Is Bitlocker HIPAA compliant?

Bitlocker has stated that it enables HIPAA compliance for data at rest. Full compliance requires integrating with a cloud service (such as Azure).

Bitlocker enables HIPAA compliance for data at rest by using the XTS-AES algorithm for data encryption on Windows systems, offering customers both AES 128-bit and 256-bit key lengths. The highest level of protection is available when this encryption is paired with a Trusted Platform Module (TPM) version 1.2 or later.

Since Bitlocker integrates with the Microsoft Windows operating system, covered entities should use additional security precautions if cloud storage is involved. Another benefit of using Bitlocker for HIPAA compliance is the data protection feature that addresses data theft risks, including exposure from computers that are stolen, lost, or inappropriately decommissioned.

Compliance depends on several criteria, such as integrating Azure cloud service and having volume licensing.

Product description

Bitlocker offers full encryption for devices running on Microsoft Windows. Integrating Bitlocker Drive Encryption with the operating system provides security features that reduce the risk of data loss.

This web page was updated on September 28, 2022.


Readers should perform their own research before making the final decision. The information on the Jotform HIPAA Compliance Checker does not constitute official healthcare or legal advice. Jotform is not liable for any damage or liabilities arising out of or connected in any manner with this platform.

If you see any incorrect, incomplete or inaccurate information, please request correction by filling the form below.

Request Correction

Get professional solutions with Jotform Enterprise

Discover how Jotform Enterprise can benefit your organization. Automate, collaborate, and scale with ease.