Here is an idea that I think would help.
Dial back HIPAA just a little bit.
Everyone still needs to have their health information kept private, but we have gone way overboard with this. I've seen the facility I work in pass on ridiculous HIPAA compliance costs to payers.
Instead of the encryption, and multi-layer authentication to treat health data as though it is Top Secret, treat it as Confidential instead. It would still be private without nearly the cost.