Encryption in Plain English: What Actually Protects Patient Data
Encryption is the single most misunderstood safeguard in a small clinic. Here is what it is, what it is not, and the exact questions to ask your vendors.

What Encryption Actually Is
Forget the math. Encryption is a locked box for information. It scrambles data into gibberish that only someone with the right key can unscramble. Without the key, a stolen laptop full of patient records is just a laptop full of noise.
Here is the part most people get wrong: a password is not encryption. A password is the lock on the front door of the office — it keeps casual visitors out. Encryption is the safe inside. If someone kicks the door in (or, more likely, steals the whole laptop out of a car in a Corpus Christi parking lot), the password does nothing. The encryption is what keeps the contents unreadable.
Most modern devices can do this for free. Windows has BitLocker, Macs have FileVault, iPhones and iPads encrypt by default when a passcode is set. The problem is not cost or complexity — it is that nobody ever turned it on, or nobody ever checked.
The Two States That Matter: At Rest and In Transit
Patient data lives in two states, and both need protection. Once you see the two states, every encryption question gets easier.
Data at rest
Data sitting still: on a laptop, a server, a phone, a backup drive, a USB stick. If someone steals the device, encryption at rest is the only thing standing between them and every record on it. This is full-disk encryption — BitLocker, FileVault, encrypted phones.
Data in transit
Data on the move: emailed to a specialist, uploaded to a payer portal, synced to a cloud backup, pulled up on the doctor’s home computer. If it travels as plain text, anyone in the middle can read it. This is encrypted email, secure portals, and VPN connections.
A clinic can have one and not the other. A laptop with full-disk encryption still leaks data if the biller emails spreadsheets of patient accounts as plain attachments. An encrypted email service does not help if the front-desk computer itself is unencrypted and gets stolen. You need both, and checking both takes less than an hour.
Where Encryption Should Already Be Working
Walk through your office against this list. Every “I don’t know” is a question for your IT person or your vendor — not a reason to panic, just a gap to close.
- Laptops and desktops: full-disk encryption turned on (BitLocker on Windows, FileVault on Mac).
- Phones and tablets used for work: passcode set, which turns on built-in encryption.
- Email carrying patient information: sent through an encrypted email service, not plain Gmail-style sending.
- Your EHR: ask the vendor directly — do not assume it encrypts data on their servers.
- Backups: encrypted before they leave the building or upload to the cloud. An unencrypted backup drive is a copy of your entire practice sitting in someone’s bag.
- USB drives and portable drives: encrypted, or better yet, not used for patient data at all.
What to Ask Your Software Vendors
Vendors love to say “we take security seriously.” That sentence means nothing. These five questions mean something — ask them in an email so the answers are in writing:
- Is our patient data encrypted when it sits on your servers — not just when it moves?
- Is it encrypted in transit, every time it travels between our office and you?
- Who holds the encryption keys — you, us, or both?
- If a laptop running your software is stolen, is the data stored on that laptop encrypted?
- Will you put these answers in writing for our records?
A straight vendor answers all five in a paragraph each. A vendor that dodges, or answers a different question than the one you asked, is telling you something too. File the answers with your risk analysis — auditors and insurers both like seeing them.
What to Do Monday Morning
Check one laptop yourself. On Windows, open Settings, search “Device encryption” or “BitLocker,” and see whether it says on or off. On a Mac, open System Settings, go to Privacy & Security, and look for FileVault. If it is off, turning it on is usually a few clicks — do it plugged in, because the first encryption pass takes a while.
Then send the five vendor questions to your EHR company. You will either get reassuring answers or discover a gap while there is still time to fix it. Either way, you end the day knowing more than you did that morning, which is the whole point.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
Is encryption actually required by HIPAA?
The Security Rule lists encryption as “addressable,” which does not mean optional. It means: implement it, or document why not and do something equivalent. In practice, for a small clinic, there is no equivalent — just encrypt.
How do I know if my laptop is encrypted?
On Windows, search Settings for “Device encryption” or “BitLocker.” On a Mac, check System Settings, then Privacy & Security, then FileVault. If it says off or you cannot find it, ask your IT person before the laptop leaves the office again.
Is a strong password the same as encryption?
No. A password controls who can log in; encryption scrambles what is stored. Pull the drive out of a password-protected-but-unencrypted laptop and everything on it is readable. Pull the drive out of an encrypted laptop and it is gibberish.
Does my EHR encrypt our data automatically?
Do not assume it. Many do, but “many” is not an answer you want to give an auditor. Ask the vendor the five questions above and get the answers in writing.
If an encrypted laptop is stolen, is that a breach we have to report?
HIPAA’s Breach Notification Rule has a safe harbor: properly encrypted data that is stolen generally does not count as a breach, because the thief cannot read it. That safe harbor alone is worth the afternoon it takes to turn encryption on.