{"id":12180,"date":"2020-03-19T12:26:24","date_gmt":"2020-03-19T16:26:24","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=12180"},"modified":"2020-12-15T09:44:16","modified_gmt":"2020-12-15T14:44:16","slug":"understanding-data-encryption-requirements-for-gdpr-ccpa-lgpd-hipaa","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/understanding-data-encryption-requirements-for-gdpr-ccpa-lgpd-hipaa\/","title":{"rendered":"Understanding Data Encryption Requirements for GDPR, CCPA, LGPD &#038; HIPAA"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong><em>Take a proactive approach towards your organization\u2019s security and compliance by gaining a greater understanding of current industry regulations for the GDPR, CCPA, LGPD, and HIPAA regarding encryption<\/em><\/strong><br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this age, organizations are dealing with an extraordinary volume of data \u2014 everything from personally identifiable information (PII) and protected health information (PHI) to financial records and other sensitive information. According to <a href=\"https:\/\/www.seagate.com\/files\/www-content\/our-story\/trends\/files\/idc-seagate-dataage-whitepaper.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">research<\/a> from Seagate and the International Data Corporation (IDC), the global datasphere is forecast to reach 175 zettabytes by 2025. To put it into perspective, researchers at IBM&#8217;s Almaden, California research lab are building the world&#8217;s largest data array, which can hold only 0.00012 zettabytes of data. If you tried to store 175 zettabytes on your home computer, you\u2019d need at least 175 billion PCs to store all the data!<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although data is seen as an asset for organizations, this amount of data can be seen as a risk as it gives hackers and risks of data sprawl a larger area to work with. In order to avoid these risks, organizations are required to encrypt their data as per global privacy regulations, and rightfully so. These encryption regulations and laws can help organizations mitigate risks and stop data sprawl and cyberattacks before they occur.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what exactly are the standards and requirements in terms of GDPR encryption, HIPAA encryption, CCPA encryption, and LGPD, or what\u2019s known as the Brazilian general data protection law?&nbsp;<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is Data Encryption?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the simplest form, data encryption can be defined as translating data in a different form that can not be deciphered (<a href=\"https:\/\/www.computerhope.com\/jargon\/d\/decrypti.htm\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">decrypted<\/a>) without the help of a special key. Encrypted data is known as ciphertext, whereas unencrypted data can be defined as plaintext. Encryption is one of the most common and effective processes organizations can incorporate to increase data security and facilitate secure communications.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The primary purpose of data encryption is to protect an organization&#8217;s digital data confidentiality. Data, which is stored on servers and computer systems, is transmitted using the insecure internet or other potentially insecure computer networks. Storing unencrypted data can jeopardize the confidentiality of the data and make it prey to data sprawl and hacking.&nbsp;<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Modern encryption algorithms play a crucial role in the security of data and communication. These algorithms provide confidentiality and other key security advantages, including affirming file integrity, authentication, and non-repudiation:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>authentication<\/strong> assists in the verification of a message\u2019s origin,&nbsp;<\/li><li><strong>integrity<\/strong> offers proof that the contents of the message have not changed since it was sent, and&nbsp;<\/li><li><strong>non-repudiation<\/strong> ensures that a message sender cannot deny sending the message.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">So, what does all this have to do with privacy regulations and data encryption laws like the <a href=\"https:\/\/www.thesslstore.com\/blog\/ccpa-vs-gdpr-what-you-need-to-know-about-these-data-privacy-laws\/\">European Union\u2019s General Data Protection Act (GDPR), the California Consumer Privacy Act (CCPA)<\/a>, Brazil\u2019s LGPD, and the <a href=\"https:\/\/www.thesslstore.com\/blog\/hipaa-compliance-technical-safeguards\/\">Health Insurance Portability and Accountability Act<\/a>? Let\u2019s explore this a bit more in depth.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Do Data Privacy Laws Require Encryption?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Although all <a href=\"https:\/\/www.thesslstore.com\/blog\/10-data-privacy-and-encryption-laws-every-business-needs-to-know\/\">data privacy laws and regulations<\/a> may not explicitly ask organizations to implement encryption in their systems, it\u2019s highly recommended as it mitigates the risk associated with data breach. Data from <a href=\"https:\/\/www.ibm.com\/security\/data-breach\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">IBM Security\u2019s 2019 Cost of a Data Breach report<\/a> put the average cost of a data breach at $3.92 million. Not only this, but around 276 health data breaches were <a href=\"https:\/\/www.careersinfosecurity.com\/health-data-breaches-involving-unencrypted-devices-reported-a-12912\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">reported to regulators<\/a> last year \u2014 including hacking incidents and thefts of unencrypted devices \u2014 already have been added to the official federal tally, with business associates involved in six of the largest incidents.