If you are storing credit card information on your site, it is highly recommended that the web.config EncryptKey be changed at least every 90 days. That must be done through this page of the admin site, so that the software can update encrypted records with the new key information. EncryptKeys should be at least 10 characters long, and should not contain special characters (letters & numbers only).
NOTE: Before this change can be made, the .NET user account must be given read/write/modify access to the folder the web.config file resides in. Contact your host for assistance with making that change.
This can take some time, do not stop the process once it has begun!