Lost or Stolen Work Phone: What HIPAA Requires Healthcare Practices to Do

A lost or stolen work phone can expose patient messages, voicemails, and photographs, and grant access to clinical accounts. 

For your practice, the immediate concern extends beyond replacing the device. You must determine what information was accessible, restrict further access, and assess your obligations under HIPAA.

However, a missing phone does not automatically mean your practice must report a breach. The circumstances of the loss, the safeguards already in place, and the evidence of potential exposure inform that decision.

The article explains how to respond, assess notification requirements, and document your findings.

It also examines how a HIPAA-compliant phone service, such as iPlum, can form part of your preparations for device loss and allow authorized colleagues to continue responding to patient communication.

Table of Contents

1. What should your practice do immediately after a work phone goes missing?

2. Does the missing phone create a reportable HIPAA breach?

3. Who must you notify if the incident is a reportable breach?

4. What should your practice document before closing the incident?

5. Manage patient calls and texts beyond the missing handset with iPlum

6. Frequently asked questions (FAQs)

7. Put patient calls and texts on a practice-managed line

What should your practice do immediately after a work phone goes missing?

Your practice should begin its incident response as soon as an employee reports a missing phone. 

Searching for the device should not delay actions to protect patient information.

Here’s what you need to do:

Notify your privacy or security officer and record the timeline

The employee should promptly contact the designated privacy or security officer through another device. Record when they last had the phone, when they discovered it was missing, and where the loss likely occurred.

Also, identify the work applications and accounts accessible from the phone. 

In addition, establish whether the device was unlocked, whether notifications displayed message content, and whether the employee had stored patient photographs or documents locally.

These details give the incident reviewer a starting point for assessing potential exposure.

Restrict the missing phone's access to practice accounts

Your administrator should revoke active sessions and disable the device's access to email, clinical systems, and communication accounts where available. 

Also, change compromised credentials and review authentication methods associated with the missing phone.

Then use the available device management features to lock the phone remotely or initiate an authorized wipe. In addition, record whether the command succeeded because an offline phone might not receive it immediately.

Contact the mobile carrier about suspending service, too. 

Preserve evidence of the loss and your response

As containment proceeds, save the available access logs, device management records, and relevant account activity. Record who took action, when they acted, and what the system confirmed.

Also, document any uncertainty, such as an unconfirmed wipe or unknown encryption status. Your practice will need those facts when deciding whether notification is necessary.

HIPAA requires practices to respond to suspected or known security incidents, mitigate harmful effects where possible, and document the incident and its outcome. Recovering the phone does not, on its own, resolve questions about earlier access. 

Does the missing phone create a reportable HIPAA breach?

After restricting access, your practice must determine whether the loss requires breach notification. 

The decision depends on the patient information involved, its protection, and the circumstances of potential exposure.

Here’s what you need to do:

Identify the patient information stored on or accessible through the phone

Start with the accounts and applications identified during your initial response. Determine which contained protected health information (PHI) and which patients the incident could affect.

For example, a downloaded lab report presents a different exposure concern from an EHR application that requires fresh authentication before displaying records.

Also, examine patient texts, voicemail, photographs, email attachments, and notification previews. Information does not have to appear in a formal medical record to qualify as PHI.

Then establish the potential scope of exposure. Record the types of information involved, the patient identifiers attached to it, and the number of affected individuals.

Verify the encryption and access protections in place before the loss

A phone passcode alone does not establish that patient information meets HHS's encryption criteria. 

Your practice should verify the encryption configuration and determine whether an unauthorized person could access readable information.

For instance, an encrypted phone that was unlocked when stolen requires examination of accessible applications and active sessions. 

Qualifying encryption can exempt the protected information from HIPAA breach notification requirements. However, your practice needs evidence that the protection applied to the information involved. 

Assess whether unsecured patient information was compromised

An impermissible use or disclosure is presumed to be a breach unless your practice demonstrates a low probability of compromise through a documented assessment. Examine:

  • The information involved and its identifying details.
  • Who obtained or could access it.
  • Evidence that anyone acquired or viewed it.
  • Actions that reduced potential exposure.

An absence of suspicious activity alone does not establish that notification is unnecessary. Evaluate the available evidence together and document the reasoning behind your decision. 

Alternatively, your practice can proceed with required notifications rather than conduct an assessment to establish a low probability of compromise. 


Who must you notify if the incident is a reportable breach?

If your assessment establishes a reportable breach, your practice must notify affected patients and HHS. 

Some breaches also require media notification. The deadlines and recipients depend on the number of affected individuals and where they reside.

Here’s what you need to do:

Notify affected patients promptly

Notify affected patients as soon as reasonably possible, no later than 60 calendar days after discovering the breach. The 60-day limit is an outer deadline, not a waiting period.

Your notice must explain:

  • What happened, including relevant dates if known.
  • Which types of patient information were involved?
  • What patients should do to protect themselves.
  • How is your practice investigating and addressing the incident?
  • How patients can contact your practice for further information.

Send written notices by first-class mail or by email if the patient previously agreed to electronic notices. Additional substitute-notice requirements apply when contact details are insufficient or outdated.

Report the breach to HHS under the applicable deadline

For breaches affecting 500 or more individuals, notify HHS promptly and no later than 60 calendar days after discovery.

For breaches affecting fewer than 500 individuals, submit the report no later than 60 calendar days after the end of the calendar year in which you discovered the breach.

However, the annual reporting schedule for smaller breaches does not extend the patient notification deadline.