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If encrypted data is breached, organizations are less likely to face fines and penalties because the data itself is unintelligible ciphertext that can&#8217;t be read by any cybercriminals who get their hands on it.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">GDPR Encryption Requirements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR is one of the largest data privacy regulations in the world and aims to protect the privacy of people located in the EU. Although this may seem EU specific, it\u2019s not. Virtually the whole world interacts with the EU in one way or another, which means that businesses around the world need to comply with the GDPR as well.&nbsp;<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The General Data Protection Regulation recognizes the importance of encryption, which is why under <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679&amp;from=EN#d1e3383-1-1\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">article 32<\/a> \u201csecurity of processing,\u201d the GDPR states:<br><\/p>\n\n\n\n<blockquote class=\"wp-block-quote\"><p>Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor <strong>shall implement appropriate technical and organisational measures<\/strong> to ensure a level of security appropriate to the risk, including inter alia as appropriate:<\/p>\n\n\n\n<ol><li>the pseudonymisation and <strong>encryption of personal data<\/strong>;<\/li><li>the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;<\/li><li>the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;<\/li><li>a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.<strong>\u201d<\/strong><\/li><\/ol><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Reading this may make it seem that encryption is only but a suggestion under the GDPR, but&nbsp;<a href=\"https:\/\/www.privacy-regulation.eu\/en\/recital-83-GDPR.htm\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">recital 83<\/a> states:<br><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and <strong>implement measures to mitigate those risks, such as encryption<\/strong>. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.<strong>\u201d<\/strong><br><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR requires organizations to incorporate encryption in order to protect consumers\u2019 data and to mitigate the risks associated with data transfers (such as data sprawl or cyberattacks).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">CCPA Encryption Requirements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Under the <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=201720180SB1121\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">California Consumer Privacy Act<\/a>, there\u2019s no explicit mention of requiring encryption measures, although organizations are wise to do so. That\u2019s because even though there may not be an explicit requirement for data encryption, there are fines associated with data breaches involving \u201cnonencrypted or nonredacted personal information\u201d (up to $750 per consumer per incident or actual damages). These fines may be waived in cases where encryption is used since the breached data is encrypted and unintelligible without the decryption key.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the highest level of security, encryption should be used to protect data both while it\u2019s at rest and in transit, regardless of where it is shared. Organizations have a responsibility to their consumers and need to layer data-centric encryption into their data management solution to facilitate the secure transfer of data when fulfilling data subject requests (DSRs).&nbsp;<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Under the <a href=\"https:\/\/stanford.edu\/~jmayer\/law696\/week5\/California%20Data%20Safeguard%20Law.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">California Civil Code Section 1798.81.5<\/a>, an organization or business that meets specific requirements and processes a California residents&#8217; personal data is obligated to implement and maintain reasonable security procedures and practices appropriate to the nature of the information it processes. This is where \u201creasonable security\u201d considerations must be given.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">LGPD Encryption Requirements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">According to an article from the International Association of Privacy Professionals (IAPP), Brazil has drafted more than <a href=\"https:\/\/iapp.org\/news\/a\/the-new-brazilian-general-data-protection-law-a-detailed-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">40 legal norms<\/a> on a federal level that deal with data privacy. The only downside of these laws is that they are sectoral, meaning that they\u2019re related to specific industries and don\u2019t cover all aspects at an overall level. This is why the new data protection law of Brazil, known as the LGPD (which stands for Lei Geral de Prote\u00e7\u00e3o de Dados Pessoais), was drafted to provide a more comprehensive and overall regulatory framework.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"http:\/\/www.planalto.gov.br\/ccivil_03\/_ato2015-2018\/2018\/lei\/L13709.htm\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Lei Geral de Prote\u00e7\u00e3o de Dados Pessoais<\/a> is closely modelled after the GDPR and contains sixty-five articles. It was passed on Aug. 14, 2018 and sanctioned by President Jair Bolsonaro in July 2019. The enforcement date is set to be Aug. 15, 2020.