Which Files Do You Need to Encrypt?

Ask most business owners which of their files are encrypted and you’ll likely hear a confident answer about the laptops. Ask which files would actually hurt if they were stolen, and the conversation quickly changes.

When it comes to which files you should encrypt, the list runs longer than most companies expect and isn’t the same for everyone. That’s why we’ve outlined how to determine which of your files should be encrypted, along with some general guidance on common file types. Read on to learn more.

How to Identify Files That Should Be Encrypted

If you’ve never encrypted files before, it can be hard to decide which files should be. These three questions can help narrow it down: 

  • Who else might want this information?
  • How long are you required to keep it?
  • What happens to real people if it gets out?

Answering these questions can help you get a better handle on what files to consider encrypting.

What File Encryption Actually Covers

Encryption scrambles a file so it reads as nonsense without the key, a secret value that has to be stored and guarded somewhere of its own. No key, no readable document.

Where you apply it decides what it protects. File encryption locks one document at a time. Full-disk encryption protects a whole drive and unlocks it when someone signs in at startup, and the National Institute of Standards and Technology (NIST) is blunt on this point: once the device is booted, full-disk encryption provides no protection, and the operating system becomes responsible for everything after that. So it protects the stolen laptop, and little else. Not a document emailed to the wrong person, a folder synced into a misconfigured cloud account, or an archive restored 12 years from now. 

File-level encryption can travel with the document between systems. Full-disk encryption doesn’t, software or self-encrypting drive alike, because it decrypts files as they’re copied out.

Now we’ll look at common file types to protect first — who holds them, how long they have to be kept, and what a breach of each can lead to.

Medical Charts and Patient Data

Who Handles Protected Health Information

Hospitals, private practices, dental offices, imaging centers, labs, and insurers all hold protected information. So do the billing companies, transcription services, IT contractors, and scanning vendors working on their behalf. Those vendors are business associates, and they carry the same obligations as the medical organizations that hired them.

Six Years of Policy, Longer for Charts

The Health Insurance Portability and Accountability Act (HIPAA) sets no retention period for patient charts. That’s the Department of Health and Human Services’ own position, and HHS points covered entities to state law instead. What the rule does require is six years of compliance paperwork: policies, risk analyses, vendor agreements, and incident logs.

State schedules have a long memory. Texas requires physicians to keep records at least seven years from the last treatment, or until a minor patient turns 21, whichever is longer. California hospitals keep records seven years after discharge, and at least a year past an unemancipated minor’s 18th birthday. New York hospitals hold charts six years from discharge, longer for minors and decedents. 

Medicare sets a five-year floor for participating hospitals, and a separate rule runs seven years from the date of service, covering the documentation behind orders, certifications, referrals, and payment requests rather than the chart itself. Our breakdown of medical records retention times goes further.

What Exposure Costs a Practice

HIPAA labels encryption “addressable” rather than required, which has never meant optional. Skip it and you have to document why it wasn’t reasonable for your organization, then put an equivalent measure in its place where that’s reasonable and appropriate.

The better argument is the safe harbor. Breach notification rules reach only unsecured health information, and data encrypted to the standard HHS specifies isn’t unsecured. Encrypt the file and a loss may not be a reportable breach at all. Leave it in the clear and the worst tier of violation starts at $73,011 apiece under the figures effective January 28, 2026.

Patients carry their own version. Medical identity theft mixes a stranger’s treatment history into a chart, which can change the care someone gets.

Financial Statements and Account Numbers

Which Businesses the Rule Covers

The Federal Trade Commission’s Safeguards Rule reaches well past banks. Mortgage brokers, auto dealers, tax preparers, collection agencies, and investment advisers who aren’t registered with the Securities and Exchange Commission (SEC) can all land inside it.

SEC-registered advisers answer to Regulation S-P instead, the commission’s own safeguards and incident response regime. Financial institutions holding information on fewer than 5,000 consumers get a partial break from four requirements under the FTC rule, the written risk assessment and the annual board report among them. The rest of it still applies, so most financial services organizations should assume they’re covered.

Three, Six, and Seven-Year Clocks

Broker-dealers work under SEC Rule 17a-4: six years for core books, three for most of the rest, with the first two years of each kept somewhere easily accessible. 

IRS periods of limitation, meaning the window in which a return can still be examined, run three years by default, six if a return leaves out more than 25% of the gross income it shows, and four for employment tax records. 

Audit workpapers carry seven years under an SEC rule written to implement Sarbanes-Oxley, and Bank Secrecy Act institutions keep applicable records five. We lay the categories side by side in a full guide to business records retention.

