It happens in every organization. A laptop is left in a car, a tablet disappears from a supply room, a phone with work email goes missing at a conference. The device itself costs a few hundred dollars. The question that matters is what was on it.
With a plan, a lost device becomes a routine incident. Without one, it can become a reportable breach and a long, stressful investigation.
Under the HIPAA Breach Notification Rule, a breach of unsecured PHI generally requires notification. HHS guidance describes PHI as secured when it is encrypted in a way that meets recognized standards, or destroyed. If a lost laptop has full-disk encryption properly enabled and the key was not compromised, the event may not qualify as a breach of unsecured PHI. That single control can spare you notification to residents, HHS and potentially the media.
So the first and best preparation is to encrypt every laptop, tablet and phone that could hold PHI, and to be able to prove that encryption was active at the time of loss.
Keep an inventory of devices, with the assigned user and serial number
Enable full-disk encryption on laptops, using tools built into the operating system or managed through your IT provider
Require screen locks and PINs on phones and tablets
Use mobile device management software that can locate, lock or wipe devices remotely
Keep PHI off removable drives where possible, and encrypt them if they must be used
Train staff to report loss immediately, without fear of blame
The employee should tell a supervisor and IT as soon as they notice. Delay reduces options.
If management tools are in place, attempt to locate the device, lock it and, where warranted, trigger a remote wipe. Note that wiping removes your ability to examine what was on the device, so record the decision.
Revoke the user's sessions, reset passwords and remove the device from trusted lists. Review recent sign-in activity for the account for anything unusual.
Document what happened, including when and where the device was last seen, whether it was police-reportable theft, and who had access.
For theft, file a police report and keep the report number. It supports your documentation.
IT should establish:
Whether the device was encrypted, with evidence such as management console records
What data may have been stored locally, such as downloaded files, email caches or spreadsheets
Whether credentials stored on the device could be used elsewhere
Whether the lock was enabled and how strong
Do not rely on memory. Management logs and backups help reconstruct the answer.
If PHI was potentially exposed and not secured, the Breach Notification Rule requires you to assess the probability that PHI was compromised, considering the nature and extent of the information, who may have accessed it, whether it was actually acquired or viewed, and how much risk has been mitigated. Document the analysis, and consult your compliance officer and attorney about notification. Timelines in the rule run from discovery, so move quickly.
Personal phones used for work email: Have a policy that requires enrollment in management or a secure container, and allows work data to be wiped.
Paper charts and printouts: Include them in your response plans. They cannot be encrypted.
USB drives: Treat as high risk. Consider disabling USB storage on most computers.
After each loss, ask what made it possible. Were devices left in cars? Was encryption enabled? Did the employee report quickly? Adjust policy, training or tooling accordingly.
UnityCare IT helps healthcare organizations deploy encryption and device management, and build clear response procedures. If you are unsure whether your laptops and tablets are encrypted today, we can verify and fix gaps.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172