HIPAA Compliance: What to Do When a Laptop Is Stolen

Quick response guide for securing your organization and meeting notification requirements

Immediate Action Required

Response Timeline

First 24 Hours

  • Activate incident response team and command center
  • File police report and document theft details
  • Issue remote kill command to wipe device
  • Identify all patient data that was on the laptop
  • Interview employee to gather specifics about the device
  • Change credentials for accounts that may have been accessed
  • Notify IT security and compliance leadership

48 Hours to 1 Week

  • Complete encryption verification audit
  • Review system logs for unauthorized access attempts
  • Conduct full breach risk assessment
  • Determine number of affected patients
  • Involve legal counsel to assess notification obligations
  • Begin breach investigation documentation
  • Notify your cyber insurance carrier

First 30 Days

  • Issue breach notifications if assessment determines a breach occurred
  • Provide notification to media if required (500+ affected)
  • File OCR breach report if applicable
  • Implement device recovery or confirmation of destruction
  • Complete post-incident review
  • Document all actions and timeline

60+ Days

  • Submit OCR notification if required
  • Retain all documentation for potential investigations
  • Implement remediation measures to prevent recurrence
  • Update security policies and device protocols
  • Monitor for any evidence of data misuse

Encryption Assessment

The key factor in determining if a stolen laptop constitutes a HIPAA breach is encryption status:

Document your encryption methodology and provide evidence of implementation in your breach assessment.

Notification Requirements

Under HIPAA Breach Notification Rule, you must notify:

Notification must include the date of the breach, description of what happened, steps individuals should take, and your mitigation steps.

Prevention Strategies

Frequently Asked Questions

Is a stolen laptop always a HIPAA breach?
Not necessarily. If the laptop is encrypted and the encryption key is not accessible to the thief, it may not constitute a breach. However, you must conduct a risk assessment to determine if the data is at risk of compromise. HIPAA allows for a low probability of compromise exception if you can demonstrate the device contained minimal or no PHI.
How quickly must I notify patients of the breach?
HIPAA requires notification without unreasonable delay and no later than 60 calendar days after discovery of the breach. This timeline is critical and must be met regardless of ongoing investigation or police proceedings.
Do I need to file a report with HHS?
Yes, if the breach affects 500 or more residents or subscribers, you must notify HHS and the media. Breaches affecting fewer than 500 individuals must be reported annually to HHS. Each state may have additional requirements.
What should I do about the stolen device?
File a police report for the theft and obtain a case number for documentation. Work with IT to remotely wipe the device if capabilities exist. Monitor for any unauthorized access attempts. Document all actions taken and maintain evidence for potential investigation.

Strengthen Your HIPAA Response Plan

A comprehensive security risk analysis can identify vulnerabilities before incidents occur.

Get Your Security Analysis