A nurse realizes her work phone is not in her bag. A therapist's laptop is gone from a parked car. A tablet from a medication cart cannot be found at shift change. These events happen in every healthcare organization eventually, and how quickly you respond determines whether the loss is a minor annoyance or a reportable breach.
This walkthrough covers what to do in the first hours and days, and what to set up beforehand so the response is easy.
Staff should know that a missing device must be reported right away, to a supervisor and to IT, by phone if possible. Do not wait to see if it turns up. The faster IT knows, the more options exist.
Make sure reporting is blame-free. People delay when they fear punishment, and delay is the biggest risk.
The person taking the report should record:
Name, role and contact information of the reporter
Device type, make, serial number or asset tag
When and where it was last seen
Circumstances, such as a vehicle break-in or left in a public place
What the device could access: email, EHR, shared files, saved passwords
Whether resident information was stored locally, such as downloaded files or photos
Whether the device was locked, password protected and encrypted
These details drive the decisions that follow.
IT should act quickly:
Disable or reset the user's passwords and sign out active sessions
Revoke tokens and saved sessions for email and cloud applications
Use mobile device management to lock the device, show a message or remotely wipe it, if available and appropriate
Block the device from the network and from corporate email
Track the device's location if the tool supports it, but do not send staff to retrieve it themselves
If the device was fully encrypted and protected by a strong passcode, the risk of data exposure is much lower. This is why encryption matters so much.
Under the HIPAA Breach Notification Rule, a loss of unsecured protected health information is presumed to be a breach unless a documented risk assessment shows a low probability that the information has been compromised. Factors considered include:
The nature and extent of the PHI involved
Who might have accessed it
Whether the information was actually acquired or viewed
The extent to which risk has been mitigated
HHS guidance identifies encryption consistent with its standards as a way to render PHI secured, which generally means the safe harbor from breach notification may apply if the device was properly encrypted and the key was not compromised. Your compliance officer or counsel should make this determination and document it.
Theft should be reported to local police, and a report number is useful for insurance and documentation. If the device was lost rather than stolen, document search efforts.
If the risk assessment concludes a breach occurred, HIPAA sets notification requirements for affected individuals, HHS and, in some cases, the media. Timelines run from discovery of the breach, so keep careful records of when you learned about it. Oklahoma, Texas and Arkansas also have state breach notification laws, and your cyber insurance policy may require prompt notice. Involve your counsel early.
After the dust settles, hold a short review:
Was the device encrypted? If not, why?
Did staff know how to report it?
How fast did IT respond?
Could the data have been kept off the device altogether?
Does policy need to change?
Update your inventory and, if needed, your risk analysis.
Encrypt every laptop, tablet and phone that could hold PHI
Require screen locks and strong passcodes or biometrics
Enroll devices in a management system that can lock and wipe remotely
Keep a current asset inventory with serial numbers and assigned users
Avoid storing resident information locally; use secured applications instead
Train staff not to leave devices in vehicles or unattended areas
Set a clear policy for personal devices used for work
UnityCare IT helps healthcare organizations deploy device encryption, remote wipe capabilities and clear reporting procedures. If you are not sure whether your devices are encrypted, we can check and close the gaps.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172