A nurse leaves a tablet in a car. A laptop disappears from an office over a weekend. A manager loses a phone with email on it. Lost and stolen devices are among the most common causes of reported healthcare data incidents, and they are also among the most preventable. With the right preparation, a lost device can be an inconvenience instead of a breach.
Under the HIPAA Breach Notification Rule, a breach involves unsecured PHI. Guidance from HHS describes encryption consistent with recognized standards as a way to render PHI unusable, unreadable or indecipherable. If a lost laptop has full-disk encryption properly enabled and the key was not compromised, the loss generally does not trigger breach notification. Without it, you may face a full risk assessment and possible notification to residents, HHS and in some cases the media.
Encryption is not mentioned as mandatory in the Security Rule, but it is an addressable specification, and in practice it is hard to justify skipping on portable devices.
Turn on full-disk encryption for laptops, using built-in tools such as BitLocker or FileVault.
Enable encryption on phones and tablets, which is on by default on most modern devices when a passcode is set.
Use encrypted USB drives if removable media is allowed at all, or block USB storage altogether.
Store recovery keys in a secure, central location.
Set a passcode or password with automatic lock after a short period of inactivity. A device that is encrypted but sitting unlocked offers no protection.
Management tools let IT enforce settings, track devices and wipe data remotely. For phones or tablets that access email or the EHR, enrolling them in management is one of the most effective controls. If personal phones are used, consider options that manage only the work data.
Record each device, its owner, its serial number and what data it may hold. When one goes missing, you will know what was on it.
Avoid storing PHI locally. Use cloud or server storage with access controls, so a lost device holds little to lose.
Report immediately to IT and your privacy or security officer. Tell staff to report within minutes, not days.
Gather the facts: what device, when and where it was last seen, whether it was locked and whether it was encrypted.
Remotely lock or wipe the device if you have management tools. Revoke access by disabling the user's sessions and resetting passwords.
If theft is suspected, file a police report and keep the report number.
Determine what PHI and credentials the device may have held, using backups, logs and the inventory.
Confirm whether encryption was active and obtain evidence, such as management console records.
Review recent account activity for signs of misuse.
Complete the HIPAA four-factor risk assessment and document it.
Follow your notification procedures, with individual notices without unreasonable delay and no later than 60 days after discovery, plus notification to HHS and the media where required. Also check state laws and insurer notice requirements.
Train staff on simple rules:
Never leave devices unattended in vehicles or public places.
Do not store PHI on personal devices or personal cloud accounts.
Report loss immediately, without worrying about blame.
Use only approved devices and apps for resident information, including photos.
Keep records of your encryption settings, device inventory and every loss incident, including the analysis and decision. These records are valuable evidence of compliance.
UnityCare IT helps healthcare organizations deploy device encryption, mobile management and response procedures. If you are not sure whether your laptops and phones are encrypted, we can check and fix the gaps.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172