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Just as with the GDPR and CCPA, the LGPD (Brazil&#8217;s General Data Protection Law \/ Lei Geral de Prote\u00e7\u00e3o de Dados Pessoais) does not explicitly require organizations to <a href=\"https:\/\/www.thesslstore.com\/blog\/deleting-data-for-gdpr-could-encryption-do-the-trick\/\">encrypt their data<\/a>, but still requires a reasonable amount of security when dealing with a consumer&#8217;s personal information. The easiest and most efficient way to facilitate this is through the use of encryption.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Under the LGPD, organizations must incorporate best practices in <a href=\"https:\/\/vpnpro.com\/web\/what-is-cyber-security\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"cybersecurity (opens in a new tab)\">cybersecurity<\/a> and data security for personal data. The LGPD notes that the law doesn\u2019t apply to any personal data that\u2019s encrypted or anonymized to a degree that makes it unintelligible and can\u2019t easily be returned to its original state by those who might breach the data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">HIPAA Encryption Requirements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.cdc.gov\/phlp\/publications\/topic\/hipaa.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Health Insurance Portability and Accountability Act<\/a> (HIPAA) requires medical providers, also known as covered entities, to implement data security in order to protect their patients&#8217; information from disclosure.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The HIPAA encryption requirements can seem confusing when it comes to understanding what\u2019s required (or not) in terms of security and data protection. The reason being that the <a href=\"https:\/\/www.thesslstore.com\/blog\/hipaa-compliance-technical-safeguards\/\">technical safeguards<\/a> relating to the encryption of protected health information are defined as \u201c<strong>addressable<\/strong>\u201d requirements. The HIPAA encryption requirements for transmission security state that covered entities should \u201c<strong>implement a mechanism to encrypt PHI whenever deemed appropriate.<\/strong>\u201d This instruction is considerably vague and open to interpretation \u2014 hence, the confusion.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In other words, HIPAA does require organizations, or covered entities, to have some degree of security for PHI. Organizations are obligated to encrypt their data unless they can justify why they can\u2019t implement encryption and can provide an equal alternative.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Fines Associated with Different Encryption Laws and Regulations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Under the CCPA, GDPR and LGPD, there are no specific fines that are associated with not implementing encryption. However, organizations may be able to avoid fines related to a data breach if proper encryption is implemented. For example, if an organization has proper encryption in place, in case of a data breach, they likely will not be penalized as the data breached is encrypted.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As for HIPAA, the law requires that organizations have proper encryption set in place for protected health information unless the organization can provide a solid reason as to why they can&#8217;t implement encryption and provide an equal alternative.&nbsp;<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even in a situation where an organization does claim to have a solid reason for not encrypting, they can still be fined heavily for not doing so. For example, The <a href=\"https:\/\/www.jems.com\/2019\/11\/06\/university-of-rochester-fined-3m-for-hipaa-violations\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">University of Rochester Medical Center (URMC) paid a $3 million penalty<\/a> for their failure to encrypt mobile devices in addition to other HIPAA violations.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Last year, <a href=\"https:\/\/edition.cnn.com\/2019\/07\/08\/tech\/british-airways-gdpr-fine\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">British Airways was fined \u00a3184 million<\/a> ($230 million) for violating the EU&#8217;s General Data Protection Regulation. Consumers&#8217; data was breached due to the organization\u2019s poor security posture at the time of the breach. <a href=\"https:\/\/edpb.europa.eu\/news\/national-news\/2019\/ico-statement-intention-fine-british-airways-ps18339m-under-gdpr-data-breach_en\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">ICO said<\/a> \u201cThe ICO&#8217;s investigation has found that a variety of information was compromised by poor security arrangements at the company, including log in, payment card, and travel booking details as well name and address information.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Data Encryption Best Practices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless of whether the GDPR, CCPA, &amp; HIPAA applies to your organization, or another regulation does (such as the <a href=\"https:\/\/www.thesslstore.com\/blog\/demystifying-pci-dss-compliance\/\">Payment Card Industry Data Security Standards<\/a>), encryption is an integral part of any organization\u2019s security. As such, it\u2019s important to keep in mind the best ways to implement data encryption to avoid any kind of mishap or loophole that can make your organization vulnerable to a data breach.