You probably already know what encryption is for: keeping your data secure. What’s less obvious is how much of it your business is legally obligated to do, and how differently a regulator treats a lost laptop depending on whether the drive was readable.
Encryption stopped being a purely technical decision some time ago. It now appears in federal rules that carry civil penalties, in state statutes that name it outright, and in the language deciding whether a missing drive becomes a public breach notice or an internal memo.
This post covers where the law requires data encryption, the relief encrypted records provide when something goes wrong, and what companies pay when they skip it. For more hands-on mechanics, from self-encrypting media to encrypting a folder on a Windows machine, our walkthrough on how to encrypt your data covers the steps.
Why Data Encryption Carries Legal Weight
Most controls around a records program protect the container. Access permissions, locked rooms, cleared drivers, and visitor logs all assume the file stays where you put it. Encryption is the one control that keeps working after that assumption breaks, whether a laptop leaves a car, a misconfigured storage bucket gets indexed, or a subcontractor’s credentials turn up for sale.
Regulators noticed. Rather than write a full security architecture into a rule, agencies build obligations around a single question: could an unauthorized person read this? Encryption is a reliable way to answer no, which is why it is central to so many federal and state requirements.
Digitizing raises the stakes in a way paper never did. A box in a warehouse is one object in one place. Run that box through a document scanning project and it becomes image files on a scanner, a technician’s workstation, a transfer drive, a quality-control queue, and a document management system. That can mean five portable copies where there had been one. Sorting out which files need encryption is the first practical step and, for most businesses, the list runs longer than expected.
How Encryption Limits Breach Exposure
Encryption does two jobs in compliance. The first is straightforward: some rules simply require it. Many businesses underestimate the second: across most American breach frameworks, properly encrypted data is carved out of the notification machinery altogether.
Regulators call this a safe harbor. The Breach Notification Rule under the Health Insurance Portability and Accountability Act (HIPAA) reaches only unsecured protected health information. The Federal Trade Commission’s (FTC) reporting trigger for financial institutions counts only unencrypted customer information. Nearly every state breach notification statute contains some version of the same exemption, such as California’s private right of action requirement that the exposed data be nonencrypted and nonredacted.

In practice, properly encrypted records can keep a stolen drive from triggering notification at all, depending on the applicable law and whether the key was compromised. The same incident either becomes a regulatory event with letters, call centers, and attorney general attention, or something you document internally and move past.
Two conditions decide which one you get:
- Keys have to live somewhere else. The Department of Health and Human Services (HHS) is explicit that decryption tools should be stored separately from the data they open, and the FTC treats customer information as unencrypted when an unauthorized person has accessed the key. Full-disk encryption offers little protection if the passphrase travels with the laptop.
- Your implementation has to meet the applicable standard, and definitions vary by state. Some statutes say “encrypted” and leave it there; others name a recognized standard or algorithm class, or add that the key must not have been acquired.
For data at rest, HHS points to its breach safe harbor guidance and to the National Institute of Standards and Technology’s Special Publication 800-111. Assuming your setup qualifies in all 50 states is a poor bet, and a breach response plan built on that assumption is worse.
Which Rules Apply to Your Records
No single American statute orders every company to encrypt data across the board.
What we have instead is a patchwork: sector rules that require it outright, rules that require it unless you can document why not, and breach statutes that provide relief when encrypted data is exposed. Plenty of businesses fall inside more of these frameworks than they expect. If your organization is bound by records storage laws, encryption is almost certainly somewhere in the stack.
HIPAA and Patient Records
Coverage here runs past hospitals and clinics. Business associates fall under HIPAA too, which pulls in billing companies, IT vendors, and contractors handling patient information on a covered entity’s behalf.
The HIPAA Security Rule lists encryption of electronic protected health information as an addressable implementation specification, both at rest and in transit. Addressable is the word that trips people up; it has never meant optional.
An organization that decides against encryption has to document why it isn’t reasonable and appropriate for its environment, then adopt an equivalent alternative where one is. The Office for Civil Rights has rarely found that documentation persuasive after a device goes missing.
