Encryption turns readable information into scrambled data that can only be unscrambled with the right key. If an encrypted laptop is lost or stolen, the thief gets a locked box instead of resident records. That difference is big enough that HHS guidance treats properly encrypted PHI as "secured," which can mean a lost device does not trigger breach notification.
Encryption is one of the highest-value protections available, and the tools are often already built into the systems you use. Here is a plain-English guide.
Protects data stored on a device or server: laptop drives, phones, USB sticks, backup media and cloud storage.
Protects data moving between places: email, web connections, VPN tunnels, Wi-Fi and file transfers.
You need both. A locked laptop with an unprotected email is only half protected.
The current Security Rule lists encryption as an "addressable" implementation specification, which means you must assess whether it is reasonable and appropriate, and either implement it or document an equivalent alternative. In practice, for portable devices, it would be hard to justify skipping it. The proposed update published in January 2025 would make encryption more clearly required, but it is a proposal and not final. Either way, encrypting is sound practice.
Windows includes BitLocker on many business editions, and Macs include FileVault. Turn it on and store recovery keys securely, such as in your management system, not on a sticky note.
Confirm status with a report from your management tool instead of assuming.
Laptops used by physicians, administrators and traveling staff come first.
Modern iPhones and Android devices encrypt storage when a passcode is set. Require a passcode and enable remote wipe.
Use mobile device management to enforce settings on devices that access email or resident information.
Best option: prohibit USB storage of PHI and provide secure alternatives.
If you must allow it, use encrypted drives and track them.
Encrypt backup data both on the media and in cloud storage.
Ask cloud vendors how they encrypt data and who holds the keys.
Protect backup encryption keys, because losing them can make backups unreadable.
Standard email can cross multiple servers in readable form unless protected. Many providers use encrypted connections between servers when available, but that is not guaranteed.
Use a secure email encryption feature for messages containing PHI sent outside the organization, ideally triggered automatically by keywords or a subject-line tag.
Better still, use a secure portal or messaging system for sensitive exchanges.
Make sure all sites collecting information use HTTPS.
Use VPN or secure gateways with current encryption standards.
Use WPA2 or WPA3 for staff networks and avoid open networks for anything involving PHI.
Encrypting laptops but forgetting external drives
Storing recovery keys on the same device
Assuming cloud storage is automatically encrypted in the way you need
Sending PHI through personal email or text messages
Using outdated encryption settings left from older equipment
Not verifying that encryption is actually turned on
Encryption is only as strong as the way keys and passwords are managed. Define who can access recovery keys, store them in a secure system, and include them in your recovery plan.
On modern computers, the performance impact of disk encryption is typically small. The bigger issue is process: someone must manage keys and make sure devices are enrolled. That is a one-time setup for new devices and can be built into your onboarding checklist.
List all laptops, tablets and phones that access PHI
Check encryption status on each
Identify any USB drives holding PHI
Test whether outbound email encryption works
Confirm backups are encrypted
Document gaps and a plan to fix them
UnityCare IT helps healthcare organizations enable and verify encryption across devices, email and backups, and document it for HIPAA purposes. If you are not sure whether your laptops are encrypted, we can check.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172