Here's what I love the most about this: If you have a full-disk encrypted Windows laptop, which is fully powered down (or hybernated), and the laptop contains PHI, _and_ you lose the laptop, then you probably do _not_ have to report it as a data breach.


But with this revelation, if you have an affected SSD, and you are running Windows, then losing such a laptop may now be a reportable event.

