Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› When should healthcare teams prioritise encryption for laptops,…
Cyber Security

When should healthcare teams prioritise encryption for laptops, portable devices, backup media, and wireless traffic?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Cyber Security

Healthcare teams should prioritise encryption when protected health information may be exposed through lost devices, removable media, or wireless transmission. Encryption does not eliminate every reporting obligation, but it can reduce breach impact and may change how incidents are handled. The strongest approach is to treat encryption as a baseline control for data at rest and data in transit across mobile and distributed environments.

When encryption should move from “good practice” to priority control

Encryption becomes a priority when a device or medium can leave the protected clinical environment, be lost, or carry patient data across an untrusted network. That includes laptops used on and off site, portable drives, backup tapes or disks, and wireless traffic that may traverse shared radio space. The practical question is not whether encryption is useful, but whether exposure without it would create avoidable patient-data risk.

For healthcare teams, the baseline decision is to encrypt when data could be exposed outside tightly controlled infrastructure, especially when portability, remote work, or backup retention increases the chance of physical loss, theft, or interception. Full-disk encryption, encrypted removable media, and strong wireless encryption together reduce the likelihood that an incident becomes a reportable disclosure.

Why these asset types justify encryption first

Laptops and portable devices are high-priority because they concentrate data and travel. A single lost endpoint can expose local files, cached attachments, browser sessions, and synced records if the device is not protected at rest. Encryption is most valuable here because it protects data even when the device itself is no longer under your control.

backup media deserves the same treatment because backups are often broader, older, and less frequently accessed than production systems. That creates a common gap: the copy that is meant to restore operations can become the copy most likely to be mishandled. Wireless traffic should be encrypted because radio transmission extends the trust boundary beyond the building, and weak or misconfigured protection can allow interception or session capture. For media disposal and retention planning, teams should align these controls with NIST SP 800-88 Media Sanitization, which is the clearest reference for disposal, clearing, purging, and destruction decisions.

In practice, encryption is strongest when it is paired with key management, device inventory, and verified recovery procedures. If teams cannot prove which assets are encrypted, where keys are held, and how recovery works during restore testing, the control is weaker than it looks on paper. For general control coverage, CIS Controls v8 provides a useful operational baseline for data protection, secure configuration, and asset governance.

How to decide whether encryption is enough

Encryption reduces exposure, but it does not automatically solve every incident. A stolen but encrypted laptop is very different from a compromised account that can still decrypt data, sync files, or access cloud services. That is why healthcare teams should separate the physical-loss problem from the access-compromise problem and review both before assuming the control is complete.

Wireless and removable-media encryption should also be judged against usability and operational resilience. If clinicians bypass controls because they are too slow, too hard to unlock, or too disruptive during care delivery, the policy will not hold. The better decision is to choose controls that are strong enough to protect the data and simple enough to survive real clinical workflow, including shifts, emergencies, and shared-device conditions.

For a broader control lens, NIST SP 800-53 Rev. 5 Security and Privacy Controls gives teams a structured way to connect encryption with access control, media protection, and system integrity, while the CISA Known Exploited Vulnerabilities Catalog is useful when you are deciding whether a device exposure is more likely to be driven by weak encryption or by an actively exploited software weakness.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SC-13 — Cryptographic ProtectionEncryption of devices, media, and wireless traffic is directly about cryptographic protection.
MP-6 — Media SanitizationBackup media and portable storage require secure disposal and sanitization decisions.
AC-19 — Access Control for Mobile DevicesLaptops and portable devices need control of portable endpoints that leave the site.
Recommendation — Apply SC-13 to protect patient data at rest and in transit with approved cryptography. Use MP-6 to sanitize backup and removable media before reuse or disposal. Apply AC-19 to enforce protection requirements on mobile devices that store sensitive data.
ISO/IEC 27001:2022A.8.24 — Use of cryptographyThe question is specifically about encrypting data at rest and in transit.
A.7.10 — Storage mediaBackup media and removable storage require explicit handling and protection controls.
Recommendation — Define encryption rules for endpoints, media, and wireless traffic under A.8.24. Control storage media handling and protection for backups and portable devices.

Practitioner Guidance

What to prioritise: Start with endpoints and backup sets that contain patient data outside the most tightly managed environment, then extend to removable media and wireless links that cross trust boundaries. If the asset can be lost, transported, replicated, or intercepted, it should be treated as an encryption candidate by default.

What to verify: Confirm that encryption is enabled by policy, not by exception, and that recovery keys are escrowed in a way that supports restore without creating a separate access sprawl. Teams should be able to show which device classes, media types, and wireless standards are covered, plus evidence that restores and remote access still work after key rotation or device replacement.

Common mistake: Treating “encrypted” as a binary label without checking scope. A partially encrypted fleet, unencrypted backup exports, or weak wireless settings can leave the highest-risk data paths exposed even when the policy appears complete.

Practitioner takeaway: In healthcare, encryption is not just a technical hardening step, it is a boundary-setting control. Prioritise it wherever patient data can leave direct physical custody or move across untrusted transmission paths, then validate that keys, recovery, and workflow reality do not undermine the protection.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org