HIPAA: Lost USB Drive with Patient Data — Response Guide

Critical response steps when a USB drive containing PHI is lost or missing

Immediate Action Required

Response Timeline

First Hours

  • Confirm the USB drive cannot be located
  • Interview the person who lost it about the device
  • Document the date device was last seen
  • Identify what files were on the device
  • Determine how many patient records were affected
  • Check the technical specifications (make, model, serial number)
  • Verify encryption status and type
  • Notify your compliance and IT leadership

First 24-48 Hours

  • Conduct thorough search of locations where device may be
  • Check with IT about tracking capabilities (if available)
  • Verify encryption strength and implementation
  • Assess if encryption keys are secured separately
  • Determine the probability of unauthorized access
  • Begin preliminary breach risk assessment
  • Notify legal counsel
  • Document all findings and search efforts

1 Week

  • Complete encryption verification audit
  • If unencrypted: Assume breach and begin assessment
  • If encrypted: Document encryption strength and key security
  • Prepare breach assessment documentation
  • Determine if breach notification is required
  • Assess number of affected patients
  • Identify what patient information was on the device

First 30 Days

  • Finalize breach assessment determination
  • If breach determined: Send patient notifications
  • File OCR notification if required
  • Implement device recovery procedures
  • Conduct post-incident review
  • Update policies to prevent future incidents
  • Document all actions and timeline

60+ Days

  • Submit OCR notification if required
  • Monitor for evidence of unauthorized use
  • Complete remediation measures
  • Implement technical controls for mobile devices
  • Provide staff retraining on device security
  • Retain documentation for investigations

Encryption Assessment

The critical factor in breach determination is encryption status:

Breach Risk Assessment

HIPAA allows for "low probability of compromise" exception:

Notification Requirements

If a breach is determined:

USB Drive Media Disposal Policies

Establish proper procedures for USB drive management and disposal:

Prevention Strategies

Frequently Asked Questions

Is a lost encrypted USB drive a breach?
Not necessarily, if it is properly encrypted. If the device has robust encryption (AES-256 or equivalent) and the encryption key is not on the device or accessible, it may not constitute a breach. However, you must conduct a risk assessment to confirm encryption status and strength. When in doubt, treat it as a breach.
How long do I have to notify patients?
HIPAA requires notification without unreasonable delay and no later than 60 calendar days after discovery of the breach. This timeline is critical and must be met regardless of ongoing investigation or device recovery efforts.
Should I try to find the USB drive?
Yes, conduct a reasonable search of locations where the drive might be located. However, if unsuccessful after several days, assume it may be lost and begin breach assessment procedures. Document all search efforts for your incident report.
What data should never be on a USB drive?
Sensitive data like complete patient records, social security numbers, financial information, or large datasets should never be stored on USB drives. Use secure alternatives like encrypted network shares, secure cloud storage, or encrypted email for data transfer instead.

Secure Your Mobile Device Data

Comprehensive security analysis can identify where patient data is at risk.

Get Your Security Analysis