keys that issue long random passwords. While the person at the other end of the message has the key to unlock the data, others do not. Most data that flows over the Internet, including chats, phone calls, and search engine activity are not encrypted.

*[ComputerWorld](http://www.computerworld.com/article/2484714/security0/encryption-still-best-way-to-protect-data----despite-nsa.html)* says that encryption remains the most secure way to transfer information across the public or private Internet. [TechRepublic](http://www.techrepublic.com/article/10-things-you-can-do-to-protect-your-data/) agrees with this finding, listing encryption in their top ten security measures all businesses and individuals should pursue to secure valuable personal information.

According to the *[HIPAA Journal](http://www.hipaajournal.com/lack-of-email-encryption-exposes-phi-of-644-raising-st-louis-participants-8727/)*, the rules for email encryption include:

The HIPAA Security Rule does not prohibit the sending of ePHI via email, although any data sent via an open network must be appropriately secured and controls implemented to prevent unauthorized access (See 45 CFR § 164.312(e)).

While the law doesn’t specifically specify encryption as the security required, it does state that the technology protocol used by the healthcare provider must protect the confidentiality of patient data. It also states, that if you don’t use encryption, you better find an alternative – and document your rationale for *not* using encryption protocols.

The [American Hospital Association](http://www.aha.org/content/00-10/cmssecurityFAQ81704.pdf) published a guide to HIPAA that addresses the encryption question. There are two primary considerations:

1. Because medical providers use email that travels across open Internet networks in different ways, there is no single standard for encrypting data. The law suggests mandating an encryption standard could have presented a real financial burden on smaller, independent medical practices.
2. However, the law indicates encryption must be implemented if the medical entity can provide it. If the provider decides encryption is not “reasonable and appropriate,” the reason why must be documented and a reasonable alternative for protecting patient data must be implemented.

**What Could Happen Without Email Encryption**

In March 2017, BJC HealthCare in St. Louis found out the hard way that email encryption is a vital security measure in healthcare. More than 600 patients in a local program sponsored by BJC had their contact information along with nursing notes and medication data exposed. That’s because BJC failed to follow their own internal security protocols that would have encrypted the data, keeping it safe from public eyes.

Verizon’s [2017 Data Breach Investigations Report](http://www.hipaajournal.com/healthcare-industry-insiders-pose-biggest-threat-8787/) showed that data breaches are increasing in healthcare, making up 15% of all security incidents in the U.S. Contact {company} at {email} or {phone} to find out how you can keep {city} patient data safe

- [Tweet](https://twitter.com/share)

#### ![BusinessOwnerGuidetoM&A-1](https://ontimetech.valeonetworks.com/hs-fs/hubfs/BusinessOwnerGuidetoM%26A-1.png?width=303&height=209&name=BusinessOwnerGuidetoM%26A-1.png)

#### Download our eBook*THE ULTIMATE ROADMAP TO CMMC COMPLIANCE* by filling out the form below!

[![New York-Presbyterian Hospital and Columbia University Medical Center: Is Your Technology HIPAA Compliant? If Not, HHS Wants You To Pay Up.](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/HIPAA-Audit.jpg)](https://ontimetech.valeonetworks.com/blog/new-york-presbyterian-hospital-and-columbia-university-medical-center-is-your-technology-hipaa-compliant-if-not-hhs-wants-you-to-pay-up)

#### [New York-Presbyterian Hospital and Columbia University Medical Center: Is Your Technology HIPAA Compliant? If Not, HHS Wants You To Pay Up.](https://ontimetech.valeonetworks.com/blog/new-york-presbyterian-hospital-and-columbia-university-medical-center-is-your-technology-hipaa-compliant-if-not-hhs-wants-you-to-pay-up)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) : May 19, 2014, 9:53:46 AM

The Department of Health and Human Services (HHS) has proven that they’re serious about HIPAA infractions. They recently imposed the largest monetary...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/new-york-presbyterian-hospital-and-columbia-university-medical-center-is-your-technology-hipaa-compliant-if-not-hhs-wants-you-to-pay-up)

