A working analysis published this week in Medical Economics makes a point worth pausing on: the classic HIPAA breach story, an unencrypted laptop stolen from a car, has largely gone away. Full disk encryption is now on by default on almost every laptop, phone, and tablet a practice buys, and OCR breach data cited in the piece shows lost or stolen device breaches fell from roughly half of large reported breaches before 2015 to under 10% by 2024, with only about six such breaches reported nationwide in 2025. That is a real win. The problem is that endpoint risk did not disappear, it moved to the parts of the environment that default encryption and centralized management never touched in the first place.
Three of those parts sit inside almost every small practice today. First, the personal phones and home laptops staff use to reach scheduling, billing, patient messaging, or a portal login. A 2025 JMIR Human Factors study cited by the article found most personal devices used for clinical work are inconsistently enrolled in any device management system, and app-level containers say nothing about whether the device itself is encrypted or patched. Second, the connected equipment in the exam room and imaging suite. HHS HC3 has reported that 28% of health care organizations run devices past the manufacturer's end-of-support date, and 44% knowingly run end-of-support devices with unpatched, publicly known vulnerabilities. That equipment does not need to hold records to be dangerous; it needs only to sit on the same network as the systems that do. Third, encryption recovery keys. BitLocker or FileVault keys stored on a shared drive, in a spreadsheet, or on a printed sheet in a desk drawer defeat the encryption they were meant to protect.
HIPAA already requires a practice to perform and keep current an accurate and thorough risk analysis of the systems that create, receive, maintain, or transmit ePHI. All three of these blind spots belong inside that risk analysis, not in a separate project. OCR's enforcement pattern has been consistent for years: organizations rarely get penalized for lacking a security program entirely, they get penalized because their risk analysis had a gap that nobody closed. A personal phone that was never inventoried, an imaging workstation on Windows 7 sharing a subnet with the billing server, and a recovery key sitting on the shared drive are exactly that kind of gap.
What to check in your practice
- List every personal device (phones, tablets, home laptops) that can reach your EHR, patient portal, billing system, or practice email, and confirm each one is enrolled in a device management or app protection tool. If it is not, decide this quarter whether to enroll it or cut its access.
- Ask every medical device and imaging vendor, in writing, what operating system each connected device runs and when the manufacturer's support ends. Use the answer to decide what belongs on a separate, isolated network segment rather than sharing one with billing and scheduling.
- Find out where your BitLocker or FileVault recovery keys actually live today. If the answer is a shared drive, a spreadsheet, or a desk drawer, move them to a managed, access-logged location this quarter.
- Add each of these three items (BYOD inventory, end-of-support equipment, recovery-key storage) as named line items in your written HIPAA Security Rule risk analysis and risk management plan, with an owner and a target date. Do not treat them as a separate project.