How-to Guide

How Encryption Actually Protects Your Personal Health Data

A password keeps out casual snoopers. Encryption changes what’s mathematically possible to read at all.

Password protection vs encryption — not the same thing

A password gate stops someone from opening an app without the password — but if the underlying data isn’t encrypted, anyone with server access, a breach, or a subpoena can potentially read it directly, password or not. Encryption transforms the data itself into unreadable noise without the correct key, regardless of any login screen.

What AES-256 actually means, in plain language

AES-256 is a widely used, extremely strong encryption standard — the same class used by governments and banks for sensitive data. In practical terms: without the correct key, the data is not just “hard” to read, it’s effectively impossible with any current technology. The number (256) refers to the key length, which is why it’s considered so strong.

On-device encryption vs encryption "in transit"

Many apps only encrypt data as it travels to their servers (“in transit”), then store it decrypted once it arrives — which means the company can read it, and so can anyone who breaches their systems. On-device encryption is stronger: the data is unreadable noise before it ever leaves your phone, so what reaches a server is already ciphertext, not something that gets decrypted and stored in the clear.

How MedKeep applies this

Every record and document in MedKeep is encrypted with AES-256 on your device before it’s stored or synced. Data on MedKeep’s servers is always encrypted ciphertext, never plain text — reading the content of your health records isn’t part of how the app operates.

Frequently asked questions

What is AES-256 encryption in simple terms?

A very strong, widely trusted encryption standard — the same class used by banks and governments — that makes data unreadable without the correct key, effectively impossible to break with current technology.

What’s the difference between encryption "in transit" and "on-device"?

Encryption in transit only protects data while it travels to a server — it’s often decrypted and stored in the clear once it arrives. On-device encryption means the data is unreadable before it ever leaves your phone, so a server only ever holds ciphertext.

Is password protection the same as encryption?

No. A password can restrict access to an app, but encryption protects the underlying data itself, independent of any login. The two are often used together but solve different problems.

MedKeep app icon

Try it with MedKeep — free

Your whole family's medications, vitals, visits and documents. Encrypted on your device, works offline.

Updated July 19, 2026 · 4 min read
Back to guides

Your health records,
always with you.

Free to start. Your whole family on the Family plan. Encrypted on your device, we can't read it.