What actually happens when a practice laptop goes missing?
Short answer: the first question is not who took it. It is whether the information on it was encrypted. If it was, the data is unreadable, and under HIPAA that changes everything about what follows.
I am Scott Derby, I am an attorney. A practice laptop going missing is one of the quiet fears in this profession. Left in a car, taken from a bag, simply gone. I want to walk you calmly through what actually happens next, because the practices that come through this fine are the ones that thought about it beforehand.
First: was it encrypted? If the device was encrypted, the data on it is scrambled and unreadable, and that changes what comes next. If it was not, the clock starts.
Then comes the assessment. You look at what was actually on the device, whose information it was, and what the real risk to those people is. This is a defined process rather than a panic. A practice that documented its security ahead of time can work through these questions in an afternoon. A practice that did not is starting from nothing on the worst possible day.
Then, depending on what you find, there may be notifications you are required to make, and timelines for making them.
Here is the part worth hearing. Encryption is the single step that turns a catastrophe into a manageable event. It is not expensive and it is not complicated, and on most modern devices it is a setting rather than a purchase.
Practices that prepare do not avoid every incident. They just get to face them from solid ground.
This is general information about federal HIPAA. It is accurate as of writing and it can change. Your state very likely has its own privacy rules that sit on top of HIPAA and can be stricter, so treat this as a starting point rather than the final word, and check what applies where you practice. This is education, not legal advice for your specific situation.