When Account Numbers Get Out

This file type carries a direct federal encryption requirement. The Safeguards Rule tells covered businesses to protect by encryption all customer information they hold or transmit, both while it crosses outside networks and while it sits on a drive. The only way around it is deciding encryption isn’t feasible and having your Qualified Individual, the person the rule puts in charge of security, approve alternative controls that work as well.

Notice what triggers the reporting duty. Unauthorized acquisition of unencrypted customer information is the event, and once you discover one affecting 500 or more consumers, it has to reach the FTC as soon as possible, and no later than 30 days after discovery. Take the decryption key along with the data and the agency treats it as never encrypted.

Payroll and Personnel Files

Every Employer, No Exceptions

A company with no customers, no patients, and no clients still holds Social Security numbers, direct deposit details, W-4s, I-9s, and employee medical information. The Americans with Disabilities Act requires that the last category be kept in separate confidential files, a strong hint about how human resources departments should treat the rest.

Overlapping Federal Retention Rules

The Fair Labor Standards Act sets three years for payroll records and two for the timecards behind them. Form I-9 has to be kept three years after the hire date or one year after employment ends, whichever comes later, and paperwork violations currently run from $288 to $2,861 per individual. 

Equal Employment Opportunity Commission rules require one year for personnel records, extended once a discrimination charge is filed. The Employee Retirement Income Security Act adds six years for plan filings. An HR document management system with permissions and audit trails beats tracking that by hand.

Tax Refund Fraud Against Your Staff

The IRS has warned about the same scam for a decade. A spoofed email that looks like it came from an executive lands in payroll asking for the W-2 list. Criminals who get it file fraudulent returns, and employees find out months later through a notice about wages they never earned. Businesses that lose W-2 data are told to email dataloss@irs.gov with “W2 Data Loss” in the subject line. One spreadsheet exposes the whole staff at once.

Case Files and Client Matters

Lawyers, Title Companies, and In-House Teams

Law firms, legal departments, title and escrow companies, and litigation support vendors hold an unusually dense concentration of other people’s secrets. A single matter can contain medical records, tax returns, and deal terms never meant to leave a room, and legal teams inherit every obligation attached.

Trust Records Kept Five to Seven Years

The American Bar Association (ABA) model rule on safekeeping client property calls for trust account records to be kept five years after the representation ends. States have gone their own ways, and the starting line moves with them. For example, New York requires seven years, counted from the events each record documents rather than from the end of the matter, while California measures five years from the final distribution of funds. One category of record, three trigger dates, and an easy set to mix up.

A Breach Reaches Every Client at Once

Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information, and ABA Formal Opinion 477R says strong protective measures, encryption among them, are warranted in some circumstances.

In the association’s 2023 cybersecurity survey, 29% of respondents reported a breach, while only 48% had file encryption available. One international firm agreed to an $8 million class settlement over a 2023 intrusion affecting more than 637,000 people. A breach doesn’t automatically waive attorney-client privilege, but showing you took reasonable steps is much harder when nothing was encrypted.

Student Transcripts and Special Education Data

Districts, Colleges, and Ed Tech Vendors

Public school districts and most colleges and universities fall under the Family Educational Rights and Privacy Act (FERPA) because they take funding through U.S. Department of Education programs. Private elementary and secondary schools usually don’t, which puts them outside it. Ed tech companies and records vendors don’t become covered institutions by holding student data either.

A school can share records with one under FERPA’s school official exception only where the vendor does work the school would otherwise handle itself, stays under the school’s direct control over how those records are used and kept, and doesn’t pass them along. The obligation stays with the schools and districts that hired them.

Retention Comes From State Schedules

FERPA sets no minimum retention period, and the Department of Education says so plainly. What it does prohibit is destroying education records while a request to inspect them is outstanding.

Special education files follow a different logic: agencies must tell parents when the information is no longer needed and destroy it on request, though a permanent record of name, address, phone number, grades, attendance, classes attended, and grade level completed may be kept without a time limit. The real numbers come from state schedules, and our record retention guidelines point to each one.

Credit Nobody Is Watching

The FTC has described a child’s identity as a blank slate, usable over a long stretch because parents typically have no reason to check a child’s credit. The theft often comes to light only when that child applies for a job or a car loan.

Blueprints, Contracts, and Trade Secrets

Builders, Engineers, and Manufacturers

Construction companies, architecture and engineering firms, manufacturers, and their suppliers hold a category many compliance frameworks ignore: files with no personal information in them and enormous commercial value. Formulations, tooling specifications, as-builts, and supplier pricing all qualify.

