Encryption becomes mandatory: AES‑256 encryption will be required for all ePHI at rest, with TLS 1.3 or higher for data in transit, removing previous flexibility. Beyond technical controls: ...
The 2026 HIPAA Security Rule updates will make encryption of all electronic protected health information (ePHI) at rest and in transit mandatory, ending the long-standing 'addressable' flexibility.
Pervasive encryption that protects data not just in transit and at rest but in use — thus freeing companies of the fear of data breaches — has long been a dream of business executives, IT teams, and ...