Stolen physician laptop
BitLocker-encrypted corporate laptop with offline notes yields no readable ePHI to the thief — AC-19(1) encryption in action.
AC-19(1) focuses on employing cryptographic protection — commonly full-device encryption or container/app-level encryption — for mobile devices that handle organizational information. In healthcare, lost phones with secure chat, tablets with EHR apps, and laptops with offline charts must keep ePHI unreadable to finders. Prefer hardware-backed full-disk encryption for corporate devices and managed containers/app protection for BYOD so clinical content stays encrypted independently of personal photos.
Ensure mobile devices used with ePHI employ full-device and/or container-based encryption so lost or stolen devices do not yield readable protected health information.
How this control shows up in healthcare and HIPAA-covered environments.
BitLocker-encrypted corporate laptop with offline notes yields no readable ePHI to the thief — AC-19(1) encryption in action.
Nurse’s personal phone uses an encrypted work container for clinical chat; personal camera roll stays separate and unencrypted work data is not stored in clear app sandboxes.
Supervised tablet with full-device encryption and managed EHR app meets encryption before it can open trauma-bay workflows.
HIPAA addressable encryption is frequently tested via mobile loss scenarios. Show enforced encryption compliance, not optional guidance.
How this NIST control supports HIPAA Security Rule expectations.
For BYOD it is often the practical control. Corporate-owned devices should generally use full-device encryption plus app controls.
Both address full-device or container encryption on mobile devices; implement consistently and map both to your MDM encryption baseline where your catalog includes both IDs.
Yes — wipe helps after report; encryption protects the window before wipe and cases never reported.
Related controls that commonly accompany AC-19(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.