Encryption Everywhere: PHI at Rest, in Transit, and in Use
Full-disk encryption protects against a stolen server. It does nothing about a compromised application account, which is the realistic threat. What each layer actually defends.
GuardsArm Team
Security Experts
"The database is encrypted" is one of the most reassuring and least informative sentences in a security review. Encryption is not one control — it is three, each defending a different scenario, and the one most commonly deployed defends the scenario least likely to happen.
What each layer actually defends against
| Layer | Protects against | Does NOT protect against |
|---|---|---|
| Full-disk / at rest | Physical theft, improper media disposal, a stolen backup tape | A compromised application, a stolen credential, an attacker with OS access |
| Database TDE | Theft of the database files themselves | Any query issued through the application's own connection |
| Column / field level | Casual internal access, some DBA access | An application that legitimately decrypts the field |
| In transit (TLS) | Interception, on-path attacks, sniffing an internal VLAN | An endpoint that is already compromised |
| In use (confidential computing) | A compromised host reading memory | Flaws in the application logic itself |
The important row is the first. Full-disk encryption protects a server that is carried out of the building. Once that server is running and the application is authenticated, the data is plaintext to anything with valid access. That is worth having — it is exactly what HIPAA's addressable specification contemplates — but it should never stand in for access control in a risk assessment.
In transit, including the part people skip
External TLS is universal. Internal TLS frequently is not, on the assumption that the internal network is trusted — the same assumption that makes lateral movement so productive.
The gaps that recur in hospital estates:
- HL7 over plain TCP between the interface engine and clinical systems, carrying complete patient records in clear text
- DICOM without TLS between modalities and PACS — see DICOM and PACS security
- Database connections from application servers, unencrypted inside the data centre
- Backup traffic to the backup target
- LDAP rather than LDAPS for directory queries
- Legacy TLS versions still enabled for compatibility with one old device
An attacker with any foothold on the network reads all of this without touching a single authenticated system.
Key management is the actual control
Encryption moves the problem from protecting data to protecting keys. Where the key lives determines what the encryption is worth.
Practical requirements:
- Separation — the key store should not be compromised by the same event
- Rotation that has actually been exercised, not just documented
- Escrow and recovery, because losing a key destroys data as surely as ransomware does
- Access logging on key use, which is often the only signal of bulk abuse
- Recovery without the primary environment, which matters during a disaster
Safe harbour, stated precisely
Under HHS guidance, PHI rendered unusable, unreadable or indecipherable — encryption meeting the specified standards being the main route — may mean a loss is not a reportable breach. This is a real and significant benefit.
Two caveats worth stating plainly:
- It applies to the encrypted state. A laptop encrypted at rest but stolen while powered on and logged in is not protected by it.
- It does nothing where the attacker used legitimate credentials, because the data was decrypted for them by design.
So safe harbour is a strong argument for encrypting laptops, portable media and backups — and no argument at all for relaxing access control.
Where to start
Map where PHI moves inside your network and find the unencrypted hops. The interface engine is usually the largest one, and it usually carries the most complete records. Fixing internal TLS on clinical interfaces is unglamorous and removes a genuine exposure that full-disk encryption never touched.
GuardsArm reviews encryption posture across clinical estates, including internal transit gaps and key custody. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Encryption Everywhere: PHI at Rest, in Transit, and in Use”
Talk to the GuardsArm team about how these services apply to your environment.


