In 2017, a Lifespan Health System employee left a MacBook in a car. It was stolen. Three years later, the health system wrote a check for $1,040,000.
The laptop belonged to an employee of Lifespan, a Rhode Island-based hospital system. It was taken from an unattended vehicle. The MacBook was not encrypted. There was no pre-boot password, no hardware lock, nothing standing between the thief and the data stored on the drive.
On that drive: the protected health information of nearly 20,000 patients. Names, medical record numbers, medications, diagnoses, and other personal details, all readable to whoever picked up that laptop.
What the investigation found
Lifespan reported the breach to HHS as required under HIPAA. The Office for Civil Rights opened an investigation. What they found was not a sophisticated attack or a technical failure. It was a laptop that was not encrypted, left in a place where it could be taken.
The OCR settlement, reached in 2020, came to $1,040,000. It was the first seven-figure HIPAA settlement of that year. Along with the financial penalty, Lifespan agreed to a corrective action plan covering device encryption policies, workforce training, and a review of its hardware inventory.
The core finding: Lifespan had failed to implement the encryption controls that HIPAA requires when a risk analysis identifies portable devices as a threat. A stolen, unencrypted device carrying patient data is not a grey area under the regulation.
What would have prevented it
The laptop left the building. That part could not be controlled. What could have been controlled was what happened to the data on the drive once it did.
The Lifespan case is a reminder that device encryption is not optional for organizations handling patient data, it is a HIPAA requirement. For Windows-based endpoints and portable storage, hardware-level encryption at the drive provides the strongest form of that protection. It operates independently of the operating system and does not depend on the device being online or remotely managed. The drive stays locked without the right credentials at power-on, regardless of who has physical access to the machine.
Opal Lock by Fidelity Height enables pre-boot authentication and hardware encryption management on compatible TCG Opal and Pyrite self-encrypting drives on Windows. For organizations managing Windows laptops and portable drives that handle sensitive data, it provides the layer of protection that makes a stolen device a non-event rather than a seven-figure settlement.
A laptop stolen from a car becomes an expensive lesson without it. With it, it becomes a non-event.
Compare Opal Lock editions at fidelityheight.com/shops/
Sources: HHS.gov | Healthcare Dive | HIPAA Journal
Ready to buy
Secure your drives. Buy your license now.
Activate hardware encryption on compatible Opal drives in minutes. Select your edition and complete purchase below.