I'm wondering what other people do for this.
I have a client who needs to meet HIPAA Security Compliance. I have two things I'm wondering about.
I need to encrypt all laptops that leave this office. Some of the users swap laptops occasionally, making the Encryption Password hard to implement. Do you think it would be wise to make all laptops use the same encryption password, or maybe just an increment of the password? Like Device-1 = PassA, Device-2 = PassB?
The Doctors have Home PCs they use that VPN into the office. From my point of view, this should also be encrypted in-case they were to get stolen. We use a software though that does not store any user data locally. Do you think I should still encrypt?
Thanks for the help!