A working analysis published this week in Medical Economics makes a point worth pausing on: the classic HIPAA breach story, an unencrypted laptop stolen from a car, has largely gone away. Full disk encryption is now on by default on almost every laptop, phone, and tablet a practice buys, and OCR breach data cited in the piece shows lost or stolen device breaches fell from roughly half of large reported breaches before 2015 to under 10% by 2024, with only about six such breaches reported nationwide in 2025. That is a real win. The problem is that endpoint risk did not disappear, it moved to the parts of the environment that default encryption and centralized management never touched in the first place.

Three of those parts sit inside almost every small practice today. First, the personal phones and home laptops staff use to reach scheduling, billing, patient messaging, or a portal login. A 2025 JMIR Human Factors study cited by the article found most personal devices used for clinical work are inconsistently enrolled in any device management system, and app-level containers say nothing about whether the device itself is encrypted or patched. Second, the connected equipment in the exam room and imaging suite. HHS HC3 has reported that 28% of health care organizations run devices past the manufacturer's end-of-support date, and 44% knowingly run end-of-support devices with unpatched, publicly known vulnerabilities. That equipment does not need to hold records to be dangerous; it needs only to sit on the same network as the systems that do. Third, encryption recovery keys. BitLocker or FileVault keys stored on a shared drive, in a spreadsheet, or on a printed sheet in a desk drawer defeat the encryption they were meant to protect.

HIPAA already requires a practice to perform and keep current an accurate and thorough risk analysis of the systems that create, receive, maintain, or transmit ePHI. All three of these blind spots belong inside that risk analysis, not in a separate project. OCR's enforcement pattern has been consistent for years: organizations rarely get penalized for lacking a security program entirely, they get penalized because their risk analysis had a gap that nobody closed. A personal phone that was never inventoried, an imaging workstation on Windows 7 sharing a subnet with the billing server, and a recovery key sitting on the shared drive are exactly that kind of gap.

What to check in your practice