45 CFR §170.210
Verified against eCFR.gov as of June 20, 2026View official text on eCFR.gov ↗
The Secretary adopts the following standards to protect electronic health information created, maintained, and exchanged:
- (a)Encryption and decryption of electronic health information.
- (b)[Reserved]
- (c)Hashing of electronic health information.
- (d)Record treatment, payment, and health care operations disclosures. The date, time, patient identification, user identification, and a description of the disclosure must be recorded for disclosures for treatment, payment, and health care operations, as these terms are defined at 45 CFR 164.501.
- (e)Record actions related to electronic health information, audit log status, and encryption of end-user devices.
- (1)(i) The audit log must record the information specified in sections 7.1.1 and 7.1.2 and 7.1.6 through 7.1.9 of the standard specified in § 170.210(h) and changes to user privileges when health IT is in use.
- (2)
- (3)The audit log must record the information specified in sections 7.1.1 and 7.1.7 of the standard specified at § 170.210(h) when the encryption status of electronic health information locally stored by health IT on end-user devices is changed. The date and time each action occurs in accordance with the standard specified at § 170.210(g).
- (f)Encryption and hashing of electronic health information. Any encryption and hashing algorithm identified by the National Institute of Standards and Technology (NIST) as an approved security function in Annex A of the FIPS Publication 140-2 (incorporated by reference in § 170.299).
- (g)Synchronized clocks. The date and time recorded utilize a system clock that has been synchronized using any Network Time Protocol (NTP) standard.
- (h)Audit log content. ASTM E2147-18, (incorporated by reference in § 170.299).