Need IT help now? Call (321) 221-7117 — We respond within 2 hours.

Need IT help? Help Desk Request Assistance Priority Intake
Cybersecurity

A Laptop With Patient Data Is Missing. Here’s the First Hour.

Aug 25, 2026·4 min read·By Ric Acevedo

What should you do first when a laptop with patient data goes missing?

Record the exact time of discovery, establish whether the drive was encrypted, and cut off account access — in that order. Do not begin by searching for the device. The encryption answer determines whether this is a reportable breach, and access can be revoked whether or not the laptop is ever found.

A staff member calls on a Saturday. The laptop is not in the car, not at home, and they last had it at the clinic on Thursday.

What happens in the next hour determines whether this is a paperwork exercise or a reportable breach. Most practices have never decided what that hour looks like, and improvise it badly.

First: do not start by looking for the laptop

The instinct is to retrace steps. Do that second. The first job is to establish what was on it and whether it can still be reached, because both of those get harder with time and neither depends on finding the device.

1. Write down the time

Not approximately. The clock starts on discovery, and the sixty-day notification window is measured from when the practice knew or reasonably should have known. Your own timeline is the first piece of evidence you will be asked for.

2. Establish whether it was encrypted

This is the question that decides everything else. If the drive was encrypted to the HHS standard and the key was not on a sticky note attached to it, the data is not “unsecured” and the breach notification obligations may not apply at all.

You need to be able to answer this from records, not memory. “I think we turned that on” is not an answer that survives scrutiny — which is why the answer should exist before the laptop goes missing.

3. Cut off access

Whether or not it was encrypted: disable the account, revoke the active sessions, and remove the device from anything it was trusted on. A laptop with a saved password to your EHR is a problem even if the local disk is unreadable.

4. Trigger the remote wipe — and know it may do nothing

If the device is managed, issue the wipe. But be honest in your notes about what that means: a remote wipe only executes when the machine connects to the internet. A laptop that is switched off, or whose drive has been pulled, will never receive it. Recording “wiped remotely” when the command was merely sent is the kind of inaccuracy that unravels later.

5. Work out what was actually on it

Not what should have been. Downloaded reports, exported spreadsheets, email attachments, the local cache of whatever they were working on Thursday. This is usually worse than people expect and is the part that determines the size of any notification.

Then, and only then, look for it

Once access is cut and the scope is known, go and search the building. Devices turn up in about half these cases — in a different bag, in a colleague’s car, under a car seat. A recovered device does not undo a breach if it was unencrypted and out of your control, but it does change what you can establish about exposure.

The uncomfortable part

If the drive was not encrypted, you are probably looking at a reportable breach: individual notification within sixty days, notification to HHS, and if more than five hundred people are affected, notification to prominent media in the state.

That is not a technology outcome. It is the outcome of a decision made months earlier about whether laptops get encrypted — which is exactly why encryption is worth sorting out while nothing is wrong.

What to put in place before you need it

  1. A list of devices and whether each is encrypted, kept current. This single document is the difference between a bad hour and a bad quarter.
  2. A named person who makes the call at the weekend. Incidents do not respect office hours, and “we waited until Monday” reads badly in a timeline.
  3. Written steps, on paper, that someone can follow while stressed. Your incident response plan is a Security Rule requirement anyway.
  4. A tested way to disable an account fast, that does not depend on one person being reachable.

Most practices have some of this. Very few have all four, and nobody discovers which ones are missing at a convenient moment.

If you want to know where your practice would actually stand on a Saturday afternoon, we can walk through it with you — and if the answer is that you are in good shape, we will say so.

General information about a regulation, not legal advice. For a live incident, involve a healthcare attorney early.

Recent Articles

Cybersecurity
HIPAA Says Encryption Is “Addressable.” That Doesn’t Mean Optional.
Aug 25, 2026
Cybersecurity
Does Your IT Company Need a BAA? (Almost Certainly Yes)
Aug 25, 2026
Cybersecurity
A Big Four firm lost client tax records through its help desk. Yours has one too.
Aug 19, 2026
Invoice Fraud: The Scam That Targets Your Accounting Team (Not Your IT)
Business IT
Invoice Fraud: The Scam That Targets Your Accounting Team (Not Your IT)
Jul 19, 2026
Renewing your PTIN this fall? Line 11 asks more than most preparers realize
Cybersecurity
Renewing your PTIN this fall? Line 11 asks more than most preparers realize
Jul 17, 2026

Related posts

Digital Business Card