A nurse realizes her work phone is not in her bag. A physician's laptop is gone from a car. A tablet vanishes from a shared cart. Lost and stolen devices are among the most common causes of reported healthcare data incidents, and most of them are preventable, or at least manageable, with the right preparation.
Here is a response sequence you can adapt to your own organization.
Staff should know that the right response to a missing device is to tell someone right away, without worrying about blame. Provide a single phone number. The sooner IT knows, the more options exist.
Collect basic facts:
Who lost it, and what device it is, including serial number or asset tag
When and where it was last seen
Whether it was locked, and whether it was in a bag, car or public place
What the person believes was on the device or accessible through it
For suspected theft, advise the employee to file a police report and keep the report number for your records.
While the device may be locked, assume it could be compromised until proven otherwise.
Sign the user out of all sessions and revoke tokens
Reset the person's passwords
Revoke or reset multi-factor authentication methods tied to that device
Review recent sign-in activity for signs of misuse
Disable any remote access connections or certificates stored on the device
If you manage devices with mobile device management or endpoint management tools, you can often:
Locate the device
Display a message or lock it remotely
Erase it remotely
Wiping is the safest option when the device is likely gone for good, but consider whether you need to preserve evidence or whether the device may still be recoverable. Make this decision quickly and record who approved it.
This is the key question for HIPAA. Ask:
Was the device encrypted? If properly encrypted and the key was not exposed, the data is generally considered secured, and breach notification typically does not apply.
Did the device store resident information locally, or only access it through secure applications?
Did it contain exported reports, photos, emails or attachments?
How many individuals and what types of information are involved?
Your IT provider can check encryption status from management logs and what was synced to the device.
If unsecured PHI may have been exposed, perform the four-factor assessment required by the Breach Notification Rule: the nature of the information, who might have obtained it, whether it was actually accessed and how well the risk was mitigated. Record your reasoning and conclusion, even if you decide it is not a reportable breach.
If it is a breach, follow your notification procedures. The timeline begins at discovery.
Replace the device and restore the user's access
Update your inventory
Notify your cyber insurer if the policy requires it
Add the incident to your log
Review whether staff training or policies need to change
Encrypt all laptops, tablets and phones, and verify it through a management console
Require screen locks and PINs
Enroll devices in management software that supports remote lock and wipe
Limit local storage of PHI, using secure cloud applications instead
Keep a current inventory so you know exactly what was lost
Remind staff not to leave devices in vehicles or unattended areas
Use separate work profiles on personal phones if you allow bring-your-own-device
If staff use personal phones for work email or messaging, your policy should explain that the organization can remove work data remotely, and the setup should enforce a passcode and encryption. Without that, a lost personal phone can be a serious exposure.
A short tabletop discussion, such as "A nurse's phone is missing. What do we do in the next hour?", can reveal gaps. UnityCare IT can help set up device management and encryption verification for healthcare teams, and build a response checklist that fits your facility.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172