Security Rule snapshot

HHS identifies access control, audit controls, integrity, person/entity authentication and transmission security among the technical safeguard areas regulated entities must address for ePHI.

Regulatory status — August 2026

HHS states that the HIPAA Security Rule currently in effect remains the operative rule. OCR’s proposed cybersecurity modifications—including more prescriptive requirements discussed in the 2025 NPRM—are still proposed, not final. This guide separates current requirements from proposed changes.

HHS: current Security Rule summary ↗ · HHS: proposed-rule fact sheet ↗

Security controls to evaluate

Access control

Limit ePHI access to authorized people and systems. Define unique identities and the least access necessary for the workflow.

Authentication

Verify that the person seeking access is who they claim to be. Consider phishing resistance, device trust and recovery paths.

Integrity

Protect ePHI from improper alteration or destruction and make sure the workflow can detect or prevent inappropriate changes.

Transmission security

Guard against unauthorized access while ePHI travels over electronic networks. End-to-end encryption can strengthen this layer when implemented correctly.

Auditability

Determine what activity your organization must record and examine. A privacy-minimizing product may intentionally collect less metadata, which can affect audit requirements.

Endpoints & people

A decrypted message on a compromised laptop, unmanaged download folder, screenshot, or forwarded file can bypass strong transport encryption.

How AliasCloak approaches privacy

AliasCloak is designed around local private keys and browser-side end-to-end encryption for mailbox messages, chat and files. Its current production design also includes TOTP protection for new sessions, encrypted backups, per-mailbox controls, blocking/muting, and limited server retention behavior.

  • Private keys are intended to remain client-side.
  • Message/file content is encrypted for recipient keys rather than relying only on server-side TLS.
  • Encrypted files can be transferred up to 4 GB.
  • New/untrusted sessions can require TOTP when a mailbox has 2FA enabled.
  • Backups can be passphrase-encrypted locally before export.
  • Retention is deliberately limited, but deployed settings and records obligations still need review.

What end-to-end encryption does not solve

  • Malware, malicious browser extensions, screen capture or a compromised device.
  • Sending to the wrong alias/public key.
  • Workforce policy, training, sanctions or authorization decisions.
  • Required Business Associate Agreements.
  • Record retention, legal holds, patient-access duties or EHR integration.
  • Incident response and organization-wide risk management.

Murmivo voice security

Murmivo says its browser-based audio rooms use application-layer end-to-end encryption for voice and ephemeral side chat, and that it does not store call audio or room chat history. Its current landing page also says unsupported browsers are blocked instead of silently downgrading to an unencrypted room. Those are useful privacy properties, but they do not replace the same HIPAA workflow and BAA analysis described above.

Primary source