Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.19

Data Encryption

activein force · 2026-08-25 – presentas-observed

(Rev. 15)

The MAC ARS includes several controls that require data encryption; however, the language

included in some of the controls appears to conflict with language in other controls. To consistently

address all of the data encryption controls included in the MAC ARS, for data that is not already

encrypted at rest or in transit, a risk assessment shall be completed to determine if the CIA of the

data can be maintained with or without encryption. All workstations and portable media containing

PII or PHI should already be encrypted. For other hardware and software maintained within the

documented and approved system security boundary, where the risk assessment determines that

CIA is at risk, FIPS 140-2 compliant encryption shall be implemented for data in transit and/or data

at rest. If the risk assessment determines that adequate controls are in place to protect the CIA of

the data while it is within the documented and approved system security boundary, then the data

can be transmitted and stored in the clear. Also, when encrypting data, the method of encryption

can be determined to be hardware or software as appropriate.

History

(Rev. 15)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
7fc8b6ed6f552435c055458f6719ae2719f87bf5b0d5b002aa2ad152e8b0ebfd
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.