Encryption in Plain English: What Healthcare Teams Need to Know

Encryption sounds technical, but the core idea is simple. It scrambles information so that it is unreadable without a key. If someone steals an encrypted laptop, they get a pile of gibberish instead of resident records. For healthcare organizations, that difference can determine whether an incident becomes a reportable breach.

This post explains where encryption matters, how it connects to HIPAA, and how to avoid common mistakes.

Why HIPAA cares

The Security Rule lists encryption and decryption as an addressable specification for access control, and encryption of data in transmission as an addressable item for transmission security. Addressable does not mean optional. You must assess whether the measure is reasonable and appropriate, implement it or an equivalent alternative, and document your reasoning.

The Breach Notification Rule adds a strong incentive. HHS guidance describes how protected health information that has been rendered unusable, unreadable or indecipherable to unauthorized persons, through encryption consistent with NIST standards, is considered secured, and its loss generally does not trigger breach notification. The encryption has to be properly implemented, and the key must not have been compromised along with the data.

The two main types

Data at rest

This is information stored on laptops, desktops, servers, phones, USB drives, backup media and cloud storage. Protecting it is essential for lost or stolen devices.

Data in transit

This is information moving across networks, such as email, web sessions, remote connections and file transfers. Protecting it prevents eavesdropping and tampering on the way.

What to encrypt first

Laptops and any portable computers, using built-in full-disk encryption such as BitLocker on Windows or FileVault on Mac

Smartphones and tablets that access email or clinical apps, with a screen passcode required, which also activates device encryption on most current models

Backups, especially copies stored off-site or in the cloud

Servers and databases that hold ePHI, as appropriate

USB drives, ideally by limiting their use or requiring encrypted drives

Email containing sensitive information, using a secure email or portal feature rather than standard messages when sending outside your organization

For transit, make sure websites and applications use HTTPS, remote access uses a VPN or secure gateway, Wi-Fi uses modern encryption such as WPA3 or WPA2 Enterprise for staff networks, and file transfers use secure protocols.

Key management matters

Encryption is only as strong as the handling of its keys.

Store recovery keys in a secure, central place, not on the same device

Limit who can retrieve them

Have a process for recovering a locked device, since lost keys mean lost data

Rotate or revoke keys when staff leave or a device is compromised

Common mistakes

Assuming a device is encrypted without verifying it. Run a report to confirm status on every laptop

Using a weak or blank sign-in, which can defeat disk encryption in practice

Leaving a device unlocked or logged in when it is lost

Sending sensitive files by email with a password in the same message

Encrypting the laptop but saving unencrypted copies to a personal cloud account

Forgetting older devices and copiers with internal drives

Believing encryption replaces other controls. It does not stop malware that runs while a system is unlocked

Check your status

Ask your IT team for a simple report: how many laptops and mobile devices you have, how many are encrypted, and how that is verified. For servers and backups, ask where encryption is enabled and where recovery keys are stored. Record the results in your risk analysis.

Performance and cost

On modern hardware, built-in encryption has little noticeable effect on performance, and the major operating systems include it at no additional license cost for many editions. The larger effort is in management and verification, which is where a central management tool helps.

Getting it right

UnityCare IT helps healthcare organizations verify encryption across devices, set up key management and document the safeguards for HIPAA. If you are unsure whether your laptops would qualify for safe harbor after a loss, we can check them with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172