Of course! And I am certain that she and colleagues always used GPG or similar when e-mailing between her personal mail server and the State Department's official mail server. Because it goes without saying they would do so, otherwise those e-mails carrying untold sensitive information would have been routed in the clear. And that obviously never happened.
What I've gathered from news reports is that her mail server was accepting SSL connections, with a certificate that was probably strong enough at the time it was installed, but that was insufficiently strong for the brute-force attacks available today. Aside from that, it wasn't too bad - especially given the physical security of her residence (i.e., Secret Service).
Note that the State Department's score on the FISMA report was significantly worse than that of the infamously hacked Office of Personnel Management, so maybe Ms. Clinton was on to something. https://www.whitehouse.gov/sites/default/files/omb/assets/eg...