encrypted at rest - one drive for business / Google Apps for business
- 
 FYI, if you're using Bitlocker, you must disable sleep/hibernation for it to truly be doing it's job. Otherwise the boottime ask for the password is bypassed because it's stored in memory. This means a full power on and power off when moving around. Just and FYI. 
- 
 @scottalanmiller said If an encrypted laptop was stolen loaded with patient data, you could still be in the same HIPAA predicament depending on the judge and expert witness. I am under the impression that OCR considers FDE as a non offense. I mean, the breach happened, but there would be no penalty as the data is potentially inaccessible. 

