NIST SP 800-111
NIST SP 800-111 is a guidance document published by the U.S. National Institute of Standards and Technology in 2007 that explains how to use encryption to protect data stored on end user devices such as laptops, desktops, smartphones, and USB drives. It helps organizations understand the basics of storage encryption and how to apply it to secure information on these devices. It is a technical guide rather than a legal requirement, and it is not part of the HIPAA regulations themselves.
NIST SP 800-111, authored by K. Scarfone and published by NIST in 2007, is a Special Publication in the NIST 800 series that provides guidance on storage encryption technologies for end user devices, including full disk encryption, volume and virtual disk encryption, and file/folder encryption. Its scope is focused on end user devices such as laptops, desktops, smartphones, and removable media (e.g., USB drives) rather than server-side or cloud storage architectures. In a HIPAA context, this publication may be referenced as a technical resource supporting encryption of ePHI at rest under the Security Rule's technical safeguards; however, encryption is an addressable implementation specification under the Security Rule (addressable does not mean optional), and SP 800-111 is guidance, not a regulatory mandate. Adopting SP 800-111 does not by itself establish HIPAA compliance, and readers should verify current NIST guidance, applicable HHS OCR expectations, and any additional requirements imposed by state law or the HITECH Act. Note that as of the cited 2007 publication, its guidance is oriented to end user devices and does not address cloud storage.
Why it matters
For organizations handling electronic protected health information (ePHI), lost and stolen end user devices such as laptops, smartphones, and USB drives represent a persistent risk. NIST SP 800-111 matters because it provides practical guidance on the storage encryption technologies that can protect data at rest on exactly these kinds of devices. When ePHI is properly encrypted on a device that is later lost or stolen, the exposure of that information is generally mitigated, which is a significant consideration under the HIPAA Security Rule and the Breach Notification Rule.
In a HIPAA context, encryption of ePHI at rest is an addressable implementation specification under the Security Rule's technical safeguards. Addressable does not mean optional; it means a covered entity or business associate must implement the specification if reasonable and appropriate, or document why not and adopt an equivalent alternative where appropriate. SP 800-111 can serve as a technical reference to help organizations understand and evaluate storage encryption options as part of that analysis. It is important to stress, however, that SP 800-111 is guidance published by NIST, not a regulatory mandate, and following it does not by itself establish HIPAA compliance.
Organizations should also be aware of the document's limits. As a publication oriented to 2007-era end user devices, its guidance addresses laptops, desktops, smartphones, and removable media rather than server-side or cloud storage architectures. Readers should verify current NIST guidance and applicable HHS OCR expectations, and should account for any additional requirements imposed by state law or the HITECH Act.
Who it's relevant to
Inside SP 800-111
Common questions
Answers to the questions practitioners most commonly ask about SP 800-111.