&nbsp;<br><\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<p class=\"wp-block-paragraph\">Here are a few of the best practices that organizations can incorporate in order to have an efficient encryption system:&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Keep Your Encryption Key Secure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The first point may seem obvious, but it\u2019s critical. This is specifically mentioned because it\u2019s an easy mistake that could allow unauthorized parties to access your data. For example, if your encryption key is in a plaintext file on your PC, there\u2019s a strong chance that someone could find it and cause damage.&nbsp;<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A few solutions to tackle this could be to:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>separate the keys from the data,&nbsp;<\/li><li>limit access of users, and&nbsp;<\/li><li>rotate your keys on a schedule.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Encrypt All Sensitive Data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s paramount that all types of sensitive data is encrypted. As safe you may think your data is, you know that several companies have been breached because they left important data unencrypted and someone gained access to it. By <a href=\"https:\/\/www.thesslstore.com\/new-to-ssl\/encryption.aspx\">encrypting your data<\/a>, you make it much harder for someone who is able to breach your systems with malicious intentions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Assess Data Encryption Performance&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Effective data encryption entails not just making your data unreadable to unauthorized parties, but doing so in a way that uses resources efficiently. If it is taking too long or consuming too much CPU time and memory to encrypt your data, consider switching to a different algorithm or experimenting with settings in your data encryption tools.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Protect Data in Transit and at Rest<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Encryption plays a crucial role in data protection and is used to secure data both in transit (while it\u2019s being transmitted) and at rest (stored for later use). Enterprises often choose to encrypt sensitive data prior to moving and\/or use encrypted connections (HTTPS, SSL, TLS, FTPS, etc.) to protect the contents of data in transit. To protect data at rest, enterprises can simply encrypt sensitive files prior to storing them and\/or choose to encrypt the storage drive itself. To protect data in transit, they can install <a href=\"https:\/\/www.thesslstore.com\/products\/ssl.aspx\">SSL\/TLS certificates<\/a> on their servers.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Encrypt Data in Your Databases&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">While other security tools protect a system from intrusion or attack, encryption of your database is a main form of defense that deals with security of the data. This means that even in the event of a system breach, compromised data is still only readable to users with the encryption key.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Implement S\/MIME to Secure Email Communications<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.thesslstore.com\/blog\/what-you-need-to-know-about-s-mime\/\">secure\/multipurpose internet mail extension (S\/MIME)<\/a> allows organizations to send end-to-end encrypted emails and fill any holes for data sprawl. A lot of sensitive data is communicated via email, and this is the best way to ensure these emails are secure.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Key Takeaway<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Data encryption is an important part of any organization\u2019s data security and facilitates secure communication. Some privacy regulations such as the GDPR, CCPA and LGPD mandate encryption, while some may not explicitly specify the use of encryption, but it\u2019s still recommended. Privacy regulations frequently penalize organizations in cases of data breaches, but these penalties can be avoided in cases where the data is encrypted, as the person that breached the data can\u2019t decipher it without the decryption key.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With zettabytes of data being created annually, organizations need to incorporate the best practices for data encryption in order to avoid any sort of data sprawl or breach. This can be achieved by securing your encryption key, encrypting all sensitive data, and assessing data encryption performance.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this era of data privacy, encryption is no longer an option and companies would do well with encrypting all their sensitive data.<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Take a proactive approach towards your organization\u2019s security and compliance by gaining a greater understanding of current industry regulations for the GDPR, CCPA, LGPD, and HIPAA regarding encryption In this&#8230;<\/p>\n","protected":false},"author":29,"featured_media":13641,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[12046,5742,6237,11309,12047],"class_list":["post-12180","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-ccpa","tag-gdpr","tag-hipaa","tag-laws","tag-lgpd","post-with-tags"],"views":24987,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/03\/gdpr-data-privacy-laws-scaled.jpeg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12180","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=12180"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12180\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/13641"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=12180"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=12180"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=12180"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}