---
title: Mobile Device Policies for Preventing HIPAA Data Breaches
description: Creating mobile device policies to guard against HIPAA data breaches can be tricky. Burdensome policies, human error and criminal intent can all defeat the best-intentioned strategies. Despite these issues, mobile device policies are a necessary part of a program preventing HIPAA data breaches.
---

- [Sign In](https://secure.proassurance.com?hsLang=en-us)
- g

Search Site

[Contact Us](https://www.proassurance.com/contact-us/?hsLang=en-us): **844-466-7225**

[![PRA-MMI-Logo®-RGB](https://www.norcal-group.com/hs-fs/hubfs/PRA-MMI-Logo%C2%AE-RGB.png?width=215&height=62&name=PRA-MMI-Logo%C2%AE-RGB.png)](https://www.norcal-group.com?hsLang=en-us)

 

- [About](https://norcal-group.com/about) 
    - [About Us](https://norcal-group.com/about)
- [Coverages](https://norcal-group.com/state)
- [Claims](https://www.proassurance.com/report-a-claim/)
- [Resources](https://www.norcal-group.com/resources) 
    - [HIPAA Resources](https://proassurance.com/hipaa)
    - [Website Accessibility](https://proassurance.com/accessibility)
- [Pay](https://www.norcal-group.com/pay)

## [Resource Library](https://www.norcal-group.com/library?hsLang=en-us)

# Mobile Device Policies for Preventing HIPAA Data Breaches

 June 14, 2018

- [Tweet](https://twitter.com/share)

Creating mobile device policies can be tricky. Burdensome security policies and strategies that diminish productivity will most likely result in employee workarounds that defeat security efforts.1,2 Additionally, human error and criminal intent can defeat the best-intentioned employee laptop and storage device security strategies. Despite these difficulties, mobile device policies are a necessary part of a comprehensive information security program to prevent HIPAA data breaches.

See also, “[Case Study Comparison: HIPAA Data Breaches and PHI on Stolen Laptops](https://www.norcal-group.com/library/case-study-comparison-hipaa-data-breaches-and-phi-on-stolen-laptops?hsLang=en-us)” for further discussion of this issue.

Encryption can secure PHI as it moves though the information stream and into computers and mobile devices. Encrypted PHI is less likely to be compromised if devices are lost, stolen or nefariously accessed. Additionally, there are various technologies available on the market that can dynamically detect and redact PHI and block sensitive information from being downloaded to certain devices.1

The HHS HealthIT.gov website has extensive [guidance on using mobile devices in clinical practice](https://www.healthit.gov/resource/your-mobile-device-and-health-information-privacy-and-security). The website includes videos on securing PHI on mobile devices, downloadable posters, presentations and fact sheets to help covered entities comply with HIPAA data security requirements.

## Bring Your Own Device (BYOD) Policies

A bring your own device (BYOD) policy should be put in place when administrators, clinicians and staff are allowed to use personally owned devices (e.g., laptops, tablets, smartphones) to access, manipulate, use, copy, store or move PHI. Lost and stolen devices are a major source of data security breaches.3 The simple act of enabling device security options such as password protection, device encryption, fingerprint or facial authentication, and time-out locks can help prevent HIPAA data beaches by making the PHI inaccessible.

Many device users don’t even realize when they are exposing PHI to a security breach. For example, various apps don’t store content on a device, they store it in the cloud. In many apps, the content is stored in the cloud by default, which requires device users to disable the cloud storage function if they don’t want data to be held there. When users don’t disable cloud storage, PHI can exist in multiple locations on cloud servers that cannot be controlled by the covered entity that is responsible for the security of the PHI. Covered entities that allow BYOD should develop and implement a policy defining how PHI must be protected, what steps must be taken if a personally owned device that potentially contains PHI is lost or otherwise compromised and the personal consequences of violating the BOYD policy.2,4

## More Information About Preventing HIPAA Data Breaches

- Overview: [Preventing HIPAA Data Breaches: Case Studies and Best Practices](https://www.norcal-group.com/library/preventing-hipaa-data-breaches-case-studies-and-best-practices?hsLang=en-us)
- Best Practices: [Best Practices for Preventing HIPAA Data Breaches by Criminal Hackers](https://www.norcal-group.com/library/best-practices-for-preventing-hipaa-data-breaches-by-criminal-hackers?hsLang=en-us)
- Case Study Comparison: [HIPAA Data Breaches and PHI on Stolen Laptops](https://www.norcal-group.com/library/case-study-comparison-hipaa-data-breaches-and-phi-on-stolen-laptops?hsLang=en-us)
- Closed Claim Case Study: [Misdelivered Email Results in a HIPAA Data Breach](https://www.norcal-group.com/library/misdelivered-email-results-in-a-hipaa-data-breach?hsLang=en-us)
- Closed Claim Case Study: [Employee Voyeurism Leads to a HIPAA Data Breach](https://www.norcal-group.com/library/employee-voyeurism-leads-to-a-hipaa-data-breach?hsLang=en-us)
- Closed Claim Case Study: [Unsecured PHI on a Lost Flash Drive Results in a HIPAA Data Breach](https://www.norcal-group.com/library/unsecured-phi-on-a-lost-flash-drive-results-in-a-hipaa-data-breach?hsLang=en-us)

**Additional Resources for Policyholders**

Guidance and additional information on the HIPAA Security Rule and on medical records security, access and release are available to all NORCAL policyholders by contacting a NORCAL Risk Management Specialist at 855.882.3412.

