Your Devices
Encryption is the one setting that turns a lost laptop from a breach into a paperweight. Same stolen device, completely different day. Every modern operating system has it built in, usually one toggle away.
Why this chapter exists, in plain English
Picture this: you’re at a coffee shop between sessions, your laptop is on the table, and you step away for thirty seconds to grab a refill. When you come back, it’s gone. For most people that’s a lost laptop. For you it could be a reportable breach — because somewhere on that disk is a cached email, a downloaded insurance form, a scheduling note. That’s your patients’ health information, in electronic form, and you’re responsible for keeping it safe whether you saved it there on purpose or not.
Encryption is the fix — it scrambles everything on the device so it’s unreadable to anyone who doesn’t have your password. Turn it on, and a stolen laptop is just a dead slab of metal to whoever walked off with it. HIPAA expects you to do this unless you have a very good, written reason not to — and for a laptop or phone that could leave the building, there isn’t one.
It’s also the biggest win you can get for the least effort. Locked cabinets and privacy screens help, but nothing else turns a stolen device into a non-event the way encryption does. Better still, it’s already built into your devices: FileVault on a Mac, BitLocker (or Device encryption) on Windows, and automatic encryption on an iPhone or Android the moment you set a passcode. Usually it’s one toggle away.
Setup
Which of these do you use for anything work-related? Pick every one.
You can change this list at any time — adding a new device just adds another configure block below.
Where you stand
Not quite there yet
Pick at least one device above to begin.