Lost or Stolen Device: A Step-by-Step Response for Care Teams

A nurse realizes her work phone is not in her bag. A therapist's laptop is gone from a parked car. A tablet from a medication cart cannot be found at shift change. These events happen in every healthcare organization eventually, and how quickly you respond determines whether the loss is a minor annoyance or a reportable breach.

This walkthrough covers what to do in the first hours and days, and what to set up beforehand so the response is easy.

Step 1: Report Immediately

Staff should know that a missing device must be reported right away, to a supervisor and to IT, by phone if possible. Do not wait to see if it turns up. The faster IT knows, the more options exist.

Make sure reporting is blame-free. People delay when they fear punishment, and delay is the biggest risk.

Step 2: Gather Key Facts

The person taking the report should record:

Name, role and contact information of the reporter

Device type, make, serial number or asset tag

When and where it was last seen

Circumstances, such as a vehicle break-in or left in a public place

What the device could access: email, EHR, shared files, saved passwords

Whether resident information was stored locally, such as downloaded files or photos

Whether the device was locked, password protected and encrypted

These details drive the decisions that follow.

Step 3: Secure the Accounts and the Device

IT should act quickly:

Disable or reset the user's passwords and sign out active sessions

Revoke tokens and saved sessions for email and cloud applications

Use mobile device management to lock the device, show a message or remotely wipe it, if available and appropriate

Block the device from the network and from corporate email

Track the device's location if the tool supports it, but do not send staff to retrieve it themselves

If the device was fully encrypted and protected by a strong passcode, the risk of data exposure is much lower. This is why encryption matters so much.

Step 4: Assess Whether PHI Was at Risk

Under the HIPAA Breach Notification Rule, a loss of unsecured protected health information is presumed to be a breach unless a documented risk assessment shows a low probability that the information has been compromised. Factors considered include:

The nature and extent of the PHI involved

Who might have accessed it

Whether the information was actually acquired or viewed

The extent to which risk has been mitigated

HHS guidance identifies encryption consistent with its standards as a way to render PHI secured, which generally means the safe harbor from breach notification may apply if the device was properly encrypted and the key was not compromised. Your compliance officer or counsel should make this determination and document it.

Step 5: Report to Law Enforcement When Appropriate

Theft should be reported to local police, and a report number is useful for insurance and documentation. If the device was lost rather than stolen, document search efforts.

Step 6: Notify Those Who Must Be Notified

If the risk assessment concludes a breach occurred, HIPAA sets notification requirements for affected individuals, HHS and, in some cases, the media. Timelines run from discovery of the breach, so keep careful records of when you learned about it. Oklahoma, Texas and Arkansas also have state breach notification laws, and your cyber insurance policy may require prompt notice. Involve your counsel early.

Step 7: Learn and Improve

After the dust settles, hold a short review:

Was the device encrypted? If not, why?

Did staff know how to report it?

How fast did IT respond?

Could the data have been kept off the device altogether?

Does policy need to change?

Update your inventory and, if needed, your risk analysis.

Prevention Before It Happens

Encrypt every laptop, tablet and phone that could hold PHI

Require screen locks and strong passcodes or biometrics

Enroll devices in a management system that can lock and wipe remotely

Keep a current asset inventory with serial numbers and assigned users

Avoid storing resident information locally; use secured applications instead

Train staff not to leave devices in vehicles or unattended areas

Set a clear policy for personal devices used for work

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations deploy device encryption, remote wipe capabilities and clear reporting procedures. If you are not sure whether your devices are encrypted, we can check and close the gaps.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172