A healthcare organization stores patient records in Azure SQL Database. To comply with HIPAA, they need to encrypt sensitive columns like Social Security Numbers (SSNs) at rest and ensure that only authorized users can decrypt them. Which feature should they implement?
Always Encrypted encrypts individual columns such as SSNs at rest and keeps the keys outside the database engine, so only clients holding the column master key can decrypt them. This satisfies HIPAA's requirement that only authorised users access sensitive data.
Why this answer
Always Encrypted (A) is correct because it encrypts sensitive columns such as SSNs at rest and keeps the encryption keys outside the database, so only clients with access to the column master key can decrypt the data. This satisfies HIPAA's requirement for column-level protection and strict control over who can decrypt values. TDE (B) encrypts the entire database at rest but does not provide column-level encryption or restrict decryption to specific authorized users.
Dynamic Data Masking (C) only obfuscates data in query results and does not encrypt stored values, and Row-Level Security (D) filters rows by user context rather than encrypting columns.