By NHI Mgmt Group Editorial TeamBased on Imprivata: “The hidden risk of lost mobile devices in healthcare: Why asset management is the fix” (June 1, 2026)

TL;DR: Healthcare mobile devices now support core clinical workflows, yet they are frequently lost, misplaced, or left unaccounted for, creating security, compliance, and productivity risk, according to Imprivata. The deeper issue is not device loss itself but the lack of reliable visibility, ownership, and control across shared clinical assets.


At a glance

What this is: This article argues that lost or unaccounted-for healthcare mobile devices expose a broader identity and workflow control problem, not just an asset management problem.

Why it matters: For IAM, NHI, and healthcare IT teams, the issue matters because device loss can trigger PHI exposure, credential misuse, workflow disruption, and reactive lock or wipe decisions.

By the numbers:

  • The average cost of replacing a healthcare device is $822.

Context

Healthcare mobile device loss is a governance problem as much as an inventory problem. In this article, mobile devices used for EHR access, medication administration, secure communication, and care coordination are shown to be frequently misplaced, left in patient rooms, or taken offsite and not returned.

The operational failure is fragmented ownership and visibility. When healthcare teams cannot reliably tell where a shared clinical device is, who is responsible for it, or whether it is in use, they lose control over access, workflow continuity, and compliance response at the same time.


Key questions

Q: What breaks when healthcare mobile devices have no clear owner?

A: When shared devices have no clear owner, accountability disappears across recovery, replacement, and security response. IT cannot tell whether a device is misplaced, abandoned, or simply undocumented, and clinicians have no reliable path for resolving access problems. That ambiguity drives hoarding, workarounds, and delayed containment decisions.

Q: Why do lost clinical devices create compliance and PHI risk even when encrypted?

A: Encryption helps, but it does not solve uncertainty about whether the device is still in use, where it is, or who can reach the data on it. If the organisation cannot verify device status quickly, it must assume exposure and may need to lock or wipe the device before it is recovered.

Q: What are the signs that device visibility is failing in a healthcare environment?

A: Common signs include stale inventory records, repeated reports of missing devices, clinicians hoarding shared hardware, and IT spending time proving whether a device is actually lost. When teams rely on manual searching or reactive replacement, visibility has already failed as a governance control.

Q: How should healthcare organisations secure shared mobile devices without slowing clinicians down?

A: Use individual identity, passwordless re-authentication, and strong session controls so staff can move quickly without sharing credentials or leaving devices signed in. The aim is to make access fast for legitimate users and hard to inherit accidentally. In healthcare, if the control adds friction but does not reduce shared access, it is not solving the real problem.


Technical breakdown

Why shared clinical devices become governance blind spots

Shared healthcare devices behave like operational endpoints with identity consequences. A tablet left in a room, a phone that never returns to a charging station, or a device taken to an offsite clinic becomes hard to distinguish from a legitimately active asset when inventory is incomplete or stale. The governance gap is not just physical loss. It is the inability to maintain a trustworthy relationship between the device, the user, and the clinical workflow it supports. That makes every downstream decision slower, from support triage to access containment.

Practical implication: treat shared mobile assets as governed access points, not just hardware to inventory.

How missing devices turn into identity and PHI risk

A lost device can expose protected health information when it still has access to applications, sessions, or cached data. Even when encryption is in place, uncertainty forces teams to act as if the device may be compromised, which can trigger remote lock or wipe actions before the device is recovered. In healthcare, that creates a difficult trade-off between data protection and operational continuity. The real weakness is not encryption alone, but the absence of reliable status and control signals that tell IT whether a device is truly missing, merely misplaced, or still in use.

Practical implication: pair encryption with device-state visibility so response actions are based on evidence, not assumption.

Why clinicians create workarounds when device access is unreliable

When devices are scarce or unpredictable, clinicians adapt. They may hoard devices, borrow from other units, share credentials, or bypass repeated login steps just to keep work moving. Those behaviours are understandable, but they weaken accountability and increase the chance of insecure access patterns spreading across the ward. In practice, device availability and access friction shape user behaviour as much as policy does. A broken workflow does not stay confined to operations. It becomes an access-governance problem because people will optimise for care delivery first and controls second.

Practical implication: reduce login and retrieval friction before informal sharing becomes the default operating model.


Threat narrative

Attacker objective: The objective is to use a missing or unaccounted-for clinical device as a path to patient data exposure, operational disruption, or both.

  1. Entry begins when a clinical mobile device is lost, misplaced, or taken offsite without reliable tracking.
  2. Credential and data exposure follow if the device remains able to reach patient systems or retains accessible information while its status is unknown.
  3. Escalation occurs when teams respond reactively with remote lock, wipe, or replacement because they cannot quickly verify the device's real location or ownership.
  4. Impact is PHI exposure, workflow disruption, and operational cost from lost productivity, replacement purchases, and compliance response.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Shared clinical devices create an identity boundary problem, not only an asset tracking problem. When a phone or tablet supports EHR access and secure communication, the question is no longer just where the device is. The question is whether access, ownership, and workflow state remain trustworthy when the asset is misplaced. That is an identity governance issue because the device has become part of the access path.

