May 18, 2011 – The omnibus federal final rule that will cover changes to the HIPAA privacy, security, breach notification and enforcement rules will not include a mandate for encryption of protected health information, confirms Susan McAndrew, deputy director for health information privacy in the Department of Health and Human Services' Office for Civil Rights.

Asked in an email interview with Health Data Management if some type of encryption mandate would be in the final rule, McAndrew noted that none of the earlier proposals called for a regulatory change to the existing security rule on encryption. Consequently, additional rulemaking would be necessary to mandate encryption, and such a mandate won't be in the omnibus final rule. "If the requirement for encryption changes from an addressable implementation specification to a required implementation specification under the security rule, then normal notice and comment rulemaking processes would need to follow," she said.

Register or login for access to this item and much more

All Information Management content is archived after seven days.

Community members receive:
  • All recent and archived articles
  • Conference offers and updates
  • A full menu of enewsletter options
  • Web seminars, white papers, ebooks

Don't have an account? Register for Free Unlimited Access