Skip to main content
Security Safeguards

Key Management

Also known as: Cryptographic key management

The secure generation, storage, rotation, and retirement of encryption keys.

Key Management is the set of practices for securely generating, distributing, storing, rotating, and retiring the cryptographic keys used to protect data.

Strong encryption is only as good as its key management: keys must be kept separate from the data they protect, access to them tightly controlled, and rotation and revocation handled cleanly. Poor key handling is a common way otherwise-encrypted ePHI becomes exposed. A worked example with AWS KMS is in Amazon RDS HIPAA compliant. In Drupal, the Key and Encrypt modules keep these keys out of the database, as our Drupal HIPAA compliant guide explains.

Share this definition with your team

View link to copy manually

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.