Bert,
Even those with a server have PHI on their workstations. Consider the following:
* Users who create Office documents and store them in their My Documents folder. Even with Folder Redirection turned on, the client computer keeps a local copy of the user's documents in the user's profile. This is how users can take their documents "offline" (think people that have laptops and travel a lot). Windows even provides nifty configurations for things like Slow Link Detection for those users who are connecting to the network via VPN, dial-up, or branch cache.
* Outlook *.pst file is stored in the user's local profile.
* Browser cache which may contain cookies with saved passwords to medical websites or other valuable information.
Users of Chrome were once very vulnerable to this problem. It simply isn't feasible to enforce the idea that no client will have PHI.
Out of all the encryption methods mentioned thus far, Bitlocker would be the one I would go with. The ability to centrally manage its deployment alone is worth it.
JamesNT