Encrypting Laptops, Drives and Email: A Plain-English Guide

Encryption turns readable information into scrambled data that can only be unscrambled with the right key. If an encrypted laptop is lost or stolen, the thief gets a locked box instead of resident records. That difference is big enough that HHS guidance treats properly encrypted PHI as "secured," which can mean a lost device does not trigger breach notification.

Encryption is one of the highest-value protections available, and the tools are often already built into the systems you use. Here is a plain-English guide.

Two Kinds of Encryption

Encryption at rest

Protects data stored on a device or server: laptop drives, phones, USB sticks, backup media and cloud storage.

Encryption in transit

Protects data moving between places: email, web connections, VPN tunnels, Wi-Fi and file transfers.

You need both. A locked laptop with an unprotected email is only half protected.

HIPAA and Encryption

The current Security Rule lists encryption as an "addressable" implementation specification, which means you must assess whether it is reasonable and appropriate, and either implement it or document an equivalent alternative. In practice, for portable devices, it would be hard to justify skipping it. The proposed update published in January 2025 would make encryption more clearly required, but it is a proposal and not final. Either way, encrypting is sound practice.

Where to Start

1. Laptops and desktops

Windows includes BitLocker on many business editions, and Macs include FileVault. Turn it on and store recovery keys securely, such as in your management system, not on a sticky note.

Confirm status with a report from your management tool instead of assuming.

Laptops used by physicians, administrators and traveling staff come first.

2. Phones and tablets

Modern iPhones and Android devices encrypt storage when a passcode is set. Require a passcode and enable remote wipe.

Use mobile device management to enforce settings on devices that access email or resident information.

3. USB drives and removable media

Best option: prohibit USB storage of PHI and provide secure alternatives.

If you must allow it, use encrypted drives and track them.

4. Servers and backups

Encrypt backup data both on the media and in cloud storage.

Ask cloud vendors how they encrypt data and who holds the keys.

Protect backup encryption keys, because losing them can make backups unreadable.

5. Email

Standard email can cross multiple servers in readable form unless protected. Many providers use encrypted connections between servers when available, but that is not guaranteed.

Use a secure email encryption feature for messages containing PHI sent outside the organization, ideally triggered automatically by keywords or a subject-line tag.

Better still, use a secure portal or messaging system for sensitive exchanges.

6. Websites, portals and remote access

Make sure all sites collecting information use HTTPS.

Use VPN or secure gateways with current encryption standards.

7. Wi-Fi

Use WPA2 or WPA3 for staff networks and avoid open networks for anything involving PHI.

Common Mistakes

Encrypting laptops but forgetting external drives

Storing recovery keys on the same device

Assuming cloud storage is automatically encrypted in the way you need

Sending PHI through personal email or text messages

Using outdated encryption settings left from older equipment

Not verifying that encryption is actually turned on

Keep the Keys Safe

Encryption is only as strong as the way keys and passwords are managed. Define who can access recovery keys, store them in a secure system, and include them in your recovery plan.

Does Encryption Slow People Down?

On modern computers, the performance impact of disk encryption is typically small. The bigger issue is process: someone must manage keys and make sure devices are enrolled. That is a one-time setup for new devices and can be built into your onboarding checklist.

A Quick Audit You Can Do This Month

List all laptops, tablets and phones that access PHI

Check encryption status on each

Identify any USB drives holding PHI

Test whether outbound email encryption works

Confirm backups are encrypted

Document gaps and a plan to fix them

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations enable and verify encryption across devices, email and backups, and document it for HIPAA purposes. If you are not sure whether your laptops are encrypted, we can check.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172