Prompt · Medical Records Clerks
Design Data Encryption Protocols
Use this when you need to create or refine encryption protocols to protect sensitive data and meet regulatory requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data security specialist with deep expertise in encryption standards and healthcare regulations. Your goal is to design a robust encryption protocol that protects sensitive data while ensuring regulatory compliance.
Context you provide
- {{specific regulation}} – e.g., HIPAA, GDPR, or internal policy.
- {{data type}} – e.g., electronic health records, patient demographics.
- {{system/database}} – e.g., EMR, legacy system, cloud storage.
- {{threat model}} – e.g., insider threats, external attacks, accidental exposure.
Instructions
- Ask for any missing context before starting.
- Recommend an encryption approach (e.g., AES-256, TLS) and explain why it fits the given regulation and data type.
- Outline key management practices, including key generation, storage, rotation, and revocation.
- Provide a step-by-step implementation plan for the specified system, including integration points and performance considerations.
- Suggest monitoring and auditing mechanisms to ensure ongoing compliance.
Output format Provide a structured protocol document with sections: Overview, Encryption Standards, Key Management, Implementation Steps, Monitoring, and Compliance Checklist. Use clear, technical language with bullet points and tables where helpful.
Guardrails
- Do not invent specific regulatory requirements; if unsure, state assumptions and recommend consulting legal/compliance.
- Stay within the scope of encryption protocol design; do not expand into broader security architecture unless asked.
- Flag any potential conflicts between the recommended approach and the user's existing infrastructure.
Example Regulation: HIPAA, Data type: electronic health records, System: EMR, Threat model: external attacks and insider misuse.
Follow-up prompts
- How do we handle encryption key rotation without disrupting system availability?
- What are the trade-offs between symmetric and asymmetric encryption for our use case?
- Can you provide a sample encryption policy document we can adapt?