Back to What's Changing

Data Encryption

Scrambling patient data so it's unreadable if it's ever stolen.

What it means

Encryption scrambles patient data into unreadable code that can only be unlocked with the correct key. "At rest" encryption protects data sitting on a server, hard drive, or backup. "In transit" encryption protects data while it's moving — like when a record is emailed or synced to the cloud.

Why it matters

If an encrypted laptop is lost or stolen, it generally does not count as a reportable HIPAA breach, because the data is unreadable without the key. Unencrypted data that's lost almost always does — meaning mandatory patient notifications, potential fines, and reputational damage.

What this looks like in practice

Full-disk encryption on all computers and laptops
Encrypted backups, including offsite and cloud backups
Encrypted email for anything containing patient information
Encrypted connections (HTTPS/VPN) for remote access to systems
Not sure where your practice stands on this?

Get a free 30-minute readiness check — no pressure, just clarity on what you need.

Get My Free Readiness Check