That flexibility may be ending. HHS proposed a Security Rule overhaul in January 2025 that would delete the addressable-versus-required distinction and mandate encryption with narrow exceptions.
The proposal drew heavy industry opposition and hasn’t been finalized, and the department’s regulatory agenda now points to July 2027. Treat it as a general direction rather than a deadline. A closer look at what HIPAA covers fills in the rest, and the medical records our network’s providers handle sit inside that scope.

The GLBA Safeguards Rule
This is the framework companies miss most often, because its definition of a financial institution stretches well beyond banks. It covers mortgage brokers, auto dealers, tax preparers, collection agencies, credit counselors, investment advisers not registered with the Securities and Exchange Commission (SEC), and companies that simply connect buyers with sellers.
For a covered business, the requirement is direct. The FTC’s Safeguards Rule, which implements the Gramm-Leach-Bliley Act (GLBA), requires those companies to protect by encryption all customer information held or transmitted, in transit over external networks and at rest. The one exception: where encryption is infeasible, you may substitute effective alternative compensating controls, reviewed and approved by your designated Qualified Individual.
Small institutions don’t entirely escape this rule. A company holding information on fewer than 5,000 consumers is relieved of four obligations: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan, and the annual board report. Encryption isn’t among them.
Since May 2024, the rule has also imposed a reporting obligation. Unauthorized acquisition of unencrypted customer information affecting at least 500 consumers has to reach the FTC as soon as possible, and no later than 30 days after discovery. Where an unauthorized person accessed the decryption key, the agency treats the data as though it had never been protected.
GLBA reaches past the Safeguards Rule, adding privacy and pretexting obligations on top, and financial services organizations are usually subject to several frameworks at once.
SEC Rules for Investment Firms
Broker-dealers, investment companies, registered advisers, and transfer agents follow a separate SEC rulebook. The agency rewrote Regulation S-P in 2024 to require a written breach response plan and notice to affected customers within 30 days. The last compliance date passed June 3, 2026, so the rules now apply to every firm the regulation covers, down to the smallest advisory shop.
Regulation S-P doesn’t spell out encryption the way the Safeguards Rule does, and it doesn’t have to. A firm can skip the notice only if it investigates and concludes the exposed information isn’t likely to be used in a way that causes real harm or inconvenience. Data nobody can read is the easiest way to reach that conclusion.
Retention rules sit right alongside the privacy ones. Broker-dealers keep records under Exchange Act Rule 17a-4, registered advisers under Advisers Act Rule 204-2. One client account statement can be a file you’re required to hold for years and required to protect the whole time it’s there, so a financial record keeping system has to do both jobs at once. At most firms, legal and compliance teams manage that overlap.

State Security and Privacy Laws
A handful of states impose more explicit encryption requirements. Massachusetts sets the strictest baseline in the country: 201 CMR 17.04 requires encryption of all personal information transmitted across public networks or wirelessly, plus encryption of all personal information stored on laptops and other portable devices.
The only softening is a “to the extent technically feasible” qualifier at the top of the section, and state guidance reads it narrowly: where a reasonable technical means exists, it has to be used. That is a far higher bar than an addressable standard.
Nevada requires data collectors to encrypt personal information moving electronically outside their secure systems, and compliance shields them from damages absent gross negligence or intentional misconduct.
California addresses the issue through liability when encryption is absent: the California Consumer Privacy Act gives consumers a private right of action when nonencrypted and nonredacted personal information is exposed through a business’s failure to maintain reasonable security, with statutory damages of up to $750 per consumer, per incident.
Twenty states now have comprehensive consumer privacy laws in force, nearly all requiring reasonable security appropriate to the data. Stack sector rules on top — the Family Educational Rights and Privacy Act (FERPA) for schools and districts, state medical retention schedules, insurance regulations — and a company operating across state lines answers to several standards at once.
PCI DSS and Card Data
One more framework can impact businesses that don’t consider themselves as regulated: the Payment Card Industry Data Security Standard (PCI DSS). It isn’t law — it’s contractual, enforced by the card brands and your acquiring bank. Failing it can cost you the ability to accept cards. Version 4.0.1 requires stored card numbers to be unreadable wherever they’re kept, and requirements that became mandatory in March 2025 narrowed what qualifies. Disk-level encryption alone generally no longer satisfies the standard on media that isn’t removable. If your records program touches anything with a card number on it, from a scanned credit application to an archived invoice, this applies to you.
