Skip to main content
Security Safeguards

Secrets Management

Also known as: Secret management, Application secrets management

Secrets management is how teams store, guard, rotate, and revoke the passwords, API tokens, and keys that let apps reach other systems.

Secrets management is how a team protects the private values that let an app use another system. These values are called secrets. A database password, an API token, an SSH key, or a signing key can each be a secret. Anyone who gets one may gain the access it grants.

Why secrets management matters for healthcare apps

A patient portal needs a private login for its database. If that login leaks through source code or a debug log, someone else may be able to use it to reach patient records.

A secrets manager, often called a vault, gives the team a controlled place to keep that login. The app fetches the value when it needs it. Staff can limit who may read it, and rotate it when needed. Keeping the login in a vault does not encrypt the patient records. Those records still need their own safeguards.

What good secret handling looks like

  • Keep secrets out of code. Never commit real passwords or tokens to a code repository. Yii's guide says never to store its cookie validation key in version control, as our Yii HIPAA compliant guide notes.
  • Be careful with environment variables. OWASP advises against them for secrets when other options exist. Other processes can often read them, and they can land in logs or dumps. Our Docker HIPAA compliant guide shows how Compose secrets mount each value as a file instead.
  • Limit access. Give each app only the secrets it needs. This follows least privilege. A staff member who can edit the site does not always need its database password.
  • Plan for change. Know which apps use each secret. Rotate it on a schedule, and revoke it if it leaks or is no longer needed. Use short-lived credentials where the service supports them.
  • Track use safely. Record who or what read a secret, and when, as part of your audit logging. Keep the secret value itself out of every log.

How it differs from key management

Key management covers the keys used in cryptography, from creation to retirement. Secrets management also covers passwords and tokens that let apps sign in to other systems. The two overlap, since an encryption key is a secret too. But a database password and a key that encrypts records serve different roles.

How secrets management connects to HIPAA

The HIPAA Security Rule never uses the phrase "secrets management." Several of its safeguards still apply to how apps handle secrets.

  • 45 CFR § 164.312(a)(1). The access control standard is required. Systems holding electronic protected health information (ePHI) must allow access only to people or software programs granted access rights. A leaked app password breaks that limit.
  • 45 CFR § 164.312(a)(2)(iv). Encryption and decryption is addressable. If you encrypt ePHI, the key that unlocks it needs the same care as any secret.
  • 45 CFR § 164.308(a)(5)(ii)(D). Password management is addressable too. It calls for procedures for creating, changing, and safeguarding passwords. It sits under the security awareness and training standard, but the same habits suit app credentials.

Addressable does not mean optional. Under 45 CFR § 164.306(d)(3), you adopt the specification when reasonable and appropriate, or document why not and use an equivalent measure if reasonable.

Examples in common app stacks

Our Symfony guide explains why Symfony's secrets vault is not data encryption. Our Lambda guide covers where database logins belong. AWS recommends Secrets Manager over environment variables for database credentials, API keys, and authorization tokens.

If you set no encryption key in self-hosted n8n, it generates one on first launch and keeps it in its own data folder. A backup of that folder can then hold the key next to the credentials it protects. Our n8n HIPAA compliant guide recommends loading that key from a secrets manager instead.

Sources: OWASP Secrets Management Cheat Sheet, AWS Lambda environment variables, Docker Compose secrets, Yii sessions and cookies guide, n8n deployment variables, and 45 CFR § 164.312, § 164.308, and § 164.306 at law.cornell.edu.

Share this definition with your team

View link to copy manually

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.