Notify the media when the resident threshold applies

If the breach affects more than 500 residents of a state or jurisdiction, notify prominent media outlets serving that area promptly, within 60 calendar days after discovery.

Media notification supplements the notices sent to patients and HHS. Posting an announcement on your practice's website alone does not satisfy that obligation.


What should your practice document before closing the incident?

Your incident file should explain what happened, how your practice responded, and why it reached its notification decision. 

But before closing the incident, address the weaknesses identified during the investigation by doing the following:

Record the notification decision and its evidence

Document the information involved, the protections in place when the phone disappeared, and any evidence of unauthorized access. Then explain how those findings informed your notification decision.

If the notification was unnecessary, retain the assessment and evidence that justifies that conclusion. If notification was required, retain copies of the notices, recipient records, and submission dates.

Also, identify who reviewed and approved the decision. Your records should explain the reasoning, even if another administrator later reviews the incident. 

Correct the specific weaknesses the loss exposed

Turn the findings into assigned corrective actions.

For instance, delayed reporting calls for employee training and an established reporting contact. Accessible message previews call for revised notification settings.

Similarly, an inability to revoke account access requires changes to account administration. Assign responsibility and a completion date, then verify the changes. HIPAA requires practices to review and modify security measures as circumstances change.

Finally, examine how the loss affected patient communication. If calls and texts reach only the missing handset, your practice needs an arrangement that lets authorized colleagues continue responding.


Manage patient calls and texts beyond the missing handset with iPlum

A missing phone raises two immediate concerns: restricting access to patient information and the ability to continue responding to patients. 

However, your practice needs a phone service that lets administrators manage communication accounts even when employees cannot access their devices.

iPlum provides business numbers, account permissions, secure texting, and shared lines that your practice can incorporate into its device-loss preparations.

iPlum allows you to:

Give clinicians a practice-managed business number

When clinicians use personal numbers for patient communication, your practice has limited authority over the accounts receiving those calls and texts.

With iPlum, you can assign business numbers through a multi-user account. Your administrator can add users, manage their lines, and restrict permissions for specific features.

Consequently, your practice can establish who administers the account before a phone disappears. That way, employees can use their assigned business numbers for patient communication rather than distribute their personal contact details.

Lock the affected user's account through the administrator portal

If a phone goes missing, your administrator can use iPlum’s lock and logout user function. The action logs out the existing user and prevents them from signing back in until the administrator unlocks the account.

Your practice can therefore restrict the affected account via the web portal as part of its incident response.

That said, be sure to record when the administrator applied the restriction and review any earlier exposure separately. On that note, account locking controls access; it does not erase information that was previously copied outside the service.

Require an app passcode for patient communication

Device protection should begin before a loss occurs. 

iPlum’s password policy settings let administrators require an app passcode that prompts users whenever they access the application.

Administrators can also enable two-factor authentication and password complexity requirements. These settings add authentication requirements to the accounts clinicians use for patient conversations.

In addition, your practice can establish encrypted texting with patients through free client accounts. With the free account, patients can participate via the iPlum app or web portal and don’t need a phone. 

Let authorized colleagues respond through a shared line

Patients will continue contacting your practice even when a clinician loses their phone. 

A prepared communication arrangement grants another authorized employee access to conversations that require a response.

With iPlum Shared Line, designated users can answer calls, send texts, and view message histories from their own devices. In addition, administrators select the users and services to share.

For example, a receptionist assigned to the practice's shared line can review an appointment conversation and respond when the clinician's device is unavailable. 

You can configure those permissions in advance, then include the shared line in your device-loss response procedure.


Frequently asked questions (FAQs)

Does HIPAA apply if the lost phone belongs to the employee?

Yes. HIPAA obligations apply to patient information used for work, regardless of device ownership. Therefore, your practice must assess the exposure and follow its incident response procedures for personal phones.

Does suspending the SIM card protect patient information already on the phone?

No. Suspending the SIM restricts cellular service but does not erase stored messages, photographs, or documents. Furthermore, the phone could still access signed-in accounts through an available wireless internet connection.

Does a successful remote wipe eliminate the need for breach notification?

Not automatically. A confirmed wipe can reduce further exposure. However, your practice must assess whether anyone accessed patient information before deletion and document how the wipe affected its notification decision.

What if the phone had EHR access but no patient records were downloaded?

Your practice must assess whether an unauthorized person could access records through an active session or saved credentials. Therefore, the absence of downloaded files does not automatically resolve the incident.

Can finding the phone later change the breach assessment?

Yes. Recovery can provide additional evidence about possession, account activity, and potential access. However, finding the phone does not establish that patient information remained protected throughout the period under review.

Does reporting the theft to police replace HIPAA breach reporting?

No. A police report documents the theft but does not satisfy HIPAA notification duties. Your practice must separately determine whether to notify affected patients, HHS, and, when applicable, the media.


Put patient calls and texts on a practice-managed line

A lost phone should trigger a response that your practice has already prepared. Your administrator needs access to communication accounts, and authorized colleagues need the ability to respond to patients.

iPlum provides your practice with business numbers, account locking, app passcodes, and shared lines to put those arrangements in place. 

Together, these features give you specific actions to take when a clinician reports a missing device.

Before another phone disappears, establish who can restrict access and who will answer patient inquiries. 

Then get an iPlum number and configure your practice's calling and texting accounts as part of your device-loss preparations starting today.

Sign up for iPlum 

Tags
No items found.
Download Our APP Now!