Lost or Stolen Devices: Encryption Myths Versus Reality

A laptop disappears from a car. A tablet is left in a resident's room and never found. A phone with work email goes missing at the airport. Few things generate more anxiety for an administrator than a lost device that might hold resident information. Whether it becomes a reportable breach often depends on one question: was the device properly encrypted?

Here are common myths about encryption and what is true.

Myth versus reality

Myth: A password on the device means the data is encrypted. Reality: A sign-in password is not the same as encryption. Without full-disk encryption, someone can remove the drive and read its contents on another computer.

Myth: Encryption is always on by default. Reality: Many modern devices support it, but it may be off, unmanaged or unverified. Check, do not assume.

Myth: Encryption makes data unrecoverable if we forget the key. Reality: Managed encryption includes recovery keys stored securely by your IT team. Plan for that rather than avoiding encryption.

Myth: Encrypting laptops covers us. Reality: Phones, tablets, USB drives, external backup disks and even copier hard drives can hold PHI.

Myth: Encryption solves everything. Reality: Encryption protects data at rest on a lost device. It does not stop phishing, a user who is signed in when the device is taken, or malware.

Why this matters for HIPAA

The HIPAA Breach Notification Rule applies to unsecured PHI. HHS guidance describes encryption that meets recognized standards, such as those from NIST, as a way to render PHI unusable, unreadable or indecipherable to unauthorized people. If a lost device was properly encrypted and the key was not compromised, the loss generally does not trigger breach notification, though you should still document your analysis. If it was not, you must assess the situation under the Breach Notification Rule, which can mean notifying residents, HHS and in some cases the media.

The Security Rule also lists encryption as an addressable implementation specification. Addressable does not mean optional. It means you must implement it or document why an equivalent alternative is reasonable. For portable devices, encryption is widely considered the expected safeguard.

Know where PHI lives on devices

Do a quick inventory:

Laptops and desktops, including those in offices that might seem low-risk

Tablets and phones used for email, texting or charting

USB drives and external disks, including backup drives

Multifunction printers and copiers with hard drives

Cameras and phones used to photograph wounds or residents

Personal devices used under a bring-your-own-device arrangement

Turn encryption on and verify

Computers: Enable full-disk encryption using built-in tools, and store recovery keys in a managed location.

Phones and tablets: Require a passcode, which enables device encryption on current models, and manage devices through a mobile device management tool.

Removable media: Prefer encrypted drives, or avoid removable media for PHI entirely.

Verify with reports. Your IT team should be able to show that every laptop is encrypted, not just say so.

Add remote lock and wipe

Management tools can lock a missing device, display a message and erase it remotely. This only works if the device is enrolled beforehand and powers on and connects to the internet, so act quickly.

What to do when a device is lost

Report immediately. Make it easy for staff to call IT at any hour, without fear of blame.

Identify the device and its contents. What was on it? Who used it? Was it encrypted?

Lock or wipe remotely if possible, and change passwords and revoke sessions for accounts used on the device.

Notify your privacy officer so that a documented risk assessment can be done.

Check logs for sign-ins from the device after it went missing.

File a police report for theft, which can help with insurance and documentation.

Document everything, including the timeline and decisions.

Follow breach notification requirements if the analysis shows unsecured PHI was compromised, no later than 60 days after discovery, and sooner whenever possible.

Prevention habits for staff

Never leave devices in vehicles

Lock screens when stepping away

Use cable locks or secured storage for shared devices

Do not store PHI on personal phones outside approved apps

Keep a device inventory with assigned owners

Building it into policy

Include a device and media policy covering encryption requirements, approved devices, reporting procedures and disposal. Make sure old devices are wiped properly before they are donated, sold or recycled.

Getting help

UnityCare IT helps healthcare organizations inventory devices, enable and verify encryption and set up remote lock and wipe. If you are not certain every laptop in your facility is encrypted, we can check.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172