[![Kansas Addiction Treatment Organization’s Email Hack Leads To Data Breach](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/GettyImages-906812954-1.jpg)](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach)

 1 min read

#### [Kansas Addiction Treatment Organization’s Email Hack Leads To Data Breach](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/lance-stone) : Feb 7, 2019, 10:59:00 AM

When people go to their doctors, they assume their information is protected. They freely and willingly provide personal information, like social...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach)

[![2018 Was a Record Year for HIPAA Penalties](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/GettyImages-1085283530.jpg)](https://ontimetech.valeonetworks.com/blog/2018-was-a-record-year-for-hipaa-penalties)

#### [2018 Was a Record Year for HIPAA Penalties](https://ontimetech.valeonetworks.com/blog/2018-was-a-record-year-for-hipaa-penalties)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/lance-stone) : Jan 28, 2019, 10:23:00 AM

2018 turned out to be a year of record fines for HIPAA violations. Over $25 million in fines, with the mean fine being just over $2.5 million. Could...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/2018-was-a-record-year-for-hipaa-penalties)

![OTT White logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/VN%20-%20Division%20Logos/OTT%20Logo/OTT%20White%20logo.png?width=524&height=140&name=OTT%20White%20logo.png)

 

##### About

About

On Time Tech is an IT Support and Computer Services company serving California. We provide services to the areas in and around We know businesses like yours need technology support in order to run highly-effective organizations. Leverage pro-growth technology services for your company now.

##### Explore On Time Time

Explore On Time Time

- [Our Services](https://ontimetech.valeonetworks.com/our-services/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources](https://ontimetech.valeonetworks.com/resources/)
- [About](https://ontimetech.valeonetworks.com/about/)
- [Contact](https://ontimetech.valeonetworks.com/contact/)

##### Contact

Contact

**San Francisco:**  
1717 Fifth Ave  
San Rafael, CA 94901

[415-294-5250](tel:4152945250)

Business Hours:   
M-F: 8AM-9PM

- [Privacy Policy](https://ontimetech.valeonetworks.com/privacy-policy/)

© 2026 On Time Tech

[*Facebook*](https://www.facebook.com/ontimetechsf/)[*Twitter*](https://twitter.com/on_time_tech?lang=en)[*LinkedIn*](https://www.linkedin.com/company/ontimetech/)[*YouTube*](https://www.youtube.com/channel/UCubqs9PU_WWF-RFhfK9xNpw)

[![Alura White logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/VN%20-%20Division%20Logos/Alura%20White%20logo.png?width=295&height=115&name=Alura%20White%20logo.png)](https://alura.valeonetworks.com/) [![Next.I.T._White-Logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Next.I.T._White-Logo.png?width=328&height=136&name=Next.I.T._White-Logo.png)](https://next-it.net/) [![White-OTT-Logo-1-768x253](https://ontimetech.valeonetworks.com/hs-fs/hubfs/White-OTT-Logo-1-768x253.png?width=313&height=103&name=White-OTT-Logo-1-768x253.png)](https://www.ontimetech.com/) [![Valeo-Logo-White (1)](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Valeo-Logo-White%20(1).png?width=288&height=123&name=Valeo-Logo-White%20(1).png)](https://valeonetworks.com/)

*Return to Top*

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Lance Stone",
    "url" : "https://ontimetech.valeonetworks.com/blog/author/ulisticadmin"
  },
  "dateModified" : "2024-01-10T16:25:27.522Z",
  "datePublished" : "2017-05-16T15:00:17.000Z",
  "headline" : "Staying Compliant by Protecting Patient Data",
  "mainEntityOfPage" : {
    "@id" : "https://ontimetech.valeonetworks.com/blog/staying-compliant-by-protecting-patient-data",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://ontimetech.valeonetworks.com/hubfs/OTT%20-%20Color%20Logo.png"
    },
    "name" : "Valeo Networks"
  }
}
```