Skip to main content
Security Safeguards

Key Management

The secure generation, storage, rotation, and retirement of encryption keys.

Key Management is the set of practices for securely generating, distributing, storing, rotating, and retiring the cryptographic keys used to protect data.

Strong encryption is only as good as its key management: keys must be kept separate from the data they protect, access to them tightly controlled, and rotation and revocation handled cleanly. Poor key handling is a common way otherwise-encrypted ePHI becomes exposed. A worked example with AWS KMS is in Amazon RDS HIPAA compliant.

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.

Email me occasional updates about HIPAA hosting and compliance. No more than a few times a month, and you can unsubscribe at any time.