I love the phrase “data is encrypted at rest.” Having worked with a lot of medical data, the rules are simple: Encrypt at rest Rest is when the database is off Never turn off the database