When a school device with student data is lost or stolen, report it immediately through the school's safety and security routes and avoid personal recovery efforts that create danger. Record the device, assigned user, last known time and place, data types, encryption and access protections, and affected services. The school should control remote actions, evidence preservation, incident classification, required notices, record correction, replacement access, and verified recovery.

Report the device through two accountable routes

For Rina, contact the school's security or IT incident route and the site safety or administrative owner. Preserve the asset label, assigned user, last known location and time, network state, applications, and data categories. Use emergency or law-enforcement routes only as directed by immediate safety and applicable policy.

Leave remote response to authorized staff

The school decides whether to lock, locate, revoke, wipe, preserve, or replace a managed device under its incident plan. Families should avoid tracking or confronting a possible possessor. Ask which evidence will be retained before a destructive action and which records may have synchronized elsewhere.

Protect continuity while the device is unavailable

Provide an approved replacement or offline path for Rina's AAC, communication profile, schedule, health and safety information, assignments, and family contact. Verify current authorized staff can access what they need. Avoid moving the full data set onto an unmanaged personal device as a quick workaround.

Review exposure and recovery separately

Track physical recovery, account containment, data-exposure classification, notice review, service restoration, and device return as different states. A recovered tablet may still require log review and credential changes. A wiped device may still involve data that synchronized, downloaded, or appeared in notifications.

Prepare Rina's privacy-incident review

Bring Rina's lost school-device incident file, the school's current privacy and security contacts, annual FERPA notice, incident messages, minimal evidence, record and account categories, access needs, service-continuity concerns, and a short decision list. Also bring school and vendor responses, correction history, complaint questions, current deadlines, and requested outcomes. End with owners, dates, and a representative validation test.

Build Rina's source-attributed incident record

Create a restricted lost school-device incident file for Rina's device, asset identifier, assigned user, last known location, data category, protection, remote action, safety, service continuity, notice, recovery, and validation. Give every field a source, version, holder, sender, recipient, time, authority, status, owner, next action, due date, correction, and closure evidence. Attribute student communication, family report, school statement, vendor notice, system evidence, clinical information, and legal conclusion separately.

Protect Rina's safety, access, and dignity

Give Rina and family participants understandable, accessible information, privacy, realistic update times, and a reliable way to ask questions, disagree, correct, accept, decline, pause, and request help. Keep AAC, interpreters, schoolwork, health and safety information, mobility, food, water, bathroom access, prescribed care, rest, and emergency help available during the response.

Ask eight incident-response questions for Rina

Use these questions in the lost school-device incident file:

  • Which alert, event, record, account, device, product, holder, sender, recipient, and time apply?
  • What is known, unknown, disputed, contained, corrected, or still exposed?
  • Which FERPA, IDEA, HIPAA, state, school, contract, security, complaint, or other source governs the step?
  • Who may classify, contain, investigate, communicate, notify, correct, restore, and close each field?
  • Which immediate safety, identity, health, disability, bullying, financial, or access risk needs action?
  • What did Rina communicate directly, and what did family, school, vendor, or a professional report separately?
  • Which evidence supports the exposure, containment, notice, correction, continuity, or recovery state?
  • Which representative test will show that the repaired path works?

Classify fields as complete, failed, pending, declined, disputed, false positive, suspected, confirmed, contained, superseded, or inapplicable with a reason.

A fictional school-data incident example for Rina

Rina is fictional. A staff tablet used for student schedules, communication supports, and emergency information cannot be located. Reviewers freeze 34 device, user, data, protection, location, response, continuity, and recovery fields and complete 23 of 34, or 67.6%, by the checkpoint. A missing event, record, holder, recipient, data, exposure, containment, account, communication, correction, continuity, or validation field remains in Rina's denominator with an owner, age, and next action.

The lost school-device incident file measures evidence completion. Legal compliance, notification duty, security effectiveness, service quality, student understanding, harm, family experience, and recovery remain separate questions. Concurrent changes limit causal conclusions.

Use compatible incident denominators for Rina

For Rina's lost school-device incident file, report alerts triaged divided by alerts due; confirmed incidents contained divided by confirmed incidents due; affected accounts secured divided by accounts due; required communications completed divided by communications due; affected records corrected divided by records due; and recovery tests passed divided by tests attempted.

Publish raw counts with percentages and age every open item. Keep discovery, triage, classification, containment, evidence preservation, exposure analysis, notice review, communication, correction, continuity, complaint, and recovery as distinct measures.

Apply the federal privacy and security boundaries for Rina

For Rina, current 34 CFR Part 99 governs FERPA within its stated scope, and the Education Department's FERPA hub provides public guidance. The Department's data-security page explains that FERPA does not prescribe specific security controls, while security failures can create privacy risk. Its older breach checklist is general best-practice guidance, and current scenario trainings support planning exercises.

No cited federal source creates one universal family notification rule for every school data incident. Verify current state, district, vendor, contract, insurance, law-enforcement, record-holder, and student-specific duties.

Apply complaint, health, and professional boundaries for Rina

For a lost or stolen device, keep the discovery date and response timeline. The current SPPO complaint page describes a federal complaint route and its 180-day timeliness rule; IdentityTheft.gov supplies a recovery-plan route when the exposed data creates identity-theft facts. Use federal school health-record guidance and joint FERPA-HIPAA guidance to identify the record holder. Arrange replacement AAC access if the device supported communication. The BACB Ethics Code and CASP overview do not expand beyond their stated scopes.

Close Rina's loop with an incident test

Ask Rina and the relevant family participant to review the outcome through their usual language and communication methods. Test the repaired recipient list, account, device control, public-link permission, vendor path, family communication, record correction, complaint file, service-continuity route, or recovery evidence suited to the event. The defined review question for Rina is school device with student data lost or stolen. Preserve every mismatch with an owner, due date, and next step.

Before closure, record what the school confirmed, what remains unknown, which source governed notice, which student access or service depended on the affected system, and how the response changed the source control. For Rina's incident review, keep incident state, family communication, record correction, safety support, and technical recovery separate. Reopen the file after a failed test, new recipient, changed exposure window, recurring alert, or inaccurate notice. The tracked topic remains school device with student data lost or stolen.

Related resources

Sources

Finni resources

Ready for the next step?

Find ABA care near you