**Information and Network Security Coverage**

Call NORCAL Customer Service at 844.4NORCAL or visit our [Information and Network Security coverage](https://www.norcal-group.com/information-network-security?hsLang=en-us) page for more information about this coverage available at no additional cost as part of the Health Care Professional (HCP) policy.

[![This content from Claims Rx](https://no-cache.hubspot.com/cta/default/508142/35fb4f75-fa17-4779-a029-6a0441b4a787.png)](https://cta-redirect.hubspot.com/cta/redirect/508142/35fb4f75-fa17-4779-a029-6a0441b4a787)

## References

1. Bitglass. “[2014 Bitglass Healthcare Breach Report](https://pages.bitglass.com/pr-2014-healthcare-breach-report.html).” (accessed 5/14/2018)

2. Pennic J. “[68% of Healthcare Data Breaches Due to Device Loss or Theft, Not Hacking](https://hitconsultant.net/2014/11/04/healthcare-data-breaches-device-theft-loss/).” HIT Consultant. (accessed 5/14/2018)

3. Verizon Enterprise. “[2018 Data Breach Investigations Report](https://www.verizonenterprise.com/resources/reports/rp_DBIR_2018_Report_en_xg.pdf).” (accessed 5/14/2018)

4. Virtu. “[HIPAA Email Compliance: 6 Best Practices for Medical Data Security](https://www.virtru.com/blog/hipaa-email-compliance/).” January 8, 2015. VirtuBlog. (accessed 5/14/2018)

## Additional Linked Resource

Office of the National Coordinator for Health Information Technology (ONC). “[Your Mobile Device and Health Information Privacy and Security](https://www.healthit.gov/resource/your-mobile-device-and-health-information-privacy-and-security).” HealthIT.gov. (accessed 5/14/2018)

 Filed under: [Digital Health](https://www.norcal-group.com/library/topic/digital-health), [Privacy & HIPAA](https://www.norcal-group.com/library/topic/privacy-hipaa), [Cybersecurity](https://www.norcal-group.com/library/topic/cybersecurity), [Best Practices](https://www.norcal-group.com/library/topic/best-practices), [Practice Manager](https://www.norcal-group.com/library/topic/practice-manager), [Information Security](https://www.norcal-group.com/library/topic/information-security)

###  Topics 

Please select Bad Outcomes & Complications Business Continuity Business Operations Community Health Consultations Cosmetic & Reconstructive Procedures Cultural Competency & Cultural Respect Cybersecurity Diagnosis & Testing Digital Practice Electronic Health Records (EHR) General Liability HIPAA Privacy & Confidentiality Industry Trends Information Security Informed Consent Leadership Litigation & Claims Marketing & Practice Building Medical Errors & Apology Medical Ethics Medical Records & Documentation Medication Errors Opioids Pain Management Patient Communication Patient Relationship Personal Finance & Career Philanthropy & Community Involvement Physician Burnout Physician Ratings Physician Wellness Practice Communication Practice Drift Practice Management Prescribing & Medication Public Relations & Communication Regulation & Compliance Reputation Management Unanticipated Outcomes Vicarious Liability

###  Specialties 

Please select Emergency Medicine Family Practice Mental & Behavioral Health Obstetrics & Gynecology Oncology Ophthalmology Orthopedics Pain Management Specialist Pediatrics Plastic & Cosmetic Surgery Radiology

### Recently Added

Interested in NORCAL Group?

**Contact Your Agent/Broker** or call 844.4NORCAL today

* NORCAL Group, now part of ProAssurance, includes NORCAL Insurance Company and its affiliated companies.

[![AM Best](https://www.norcal-group.com/hubfs/Norcal_Mutual_Images/graphic_am-best.png)](https://www.norcal-group.com/ambest?hsLang=en-us)

- [About](https://norcal-group.com/about) 
    - [About Us](https://norcal-group.com/about)
- [Coverages](https://norcal-group.com/state)
- [Claims](https://www.proassurance.com/report-a-claim/)
- [Resources](https://www.norcal-group.com/resources) 
    - [HIPAA Resources](https://proassurance.com/hipaa)
    - [Website Accessibility](https://proassurance.com/accessibility)
- [Pay](https://www.norcal-group.com/pay)

© 2001 - 2024 ProAssurance  
All rights reserved

- [844-466-7225 ](tel:18444667225)
- [Privacy Policy](https://proassurancegroup.com/privacy-policy?hsLang=en-us)
- [Terms of Use](https://www.norcal-group.com/terms?hsLang=en-us)
- [Website Accessibility](https://www.norcal-group.com/accessibility?hsLang=en-us)

```json
{
  "@context" : "http://schema.org",
  "@type" : "InsuranceAgency",
  "contactPoint" : {
    "@type" : "ContactPoint",
    "contactType" : "customer service",
    "telephone" : "1.844.466.7225"
  },
  "description" : "The NORCAL Group of companies provide medical professional liability insurance to physicians, health care extenders, medical groups, hospitals, community clinics and allied health care facilities throughout the country.",
  "foundingDate" : "1975-01-01",
  "foundingLocation" : "California",
  "legalName" : "NORCAL Mutual Insurance Company",
  "logo" : "https://files.norcal-group.com/hubfs/Website/Logos/NORCAL-Group-Logo-X-18.png",
  "name" : "NORCAL Group",
  "potentialAction" : {
    "@type" : "SearchAction",
    "query-input" : "required name=search_term_string",
    "target" : "http://www.norcal-group.com/search?search={search_term_string}"
  },
  "subOrganization" : [ "Medicus", "FD Insurance", "NORCAL Specialty Insurance Company", "PMSLIC" ],
  "url" : "http://www.norcal-group.com"
}
```