Requirements
What the regulation expects

Customer-controlled keys under HIPAA
Technical safeguards should show who can reach ePHI; keys you govern make that auditable.
Access control and workforce clearance
Keys should align with role-based access: only approved systems and operators can trigger decrypt operations, with traceability.
Integrity and non-repudiation of protections
You must guard against improper alteration or destruction. Cryptographic integrity plus controlled keys supports defensible controls for systems-of-record.
Vendor and BAA boundaries
A BAA does not remove the need for strong technical separation. External keys limit vendor access even when they operate the application stack.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Standardise how EHR-adjacent apps, data lakes and integration layers consume keys under your security programme.
Learn moreAWS XKS for health workloads on AWS
Bind storage encryption to keys outside AWS’s default custody model.
Learn moreMicrosoft 365 Customer Key & DKE
Keep Microsoft from being the sole administrator of keys that protect regulated content.
Learn moreTokenisation for identifiers
Replace direct identifiers with tokens under your key control.
Learn moreKey themes
Where independent key control fits
DuoKey provides the technical key separation that auditors look for when assessing ePHI safeguards, ensuring that encryption is not just enabled but controlled by the covered entity or its designated business associate.
§164.312(a)(2)(iv), encryption and decryption
Implement mechanisms consistent with your risk analysis; external key management documents who can decrypt and how.
§164.312(b), audit controls
Integrate KMS and HSM audit streams with your SIEM for ePHI access paths that involve cryptography.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
