Encryption sounds technical, but the core idea is simple. It scrambles information so that it is unreadable without a key. If someone steals an encrypted laptop, they get a pile of gibberish instead of resident records. For healthcare organizations, that difference can determine whether an incident becomes a reportable breach.
This post explains where encryption matters, how it connects to HIPAA, and how to avoid common mistakes.
The Security Rule lists encryption and decryption as an addressable specification for access control, and encryption of data in transmission as an addressable item for transmission security. Addressable does not mean optional. You must assess whether the measure is reasonable and appropriate, implement it or an equivalent alternative, and document your reasoning.
The Breach Notification Rule adds a strong incentive. HHS guidance describes how protected health information that has been rendered unusable, unreadable or indecipherable to unauthorized persons, through encryption consistent with NIST standards, is considered secured, and its loss generally does not trigger breach notification. The encryption has to be properly implemented, and the key must not have been compromised along with the data.
This is information stored on laptops, desktops, servers, phones, USB drives, backup media and cloud storage. Protecting it is essential for lost or stolen devices.
This is information moving across networks, such as email, web sessions, remote connections and file transfers. Protecting it prevents eavesdropping and tampering on the way.
Laptops and any portable computers, using built-in full-disk encryption such as BitLocker on Windows or FileVault on Mac
Smartphones and tablets that access email or clinical apps, with a screen passcode required, which also activates device encryption on most current models
Backups, especially copies stored off-site or in the cloud
Servers and databases that hold ePHI, as appropriate
USB drives, ideally by limiting their use or requiring encrypted drives
Email containing sensitive information, using a secure email or portal feature rather than standard messages when sending outside your organization
For transit, make sure websites and applications use HTTPS, remote access uses a VPN or secure gateway, Wi-Fi uses modern encryption such as WPA3 or WPA2 Enterprise for staff networks, and file transfers use secure protocols.
Encryption is only as strong as the handling of its keys.
Store recovery keys in a secure, central place, not on the same device
Limit who can retrieve them
Have a process for recovering a locked device, since lost keys mean lost data
Rotate or revoke keys when staff leave or a device is compromised
Assuming a device is encrypted without verifying it. Run a report to confirm status on every laptop
Using a weak or blank sign-in, which can defeat disk encryption in practice
Leaving a device unlocked or logged in when it is lost
Sending sensitive files by email with a password in the same message
Encrypting the laptop but saving unencrypted copies to a personal cloud account
Forgetting older devices and copiers with internal drives
Believing encryption replaces other controls. It does not stop malware that runs while a system is unlocked
Ask your IT team for a simple report: how many laptops and mobile devices you have, how many are encrypted, and how that is verified. For servers and backups, ask where encryption is enabled and where recovery keys are stored. Record the results in your risk analysis.
On modern hardware, built-in encryption has little noticeable effect on performance, and the major operating systems include it at no additional license cost for many editions. The larger effort is in management and verification, which is where a central management tool helps.
UnityCare IT helps healthcare organizations verify encryption across devices, set up key management and document the safeguards for HIPAA. If you are unsure whether your laptops would qualify for safe harbor after a loss, we can check them with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172