Back to blog
GDPRPublished on August 24, 20268 min read

Health Data: Securing the Devices That Access It

HDS and GDPR context: which endpoint-side measures to apply to protect the health data your teams handle, using Microsoft Intune across the fleet.

Handling health data demands a high level of rigor, and for good reason: it is among the most sensitive information an organization can process. While hosting itself relies on a certified provider, security never stops at the datacenter. The laptops, desktops and phones that access the data are a major exposure surface, often overlooked in risk analyses. GDPR requires technical measures proportionate to the risk, and a single poorly protected device is enough to trigger a breach of health data with heavy consequences.

Health data is sensitive data under Article 9 of the GDPR: it benefits from reinforced protection and its processing is in principle prohibited except in tightly framed cases. Encrypting central storage at the host is therefore not enough; you must control every device that reads, enters, downloads or exports this information, wherever it is. This is exactly what centralized endpoint management enables.

The concrete risks on the endpoint side

The most frequent incidents come not from sophisticated attacks but from basic hygiene failures on the endpoints. A practice, a lab or a clinic is rarely the target of a dedicated operation; far more often it falls victim to a mundane chain of oversights.

  • Theft or loss of an unencrypted laptop exposing complete patient records.
  • An out-of-date device exploited by malware to quietly exfiltrate data.
  • A session left open, with no automatic lock, on a shared reception machine.
  • Copying data to a USB stick or a completely unmanaged personal cloud.
  • An outdated app serving as an entry point for ransomware that paralyzes operations.
Full-disk encryption is the first barrier if a device is stolen.

The endpoint measures to apply

Most of these protections are configured in Microsoft Intune and verified continuously through device compliance policies. The value of Intune is that it turns good intentions into settings genuinely applied and checked on each machine.

  • Full-disk encryption (BitLocker on Windows, FileVault on macOS) on every device.
  • Automatic lock after inactivity and a strong passcode enforced by policy.
  • Active antivirus or EDR and up-to-date systems, checked by a compliance policy.
  • Removable media control and data-loss prevention (DLP).
  • Conditional Access: only compliant devices reach health applications.

Encryption and locking: the non-negotiable baseline

Disk encryption protects data if the device is stolen or lost, the most common situation. With Intune, you enforce BitLocker and escrow the keys centrally, so you never lose access to a machine. Automatic locking after a few minutes of inactivity prevents a session from staying open on a reception desk anyone could browse.

Compliance and Conditional Access: a coherent chain

These measures form a chain: Conditional Access only matters if compliance is genuinely evaluated, and encryption only protects if it is actually enabled on each machine. A compliance policy continuously verifies that encryption, antivirus and updates are in place; Conditional Access then denies access to health applications from any device that fails these criteria. Hence the importance of centralized verification rather than one-off checks.

Traceability and data minimization

GDPR expects measures to be documented and their enforcement demonstrable. You need to know which devices access the data, whether they are encrypted and up to date, and to limit access to the people who genuinely need it, following the minimization principle. A front desk does not necessarily need the same data access as a practitioner.

This traceability is also valuable during a regulator audit or after an incident: being able to prove that the devices involved were encrypted and up to date radically changes the legal scope of any breach. A breach touching health data on an encrypted, compliant device does not carry the same consequences as a leak from an unprotected one.

Documenting the real state of devices makes any regulator audit easier.

Don't forget mobiles and BYOD

Smartphones and tablets that open a mailbox or a health line-of-business app are too often left out of the security scope. Yet they handle the same sensitive data as computers, with an even higher risk of loss or theft given their mobility. They must therefore fall under the same management logic, including when they are personal devices used in BYOD.

  • Separate professional data from personal data on BYOD devices.
  • Require a passcode and device encryption before any access to the data.
  • Be able to remotely wipe only the professional data if a device is lost or stolen.
  • Block access from non-compliant, jailbroken or out-of-date devices.

Common mistakes to avoid

Some approximations create a false sense of security and expose the organization the day of an audit or an incident.

  • Believing that HDS hosting is enough and neglecting the endpoints entirely.
  • Enabling encryption without verifying that it is actually applied on each device.
  • Letting third-party apps drift toward vulnerable versions for lack of tracking.
  • Forgetting mobile and personal devices in the security policy.

A concrete compliance example

Take a medical imaging practice of twenty machines whose practitioners open a patient record hosted at a certified provider. Before any intervention, the inventory reveals that six laptops are not encrypted and that three PDF readers still run a version for which a CVE has been published. Within a few days, BitLocker is enforced through Intune across the whole fleet, the recovery keys are escrowed centrally, and a compliance policy now requires encryption, active antivirus and an up-to-date system on every device.

  1. 1Inventory the devices that actually access health data, mobiles included.
  2. 2Enforce disk encryption and escrow the keys centrally.
  3. 3Verify compliance continuously before granting any access to the line-of-business app.
  4. 4Fix vulnerable apps only on the affected machines, leaving the others untouched.
  5. 5Archive a dated record proving the effective protection of every device on the fleet.

Once this chain is in place, Conditional Access denies the line-of-business app to any non-compliant device, while the PDF-reader fixes are pushed solely to the machines on a vulnerable version. The practice then has, at any moment, a dated record showing that every device accessing the data is encrypted and current. This example shows that endpoint compliance is not an endless project: it rests on a few well-targeted measures, applied uniformly and verifiable at will. The real difficulty is never technical, it is visibility, because without a reliable inventory you cannot tell which machines still need attention.

How AuPoint helps

AuPoint lets healthcare SMBs and MSSPs deploy these protections without PowerShell expertise: encryption, compliance, Conditional Access, a complete software inventory and detection of vulnerable apps and their associated CVEs on every device, with patch deployment through Intune. You get a clear view of the fleet's real state and the dated reports needed to demonstrate due diligence, alongside certified hosting.

Frequently asked questions

Is certified hosting enough to be compliant?

No. Certification covers hosting, but GDPR applies to the whole processing chain, including the devices that access the data. A stolen unencrypted laptop exposes records regardless of the datacenter's security level.

Is BYOD compatible with health data?

Yes, provided you isolate professional data, enforce encryption and a passcode, and can remotely wipe the professional portion. Intune enables this separation without touching the user's personal data.

How do I prove due diligence to a regulator?

By keeping dated reports: encrypted, compliant devices, deployed software versions and restricted access. This evidence shows the measures were genuinely in place, which a written policy alone cannot establish.

Do machines that only access email need the same treatment?

Yes, as soon as they receive attachments that may contain health data. Email is a frequent exposure channel, and an unencrypted machine reading those messages carries the same risk as a direct connection to the line-of-business app. It must therefore fall within the same scope of encryption, compliance and patch tracking as every other device.

Your teams handle health data every day: make sure every device that accesses it is genuinely protected. With AuPoint, deploy encryption, compliance and Conditional Access across your whole Intune fleet, and keep the proof of your due diligence. Request a demo tailored to the healthcare sector.

Secure your tenant in 15 minutes

Free trial