Artificial Intelligence & Machine Learning , Cloud Security , Data Privacy
Breaches From Lost or Stolen Devices Hit All-Time Low
Experts Say Encryption, Endpoint Management Helped Cut Breaches, But AI Risks LoomGood news about progress in cybersecurity in healthcare is rare, but this year reports of breaches involving lost or stolen unencrypted laptops, desktop computers, servers or other computing devices may hit an all-time low.
See Also: Accelerate Vector Search for enterprise-scale AI with Elastic and NVIDIA
In fact, in the first half of 2026, no such breaches have been reported to federal regulators. The number of breaches tied to endpoints has been steadily declining since 2013, when nearly 80% of all breaches involved lost or stolen unencrypted computing devices, affecting 5.5 million people, according to data reported to the U.S. Department of Health and Human Services.
Cybersecurity experts say the decline in breaches reflects years of focus by healthcare organizations and vendors on encryption, endpoint management and cloud security practices, but they warn that artificial intelligence tools are creating new risks for endpoints.
"It has evolved," said Ellen Boehm, senior vice president of strategy and AI innovation at security firm Keyfactor. "Healthcare organizations are now securing a much broader ecosystem of laptops, mobile devices, medical equipment, AI systems and other connected assets."
A decade of HHS enforcement actions and costly HIPAA settlements against healthcare organizations reporting major health data breaches involving unencrypted computing devices have "built lasting institutional muscle memory," said Dave Bailey, a vice president at privacy and security consultancy Clearwater.
One of the largest such breaches on record occurred at Chicago-based Advocate Health Care in 2013, involving four stolen unencrypted computers and affecting about 4 million patients. HHS settled with the Advocate Health in 2016 with a $5.5 million fine. By 2025, the total number of endpoint-related breaches fell to six - affecting only 24,500 people.
The government's "definitional quirk" about HIPAA breaches helps that trend, Bailey said. "Theft of an encrypted device without key compromise isn't reportable as a breach at all" under HHS' regulations, he said. In other words, devices may be lost or stolen, but they don't qualify as breaches, and tech vendors have recognized that.
"Encryption now ships as a default rather than an opt-in. BitLocker auto-enables on Windows 11 24H2, and FileVault has been one-click on Mac for years. Unified endpoint management platforms enforce encryption as policy, so it's no longer left to chance," he said.
Also, compliance audits really matter in healthcare, said Martin Zugec, technical solutions director at security firm Bitdefender.
"When a device disappears, the organization can demonstrate it was encrypted and remotely wiped, which changes the incident from a reportable breach into a routine asset write-off," Zugec said. "The same model has largely tamed clinician smartphones and tablets. Personal devices either enroll in mobile device management and meet the encryption bar, or they don't touch patient data."
"Concentrating everything behind one login raises the stakes of the credential that opens it. The risk didn't disappear. It pooled. A decade of consolidation drained a thousand puddles into one reservoir, and now the job that matters is guarding the dam."
– Jason Elrod, CISO, MultiCare Health
The shift to virtual desktop infrastructures, thin clients and cloud-hosted electronic health records access also means a stolen laptop often holds no local protected health information, just a window into data stored elsewhere, Bailey said.
Shifting the Risk to Identity
But those downward trends indicate a shift in risk for healthcare providers, not an elimination of risk. "Exposure moves to identity and session security instead," he said.
Jason Elrod, CISO at MultiCare Health Systems and executive advisor at security firm Elisity, agrees the move to virtual desktops and browser-based applications has helped secure healthcare providers, but the risks of compromise are even greater.
"Concentrating everything behind one login raises the stakes of the credential that opens it. The risk didn't disappear. It pooled. A decade of consolidation drained a thousand puddles into one reservoir, and now the job that matters is guarding the dam."
Asset management improvements are also helping. Cloud-based unified endpoint management gives real-time visibility into encryption and patch status, and zero-touch provisioning applies policy before a device ever reaches a user, Bailey said. "Maturity is uneven, though - strong for managed endpoints, weak for the unmanaged long tail."
Historically, healthcare asset management was a disjointed mess of static spreadsheets, said Skip Sorrels, field CTO and CISO at security firm Claroty. "Today, the industry has shifted toward cybersecurity asset management - CAASM, which provides continuous, dynamic visibility into every single connected device across the enterprise, he said.
Meanwhile, AI is hyper-accelerating this space by shifting organizations from reactive mapping to proactive posture management, Sorrels said.
"AI-driven asset discovery engines don't just flag a device. They analyze behavioral baselines to instantly fingerprint what a device is, what it should be talking to and whether its configuration has drifted into a vulnerable state," he said. "AI allows us to contextualize risk at scale - ensuring that an unpatched endpoint or an unauthorized device is isolated before it can be leveraged as an initial entry point by threat actors."
AI-enabled asset management and anomaly detection "are only as good as the discipline underneath because data is the oil of the information age, but it's the DNA of the AI age," Elory said.
"If your inventory is fiction, your AI is confidently wrong at machine speed. On the risk side, every AI agent is a new kind of endpoint identity: Agents aren't users with bad behavior. They're identities with no judgment. They deserve the same life cycle scrutiny we finally learned to give laptops."
AI Risks and Benefits
While encryption largely solved one generation of endpoint risk, AI is creating another. Security leaders say organizations now have to manage not only laptops and mobile devices but autonomous software agents, machine identities and AI-enabled systems that increasingly access sensitive clinical data.
AI tools are helping improve asset discovery and risk detection, but they are also increasing the number of machine identities that must be trusted and managed, Boehm said. "The focus is shifting from simply encrypting devices to continuously verifying and governing every machine and identity that accesses sensitive data."
The biggest remaining gaps are in the device categories that managed endpoint tools were never built to handle, said Ty Greenhalgh, healthcare technology strategist, Armis from ServiceNow.
"Personal devices used informally for clinical work, operational technology in clinical environments and connected medical devices are all places where visibility is still limited and risk is still high," he said.
BYOD Just Won't Go Away
Bailey calls smartphones and personal mobile devices used by clinicians "the least mature risk area."
"Personal phones and tablets are inconsistently enrolled in mobile device management and often rely on app-level containers rather than full device management. Each incident carries smaller PHI exposure, but the population of devices is much larger and far less inventoried," he said.
Greenhalgh points out "an interesting dynamic emerging on the encryption side" worth noting: As medical device manufacturers upgrade their communications protocols to modern encryption standards, a visibility tradeoff can appear, he said.
"Passive network monitoring loses the ability to inspect traffic it could previously read. The industry is actively working through this," he said. The direction manufacturers are moving in is toward sharing device identity and software data with authorized security monitoring platforms through standardized protocols.
"The idea is that when manufacturers complete their testing and validation, they will release the necessary information to security platforms so visibility is preserved even as encryption improves," he said. "Security and better encryption should advance together, not trade off against each other."
Meanwhile, other factors are also contributing to endpoint device breach trends such as cyber insurance policies that now require encryption attestation, remote work forced formal mobile device management adoption and ongoing hardware refresh cycles have quietly retired pre-encryption-by-default devices from inventories, Bailey said.
Healthcare appears to have largely solved the problem of stolen and lost unencrypted laptops leading into major PHI breaches. But the next challenge is ensuring organizations can securely identify, authenticate and monitor the growing number of connected medical devices, AI systems and machine identities now accessing sensitive patient data.