Files That Outlive the Project

Construction statutes of repose, the deadlines after which nobody can sue you over the work, run from four years to 20 depending on the state, and New York and Vermont have none at all. That’s why drawings and specifications are commonly held permanently — they outlast the workstations that made them, the formats they were saved in, and probably the vendor storing them. Protection applied to the document survives all three moves, while a control tied to one machine doesn’t.

Losing the Asset and Its Legal Status

Under the Defend Trade Secrets Act, information qualifies as a trade secret only where the owner has taken reasonable measures to keep it secret. That’s part of the definition rather than a factor in damages. Guard it poorly and it stops being a trade secret in the eyes of a court.

Courts have held companies to this standard. A federal court in New York dismissed a 2025 trade secret claim from a company that used multi-factor logins and view-only files but never told the contractor the material was confidential. Verizon’s 2026 Data Breach Investigations Report showed internal business data turned up in about 80% of manufacturing breaches. A stolen customer list costs you customers. A stolen formulation can potentially cost you the legal right to claim it.

Credentials, Backups, and Forgotten Archives

These usually have no owner, which is why they go unprotected:

  • Password files and encryption keys. The shared login spreadsheet, the credentials in a configuration file, the recovery keys somebody saved and forgot. HHS advises keeping decryption tools on a different device from the data they open. An encrypted archive stored beside its own key is an unencrypted archive with extra steps. Worth pairing with a look at your password practices.
  • Backup sets and legacy media. A backup inherits the sensitivity of everything inside it and almost none of the attention. Tapes and microfilm written a decade ago predate whatever encryption policy you have now, and they’re judged by today’s rules. Tape and microfilm storage is a specialty service for that reason.
  • Working copies during a scanning project. Digitizing a box multiplies it. The same records briefly sit readable on the scanner, the prep station, a transfer drive, and the destination system, so settle encrypted transfer and documented chain of custody before the project starts.

Household and Home Office Paperwork

Sole proprietors, home offices, and households hold versions of nearly every category above, usually in a filing cabinet and a downloads folder rather than a records program. The short list is tax returns and the receipts behind them, mortgage and closing documents, insurance policies, wills, and the scans of birth certificates, passports, and Social Security cards people make once and then forget. 

Retention is simpler here: the same IRS windows apply, property records stay until you sell and the clock runs out, and vital records are permanent.

A household breach doesn’t produce a regulatory filing. It produces someone opening credit in your name, filing a return before you do, or draining an account. The FTC took more than 1.1 million identity theft reports through IdentityTheft.gov in 2024. Our guide to personal records retention covers what’s safe to let go of.

Where to Start This Week

  • Inventory before you encrypt. Run those initial three questions across your record categories. (Who wants it? How long do you need to hold it? What happens if it gets out?) The answers rank the list and surface files nobody had claimed.
  • Encrypt at creation, and keep the keys elsewhere. NIST’s media sanitization guidance accepts destroying the key instead of the drive as a legitimate way to purge data, but only where nothing sensitive was ever written to that drive unencrypted. Turning encryption on at day one gives you that option years later. Store recovery credentials somewhere other than the backup set holding the files they open.
  • Tie retention to disposal. Records held past their required period are pure liability. Build the schedule into the system, then close the loop with certified destruction when the clock runs out.
  • Ask vendors about key custody. Who holds the keys? Is the encryption running in a tested and approved cryptographic module, and can you see the certificate? What happens to your data when the contract ends? A provider still citing FIPS 140-2 for a new deployment deserves a follow-up, since those certificates move to the validation program’s historical list on September 22, 2026.
  • Remember what encryption can’t reach. Paper holding any of the categories above are outside every protection on this page until it’s digitized or moved somewhere with real physical security. Our guide to encrypting data for compliance and security maps laws to obligations.

How Record Nations Can Help

Record Nations connects you with local scanning and storage companies chosen for the certifications, security controls, and industry experience your records call for. Instead of calling six vendors and comparing six answers about key management and custody, you describe the project once and hear from providers who have done it all before.

We’re an i-SIGMA member, and we work closely with the association to ensure providers in our network meet PRISM Privacy+ specifications for information management and NAID AAA standards for secure destruction. Many also hold ISO 9001 registration for quality management. Those expectations don’t change with the ZIP code — the same standards apply to document scanning in Fort Collins, CO, or records storage in Knoxville, TN.

Providers can convert paper through a document scanning project, hold hard copy in secure offsite storage with indexed retrieval and documented custody, run active files in a document management platform with permissions and audit trails, or move them to encrypted cloud storage where retention rules travel with the documents.

To get started, fill out our form or call us at (866) 385-3706. We’ll scope the project and help find competitive quotes from providers who can show how they’d protect every file type here.




Contact Us For Your Free Quote

We're here to help you explore your options and find the perfect service for your needs.