US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.19
Data Encryption
(Rev. 15)
The MAC ARS includes several controls that require data encryption; however, the language
included in some of the controls appears to conflict with language in other controls. To consistently
address all of the data encryption controls included in the MAC ARS, for data that is not already
encrypted at rest or in transit, a risk assessment shall be completed to determine if the CIA of the
data can be maintained with or without encryption. All workstations and portable media containing
PII or PHI should already be encrypted. For other hardware and software maintained within the
documented and approved system security boundary, where the risk assessment determines that
CIA is at risk, FIPS 140-2 compliant encryption shall be implemented for data in transit and/or data
at rest. If the risk assessment determines that adequate controls are in place to protect the CIA of
the data while it is within the documented and approved system security boundary, then the data
can be transmitted and stored in the clear. Also, when encrypting data, the method of encryption
can be determined to be hardware or software as appropriate.
History
(Rev. 15)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
7fc8b6ed6f552435c055458f6719ae2719f87bf5b0d5b002aa2ad152e8b0ebfd
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.