It is 7:15 on a Monday morning. A case manager realizes her laptop is no longer in the back seat of her car. Or a nurse cannot find the work phone she used on the weekend. Lost and stolen devices are among the most common events that lead to HIPAA breach reviews, and the first hour often decides how serious the outcome will be.
This walkthrough breaks that first hour into steps that anyone in leadership can follow. Adapt it to your organization, and keep a copy where it can be found without network access.
The employee should call the IT contact or helpdesk immediately, rather than emailing. Ask for:
What device it was, and its asset tag or serial number if available
When and where it was last seen
Whether it was locked, and whether a screen passcode was in place
What the device could access, such as email, EHR, shared drives or saved passwords
Whether any paper records or resident lists were with it
Write down the time of the report. Do not criticize the employee. People who fear blame wait to report, and waiting makes everything worse.
Have IT reset the user's passwords, revoke active sessions and disable sign-in from that device. If the user had MFA, review registered methods and remove the lost device if it was one of them.
If the device is enrolled in a management tool, send a lock command, and if it is clear that recovery is unlikely, a remote wipe. Be aware that a wipe only works if the device connects to the internet, and it may destroy evidence you want for your analysis, so decide based on guidance from your IT partner.
Look for saved browser passwords, VPN profiles, and access tokens for cloud applications. Revoke those as well.
The key question for HIPAA is whether unsecured protected health information was compromised. Several facts shape the answer:
Was the drive encrypted? Properly encrypted devices that are protected by a strong sign-in generally fall under the safe harbor described in HHS guidance, because the data is considered secured
What data was stored locally, versus accessed through cloud systems?
How many residents or patients are involved, and what types of information, such as names, diagnoses, social security numbers or insurance details?
Is there evidence the device was accessed after it went missing? Sign-in logs and device management records can help
If you cannot show that the device was encrypted, treat it as a potential breach and move to a formal risk assessment.
Inform your privacy officer, security officer, administrator and, as your plan requires, your cyber insurer and legal counsel. Many insurance policies require prompt notice.
For a theft, file a report with local law enforcement and keep the report number. It can be useful for insurance and for showing diligence.
Capture the timeline, the facts above, who was notified, and every action taken. The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than sixty days after discovery of a breach, and to notify HHS as well. For smaller breaches, reporting to HHS can be done after the end of the calendar year, but the clock for individuals still applies. Your counsel can confirm the details for your situation.
Encrypt every laptop and phone that can touch protected information
Enroll devices in a management tool that supports remote lock and wipe
Require screen locks with short timeouts
Keep resident data in controlled systems, not on local desktops or downloads folders
Maintain an up-to-date asset inventory so you know exactly what is missing
Train staff to never leave devices visible in vehicles
The best time to build this checklist is before a laptop goes missing. UnityCare IT helps healthcare organizations set up device encryption, mobile device management and incident response procedures. If you are not sure whether your laptops are encrypted today, we can check quickly.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172