Device loss exposes a visibility gap that traditional mobile management does not close. Mobile device management can configure and secure endpoints, but it does not by itself answer whether a shared device is present, in use, idle, or missing. Without that context, teams are forced into reactive decisions. The practical implication is that inventory, usage, and identity context must be governed together.

Confidence in clinical access is the real control target. The article shows that clinicians do not need more devices so much as predictable availability of the right device at the right time. That means governance has to reduce hoarding, credential sharing, and workarounds that emerge when access is unreliable. The practitioner conclusion is that access reliability is a security control as much as an operations metric.

Identity and workflow controls fail together when shared devices lack accountable ownership. A device with no clear owner, stale inventory data, or no usage telemetry cannot support clean offboarding, reliable recovery, or defensible compliance action. This is where healthcare asset governance and IAM intersect: the organisation loses both operational control and the ability to explain who had access to what, and when.

Continuous visibility is the named control concept this article sharpens. The article's central lesson is that healthcare organisations need continuous device-state visibility across shared clinical assets, because reactive search-and-replace models only increase cost and uncertainty. When the environment cannot distinguish found, missing, and in-use devices, policy enforcement becomes guesswork. Practitioners should treat visibility as the foundation for every downstream control.

From our research library:

  • 60% of healthcare organisations do not assess a vendor's security before signing a contract that grants access to protected health information, according to Ponemon Institute's 2023 Third-Party Risk in Healthcare report.

What this signals

Continuous visibility is the real control objective: healthcare organisations need to know where shared devices are, who is using them, and whether they are still fit for clinical work. Without that, inventory management becomes reactive and every lost-device event turns into an access and workflow decision under uncertainty.

The operational lesson for identity teams is that device governance and access governance cannot be separated in clinical environments. If clinicians can only get to patient data by borrowing hardware, reusing sessions, or improvising around missing devices, the environment is already signalling that formal controls are too slow for frontline work.


For practitioners

  • Map shared clinical devices to accountable owners Assign a named operational owner for every shared phone, tablet, and clinical workstation so missing-device triage and recovery are not ambiguous.
  • Unify inventory with device-state telemetry Correlate inventory records with usage and location signals so IT can distinguish missing, idle, and actively used devices before taking containment action.
  • Reduce workaround-driven credential sharing Make application access fast enough that clinicians do not need to borrow devices or reuse credentials to complete charting, scanning, or messaging.
  • Set a decision rule for lock or wipe actions Define when a device moves from misplaced to untrusted so remote lock or wipe is based on status evidence rather than guesswork.
  • Tie procurement to utilisation evidence Use utilisation analytics before buying more devices so shortage assumptions do not turn into excess inventory and higher support burden.

Key takeaways

  • Lost healthcare devices are not just an IT nuisance. They create an identity and workflow control gap that can expose patient data and slow care delivery.
  • The article shows that the main weakness is not the hardware itself but the lack of reliable ownership, visibility, and accountability across shared clinical devices.
  • Healthcare teams should connect device inventory, access state, and recovery actions so lost-device response is based on evidence rather than guesswork.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingLost shared clinical devices are effectively assets that were never cleanly removed from service or accounted for.
NHI-05 — Overprivileged NHIShared devices with broad access can expose more PHI and workflow systems than they need to.
NHI-10 — Human Use of NHIClinicians sharing devices and credentials turns managed endpoints into informal access channels.
Recommendation — Track shared clinical devices through offboarding so missing assets are retired, recovered, or remediated before risk accumulates. Restrict shared-device access to the minimum clinical applications and data required for the task. Detect and remove human workarounds that turn shared devices into informal access paths.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centers on who can access patient systems when devices are lost or misused.
Recommendation — Review device-linked access permissions so lost assets cannot retain unnecessary entitlement paths.
CIS Controls v8CIS-5 — Account ManagementShared device access and clinician workarounds are an account-management problem as much as an asset problem.
Recommendation — Tie shared device workflows to account management controls so access remains attributable and revocable.

Key terms

  • Shared Clinical Device: A shared clinical device is a phone, tablet, or similar endpoint used by multiple staff members to support care delivery. In governance terms, it is an access-bearing asset because it can hold sessions, cached credentials, and application pathways that must be managed across shifts and locations.
  • Device State Visibility: Device state visibility is the ability to know whether an endpoint is in use, idle, missing, or out of scope for normal operations. For healthcare mobile fleets, this is the difference between reacting to a reported loss and making a defensible containment decision based on evidence.
  • Security Workaround: A security workaround is an informal method people use to get work done when approved access is too slow or inconvenient. Examples include shadow accounts, shared credentials, and unmanaged tools. Workarounds usually emerge from process failure, and they create blind spots that make governance, monitoring, and incident response harder.
  • Mobile Asset Governance: Mobile asset governance is the discipline of assigning ownership, inventory accuracy, lifecycle status, and usage oversight to portable devices. For healthcare teams, it connects endpoint management to identity and operational control so devices can be recovered, restricted, or retired with confidence.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 4, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org