What Noncompliance Costs
Penalties and Private Lawsuits
HIPAA penalties are adjusted for inflation, and the amounts now in force took effect January 28, 2026. They run from $145 per violation at the lowest tier to $2,190,294 for willful neglect left uncorrected past 30 days. A continuing violation is assessed separately for each day it persists, and where the obligation runs to individuals, separately for each person affected.
One unencrypted device holding thousands of charts generates far more than a single penalty. State attorneys general can bring their own HIPAA actions where HHS isn’t pursuing the same violation, and the record of HIPAA violations is largely a story of lost and stolen hardware.
Texas adds another layer, assessing civil penalties of at least $2,000 and up to $50,000 for each violation of its Identity Theft Enforcement and Protection Act, plus as much as $100 per affected person for every day a required notification is delayed, capped at $250,000 per breach.
Regulators aren’t the only parties with standing. California’s statutory damages don’t turn on proof of financial loss, though a plaintiff still has to plead that the data was actually taken or disclosed rather than merely exposed. A breach touching 50,000 residents there carries theoretical exposure between $5 million and $37.5 million before defense costs, and encryption is the specific fact that keeps a company outside that statute.

The Cost of the Breach Itself
Penalties are only part of the bill. IBM’s 2026 Cost of a Data Breach study put the global average at $4.99 million. This shows the cost up 12% year over year, with the U.S. average at $11.5 million and health care again the costliest sector at $6.64 million per incident. Those figures fold in forensics, outside counsel, notification, credit monitoring, regulatory response, downtime, and lost business.
Set against that, encrypting data is inexpensive. Full-disk encryption is built into every current desktop operating system, and reputable cloud and document management platforms include it, though built in isn’t the same as switched on. The expensive part for a records program is the inventory work of finding every place the data actually sits.
Where Encryption Gaps Usually Hide
Data compliance gaps in records management often appear outside the systems teams monitor most closely.
- Legacy media. Backup tapes and microfilm predate most encryption policies. Tapes written a decade ago on hardware nobody still owns sit in offsite vaults right now holding personal information governed by today’s rules, not those in force when they were written.
- Data in motion during a project. A digitization engagement moves boxes out of your control and into a truck. That’s the window where chain of custody documentation and encrypted transfer of the resulting image files stop being paperwork and start being evidence.
- Vendors. Your obligations follow your data. Business associate agreements, service provider oversight under state privacy laws, and the Safeguards Rule’s vendor provisions leave you on the hook for what a contractor does with files you handed over. Certification is the practical filter: providers holding PRISM Privacy+ have had their information management controls verified by an independent auditor as a condition of keeping the credential.
- End of retention. Encrypted archives still have to be disposed of when their retention period runs out. Retention schedules govern digital copies the same way they govern boxes, and cryptographic erasure isn’t universally accepted as destruction, while certified destruction of the underlying media generally is.
- Cloud repositories. Encrypted data storage inside a vendor’s data center is the baseline. The questions worth asking are who holds the keys, whether data stays encrypted in transit between services, and what happens at offboarding. Working through cloud storage security with a provider before you sign is worth the hour it takes.
Matching Your Records to a Compliant Provider
Meeting these requirements is easier with providers already operating under the applicable rules. Record Nations connects you with local scanning and storage companies chosen for the certifications, data security controls, and industry experience your project calls for, which cuts the time spent contacting vendors and comparing key-management practices.
Our network of providers run document scanning in Minneapolis and records storage in Denver under the same expectations, so your controls don’t change with the location of the files. Whether you need paper converted, offsite storage with indexed retrieval, or cloud storage with encryption applied before upload, we can help find competitive quotes from companies able to document how they’d protect the data.
To get started, fill out our form or call us at (866) 385-3706. We’ll help scope the project and connect you with providers in your area who can meet the requirements you’re working under.