Lost or Stolen Device? A First-Hour Response Walkthrough

It is 7:15 on a Monday morning. A case manager realizes her laptop is no longer in the back seat of her car. Or a nurse cannot find the work phone she used on the weekend. Lost and stolen devices are among the most common events that lead to HIPAA breach reviews, and the first hour often decides how serious the outcome will be.

This walkthrough breaks that first hour into steps that anyone in leadership can follow. Adapt it to your organization, and keep a copy where it can be found without network access.

Minutes 0 to 10: Report and gather facts

The employee should call the IT contact or helpdesk immediately, rather than emailing. Ask for:

What device it was, and its asset tag or serial number if available

When and where it was last seen

Whether it was locked, and whether a screen passcode was in place

What the device could access, such as email, EHR, shared drives or saved passwords

Whether any paper records or resident lists were with it

Write down the time of the report. Do not criticize the employee. People who fear blame wait to report, and waiting makes everything worse.

Minutes 10 to 30: Contain access

Disable or revoke

Have IT reset the user's passwords, revoke active sessions and disable sign-in from that device. If the user had MFA, review registered methods and remove the lost device if it was one of them.

Remote lock or wipe

If the device is enrolled in a management tool, send a lock command, and if it is clear that recovery is unlikely, a remote wipe. Be aware that a wipe only works if the device connects to the internet, and it may destroy evidence you want for your analysis, so decide based on guidance from your IT partner.

Check other access

Look for saved browser passwords, VPN profiles, and access tokens for cloud applications. Revoke those as well.

Minutes 30 to 45: Assess what was exposed

The key question for HIPAA is whether unsecured protected health information was compromised. Several facts shape the answer:

Was the drive encrypted? Properly encrypted devices that are protected by a strong sign-in generally fall under the safe harbor described in HHS guidance, because the data is considered secured

What data was stored locally, versus accessed through cloud systems?

How many residents or patients are involved, and what types of information, such as names, diagnoses, social security numbers or insurance details?

Is there evidence the device was accessed after it went missing? Sign-in logs and device management records can help

If you cannot show that the device was encrypted, treat it as a potential breach and move to a formal risk assessment.

Minutes 45 to 60: Notify and document

Internal notifications

Inform your privacy officer, security officer, administrator and, as your plan requires, your cyber insurer and legal counsel. Many insurance policies require prompt notice.

Police report

For a theft, file a report with local law enforcement and keep the report number. It can be useful for insurance and for showing diligence.

Start an incident record

Capture the timeline, the facts above, who was notified, and every action taken. The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than sixty days after discovery of a breach, and to notify HHS as well. For smaller breaches, reporting to HHS can be done after the end of the calendar year, but the clock for individuals still applies. Your counsel can confirm the details for your situation.

Prevent the next one

Encrypt every laptop and phone that can touch protected information

Enroll devices in a management tool that supports remote lock and wipe

Require screen locks with short timeouts

Keep resident data in controlled systems, not on local desktops or downloads folders

Maintain an up-to-date asset inventory so you know exactly what is missing

Train staff to never leave devices visible in vehicles

Getting ready before it happens

The best time to build this checklist is before a laptop goes missing. UnityCare IT helps healthcare organizations set up device encryption, mobile device management and incident response procedures. If you are not sure whether your laptops are encrypted today, we can check quickly.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172