Lost or Stolen Device Playbook for Clinics and Care Facilities

It happens in every organization. A laptop is left in a car, a tablet disappears from a supply room, a phone with work email goes missing at a conference. The device itself costs a few hundred dollars. The question that matters is what was on it.

With a plan, a lost device becomes a routine incident. Without one, it can become a reportable breach and a long, stressful investigation.

Why Encryption Changes Everything

Under the HIPAA Breach Notification Rule, a breach of unsecured PHI generally requires notification. HHS guidance describes PHI as secured when it is encrypted in a way that meets recognized standards, or destroyed. If a lost laptop has full-disk encryption properly enabled and the key was not compromised, the event may not qualify as a breach of unsecured PHI. That single control can spare you notification to residents, HHS and potentially the media.

So the first and best preparation is to encrypt every laptop, tablet and phone that could hold PHI, and to be able to prove that encryption was active at the time of loss.

Before Anything Is Lost

Keep an inventory of devices, with the assigned user and serial number

Enable full-disk encryption on laptops, using tools built into the operating system or managed through your IT provider

Require screen locks and PINs on phones and tablets

Use mobile device management software that can locate, lock or wipe devices remotely

Keep PHI off removable drives where possible, and encrypt them if they must be used

Train staff to report loss immediately, without fear of blame

The First Hour

Step 1: Report immediately

The employee should tell a supervisor and IT as soon as they notice. Delay reduces options.

Step 2: Lock and locate

If management tools are in place, attempt to locate the device, lock it and, where warranted, trigger a remote wipe. Note that wiping removes your ability to examine what was on the device, so record the decision.

Step 3: Disable access

Revoke the user's sessions, reset passwords and remove the device from trusted lists. Review recent sign-in activity for the account for anything unusual.

Step 4: Gather facts

Document what happened, including when and where the device was last seen, whether it was police-reportable theft, and who had access.

Step 5: Report theft to police

For theft, file a police report and keep the report number. It supports your documentation.

Determine What Was on the Device

IT should establish:

Whether the device was encrypted, with evidence such as management console records

What data may have been stored locally, such as downloaded files, email caches or spreadsheets

Whether credentials stored on the device could be used elsewhere

Whether the lock was enabled and how strong

Do not rely on memory. Management logs and backups help reconstruct the answer.

Perform and Document a Risk Assessment

If PHI was potentially exposed and not secured, the Breach Notification Rule requires you to assess the probability that PHI was compromised, considering the nature and extent of the information, who may have accessed it, whether it was actually acquired or viewed, and how much risk has been mitigated. Document the analysis, and consult your compliance officer and attorney about notification. Timelines in the rule run from discovery, so move quickly.

Special Situations

Personal phones used for work email: Have a policy that requires enrollment in management or a secure container, and allows work data to be wiped.

Paper charts and printouts: Include them in your response plans. They cannot be encrypted.

USB drives: Treat as high risk. Consider disabling USB storage on most computers.

Learn From Each Event

After each loss, ask what made it possible. Were devices left in cars? Was encryption enabled? Did the employee report quickly? Adjust policy, training or tooling accordingly.

Preparing With UnityCare IT

UnityCare IT helps healthcare organizations deploy encryption and device management, and build clear response procedures. If you are unsure whether your laptops and tablets are encrypted today, we can verify and fix gaps.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172