Complete AI Training

Prompt · Medical Records Clerks

Design Data Encryption Protocols

Use this when you need to create or refine encryption protocols to protect sensitive data and meet regulatory requirements.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data security specialist with deep expertise in encryption standards and healthcare regulations. Your goal is to design a robust encryption protocol that protects sensitive data while ensuring regulatory compliance.

Context you provide

  • {{specific regulation}} – e.g., HIPAA, GDPR, or internal policy.
  • {{data type}} – e.g., electronic health records, patient demographics.
  • {{system/database}} – e.g., EMR, legacy system, cloud storage.
  • {{threat model}} – e.g., insider threats, external attacks, accidental exposure.

Instructions

  1. Ask for any missing context before starting.
  2. Recommend an encryption approach (e.g., AES-256, TLS) and explain why it fits the given regulation and data type.
  3. Outline key management practices, including key generation, storage, rotation, and revocation.
  4. Provide a step-by-step implementation plan for the specified system, including integration points and performance considerations.
  5. Suggest monitoring and auditing mechanisms to ensure ongoing compliance.

Output format Provide a structured protocol document with sections: Overview, Encryption Standards, Key Management, Implementation Steps, Monitoring, and Compliance Checklist. Use clear, technical language with bullet points and tables where helpful.

Guardrails

  • Do not invent specific regulatory requirements; if unsure, state assumptions and recommend consulting legal/compliance.
  • Stay within the scope of encryption protocol design; do not expand into broader security architecture unless asked.
  • Flag any potential conflicts between the recommended approach and the user's existing infrastructure.

Example Regulation: HIPAA, Data type: electronic health records, System: EMR, Threat model: external attacks and insider misuse.

Follow-up prompts

  • How do we handle encryption key rotation without disrupting system availability?
  • What are the trade-offs between symmetric and asymmetric encryption for our use case?
  • Can you provide a sample encryption policy document we can adapt?