A field device went missing
The tablet left at a client's home, the phone gone from the car: what happens next under HIPAA, why encryption decides which of two very different days you are having, and the five-minute drill that makes the answer boring.
Last verified: 2026-07-12
An RBT calls from the car: the tablet is not in the bag. Maybe it is at the last house, maybe it is on the roof of the car three intersections back, maybe it is gone. Field-based care means devices in living rooms, schools, and back seats, which means this call is not a failure of your clinic; it is a statistical certainty of your model. What is not certain is which of two very different days you are about to have, and that was decided weeks ago, by a checkbox.
The first thirty minutes
Try the boring explanation first. Call the family from the last session. A tablet on their couch, retrieved tomorrow with a confirmation of where it sat, is not an incident; it is Tuesday. Note it anyway.
If it does not surface, act as if it is gone. Remote-lock the device now, through your device management console or the platform’s find-my tools. If your policy is wipe-on-loss and the data syncs to the cloud, issue the wipe; you lose nothing that matters and you end the question of what happens next on that device.
Check what the device could actually reach. Last sync time, which apps were signed in, whether sessions were cached locally or the device was a thin window into the cloud. A tablet whose data collection app holds three cached sessions is a different object from one storing a year of video.
Pull the register entry. Which device it was, who has had it and since when, and, the load-bearing field, its encryption status. This is the accountability record the physical safeguards expect you to keep (45 CFR 164.310(d)(2)(iii)), and this half hour is the argument for it: a clinic with a register is doing a lookup; a clinic without one is doing archaeology under stress.
Write the timeline down. When it was last seen, when the loss was noticed, when you locked or wiped it, what it held. Every clock and every judgment downstream leans on this record.
The fork
Now the legal question, and it is exactly one question: was the PHI on that device unsecured (45 CFR 164.402)?
The encrypted day. If the device was encrypted consistent with the HHS guidance (for data at rest, encryption consistent with NIST SP 800-111, which is what a modern tablet or laptop’s full-disk encryption provides when it is actually enabled), and the means of decryption did not travel with it, no passcode on a sticky note in the same bag, no password taped to the case, then the data on it was not unsecured PHI. The breach notification machinery generally does not fire. You document the loss, the encryption status, and the basis for concluding the key was not compromised, you keep that record six years, and you move on to replacing a piece of hardware. That is the whole day.
The unencrypted day. The presumption applies: the loss is presumed a breach unless a documented four-factor risk assessment honestly demonstrates a low probability that the PHI was compromised. Be careful with the honesty here, because the lost-device version of this assessment tempts people. “It is probably in a landfill” is a hope, not a factor. The factors are what they are: what PHI was on it, and how identifiable; who plausibly has it; whether it was actually accessed, which a passcode alone makes harder but, without encryption, does not make false; and what you did to mitigate, where a confirmed remote wipe after loss genuinely counts. If the assessment honestly lands at low probability, document it and keep it. If it does not, the notification clocks are here: individuals within 60 days, HHS by count, and the rest.
You are not trying to find out whether you can avoid reporting. You are trying to find out what is true. The assessment is evidence, and it will be read someday by someone who was not hoping.
One nuance worth stating because it is counterintuitive: a lock-screen passcode without encryption is a doorknob lock on a filing cabinet with removable drawers; the storage can be read without ever satisfying the passcode. Encryption is the property that makes the data itself unreadable, and it is the only property the safe harbor credits.
“You are not trying to find out whether you can avoid reporting. You are trying to find out what is true.”
The five-minute drill that changes which day you get
Everything above was decided before the tablet went missing. The pre-work:
Encrypt everything, today. Full-disk encryption is built into the devices your clinic already owns and costs nothing but the settings screen it lives on. Modern iPads and iPhones encrypt by default when a passcode is set; laptops and Android devices have it as a toggle. Encryption is formally an addressable specification (45 CFR 164.312(a)(2)(iv)), and the honest assessment for a fleet that rides into living rooms takes one sentence: the likeliest loss event in this clinic is a device leaving our control, and encryption is the difference between that event being a hardware cost and a notification event. Verify it is on, per device, and record the verification in the register; “the defaults probably handled it” is not a record.
Keep the register current. Device, holder, since when, encryption verified on what date. One row per device. It satisfies the accountability specification (45 CFR 164.310(d)(2)(iii)) and, more to the point, it is the difference between the two openings of the incident file: “iPad 7, assigned to J., encrypted, last synced 2:40pm” versus “an iPad is missing.”
Cache less. Where the platform allows it, configure field devices as windows rather than warehouses: cloud-synced data collection, no local video exports, no downloading records for offline convenience. The less a device holds, the less a loss means.
Set the reflexes. Automatic logoff after short inactivity (45 CFR 164.312(a)(2)(iii)), remote-wipe enrollment before a device ever goes to the field, and one sentence in training: the moment a device might be gone, say so. The RBT who reports at 3pm gave you containment; a culture where people sit on it until Friday gave you a discovery-clock problem, because discovery runs on what your organization should have known.
The honest close
No clinic prevents every loss; the model guarantees the attempt fails eventually. What a clinic controls is whether the loss lands on a prepared surface. The prepared version of this day, encrypted device, current register, quick report, confirmed wipe, documented file, is fifteen minutes of administration. The unprepared version is a four-factor assessment written under pressure about a device nobody can describe, and every family on that tablet getting a letter. Same tablet, same parking lot, two different clinics.
The short version
- First moves: remote-lock or wipe, check last sync, pull the device register entry, write down the timeline. Minutes matter for containment and for the record.
- If the device was encrypted to the HHS guidance standards and the passcode did not travel with it, the data is not unsecured PHI and the notification machinery generally does not fire.
- If it was not encrypted, the presumption applies: it is a breach unless a documented four-factor assessment honestly shows low probability of compromise.
- A device register (which device, whose hands, since when, encryption status) turns a panicked mystery into a five-minute lookup.
- Turn on full-disk encryption today on every device that touches sessions; it is built into the hardware you already own and it is the whole difference between the two versions of this day.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Definitions, including breach, the presumption, and unsecured PHI45 CFR 164.402https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402
- HHS guidance to render unsecured PHI unusable, unreadable, or indecipherable74 FR 19006, April 27, 2009https://www.federalregister.gov/documents/2009/04/27/E9-9512/guidance-specifying-the-technologies-and-methodologies-that-render-protected-health-information
- HHS breach notification guidance, current versionHHS.gov, Office for Civil Rightshttps://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html
- Device and media controls, including accountability45 CFR 164.310(d)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310
- Access control, including encryption and automatic logoff45 CFR 164.312(a)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
- Notification to individuals45 CFR 164.404https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404
Know the answer before the question.
Which device, whose hands, encrypted or not, last synced when: WiseUpHIPAA keeps your device register and its encryption status current as your clinic runs, so a missing tablet is a lookup, not an investigation.