Blog

Hardware Encryption

The MD Anderson Breach: What Three Unencrypted Devices Cost a Cancer Center

A stolen laptop. Two lost USB drives. 33,500 patient records. A $4.3 million fine. And a warning the organization had already given itself years earlier. Between 2012 and 2013, the University of Texas MD Anderson Cancer Center reported three separate data breaches to the U.S. Department of Health and Human Services. Each one involved an unencrypted portable device. Each one was preventable. And together, they became one of the most cited HIPAA enforcement cases in healthcare data security history.   What happened The first incident occurred in April 2012, when a laptop was stolen from the home of an employee who had been working remotely. The laptop had been purchased

Read More »
Data Breach

When Hospital Hard Drives End Up at Auction: The Hokkaido Data Breach

A waste disposal company. A batch of unwiped hard drives. Up to 510,000 patient records were exposed. In June 2026, Japan’s National Hospital Organization disclosed that hard drives from two hospitals in Hokkaido had been listed and sold on online auction sites. The drives contained personal information belonging to patients and staff at the Hokkaido Medical Center and the Hokkaido Cancer Center, including names, addresses, dates of birth, and medical diagnoses. The breach came to light after someone who purchased a hard drive at an online auction site contacted the Hokkaido Medical Center to report that the device appeared to contain the hospital’s patient data. The hospital launched an investigation

Read More »
Hardware Encryption

Hardware Encryption. Why It Holds When Software Cannot.

When a device leaves your hands, the question is not whether you had encryption. It is whether the encryption stays with the data. Picture this: your laptop goes missing. Maybe it was left somewhere. Maybe it was taken. Either way, someone now has the device and everything on it. What happens next depends entirely on where your encryption lives.   Software encryption and its limits Software encryption protects data through the operating system. It runs on the host, depends on the OS being present and intact, and sits above the hardware. If the OS is bypassed or the drive is removed and placed in another machine, the protection software encryption

Read More »
Storage Security

Passwords Lock the Door. Encryption Locks the Data.

A login password keeps people out of your system. Encryption keeps them out of your data. Every day, most people unlock their phone without thinking twice. Face ID, fingerprint, PIN – It is instinctive because personal information is on the line. But when was the last time anyone thought about the SSD inside their laptop? That is where the emails, documents, client files, and backups actually live. And in most setups, that drive has no protection of its own.   A password is not the same as encryption A login password keeps unauthorized users out of your operating system. It is the front door. But if someone removes the drive

Read More »
Hardware Encryption

How Opal Lock Manages Self-Encrypting Drives Across Their Full Lifecycle

  From first setup to final erase, here is what managing a self-encrypting drive actually looks like. Most organizations assume their drive security is working until something tests it. A device goes missing. A drive gets pulled from a machine. A system gets wiped. These are the moments when software-level security fails and hardware encryption holds. Opal Lock by Fidelity Height is a Windows application that activates and manages the encryption already built into compatible TCG Opal and Pyrite self-encrypting drives. It does not add encryption to a standard drive. It gives users and IT teams control over the encryption engine inside a compatible drive, across the full drive lifecycle.

Read More »
Hardware Encryption

Opal vs BitLocker: What Is the Difference and Which One Do You Need?

  Both encrypt your drive. They do it at different layers, with different consequences when something goes wrong. BitLocker is the encryption tool most Windows users know. It is built into Windows, it is free, and it works without any additional hardware. For many teams, it is the default choice simply because it is already there. TCG Opal is something different. It is a hardware standard built into the drive itself, and it operates independently of the operating system and everything running on top of it. The two are often treated as alternatives. In some scenarios they are. In others, they are solving different parts of the same problem. What

Read More »
Hardware Encryption

Hardware Encryption vs Software Encryption: What Actually Happens When Something Goes Wrong

The difference between the two is not just technical. It shows up in the moments that matter most. Most teams assume their encryption is working until something tests it. A device goes missing. A drive gets pulled from a machine. A system gets wiped before anyone thought to check what was on it. These are the moments where the difference between hardware encryption and software encryption becomes real. Not in a spec sheet comparison, but in what actually happens to the data. What follows is a look at three common scenarios and what each encryption approach does, or fails to do, when they occur.   Scenario 1: A laptop goes

Read More »
Product Education

What Is an Opal SSD and Why Does It Need to Be Activated?

Most people who own one have never turned it on. Browse any laptop spec sheet or SSD listing today and you will likely see terms like “self-encrypting” or “Opal-compliant.” They appear often. What they actually mean, and what needs to happen before they protect anything, is less often explained. If you already own a modern laptop or external SSD, there is a reasonable chance the drive inside it was built to encrypt your data at the hardware level. Not because you specifically chose it, but because most drives from major manufacturers ship with a built-in encryption engine. The problem is that most people, and most IT teams, have never turned

Read More »
Hardware Encryption

Hardware-Based Encryption: The Definitive Standard for Data Protection

Why the encryption layer matters as much as the encryption itself. Picture this: a laptop goes missing. It happens more often than most teams want to admit, and when it does, the question is not whether the device is gone. The question is whether the data on it is protected. The answer depends entirely on where the encryption lives.   Why hardware-based encryption matters Software encryption has its place, but it has a structural limitation that becomes critical the moment a device leaves its owner’s hands. When a drive is removed from a machine and connected elsewhere, the operating system that software encryption depends on is no longer in the

Read More »
Data Sanitization

How to Manage Multiple Self-Encrypting Drives Without Losing Control

What IT teams and MSPs need to know about running multi-drive SED workflows with Opal Lock Premium. Managing one self-encrypting drive is straightforward. Managing several across a single machine, a team, or a fleet is a different problem entirely. Each drive needs to be set up, locked, unlocked, audited, and eventually erased. Done one drive at a time, that process becomes repetitive, time-consuming, and harder to keep consistent. This is the problem Opal Lock Premium is built to address. This post covers what multi-drive management in Opal Lock actually involves, which operations can be run across multiple drives at once, and what IT teams and MSPs should know before deploying

Read More »
Product Features

Pre-Boot Authentication Explained: What It Is, How It Works, and Why It Matters

A practical guide for IT teams evaluating whether pre-boot authentication belongs in their drive security workflow. When a drive is locked, the question is not just whether the data is encrypted. The question is when and where authentication happens. Software-level login screens run after the operating system loads, which means the OS itself has already started before any credentials are checked. Pre-boot authentication works differently. It requires a user to authenticate before the operating system loads at all. This distinction matters more than it might seem, and it is the reason pre-boot authentication is a specific, separately licensed capability in Opal Lock Standard and Premium.   What Pre-Boot Authentication Actually

Read More »
Product Features

Opal Lock Editions Compared: Which One Is Right for Your Setup?

  USB, Standard, Premium, and Lite – what each edition actually covers and how to choose. Opal Lock comes in four editions. Each one is built around a specific type of drive environment, and the right choice depends on what drives you are managing, how many of them you have, and what you need to do with them. This post breaks down each edition using the features and scope listed on the Opal Lock shop page, so you can make the decision without opening multiple tabs.   The Short Answer Standard fits most teams. USB is for portable external drives only. Premium is for IT teams managing multiple drives per

Read More »