A Practical Policy for Personal Phones in Care Settings

Walk down any hallway and you will see staff checking phones. Some of that is personal, and some of it is work: a quick text to a coworker, a photo of a skin condition for a nurse practitioner, a calendar check, a scheduling app, a call to a family member. Whether or not your organization has approved it, personal phones are already part of your operations.

A bring-your-own-device (BYOD) policy lets you set sensible rules instead of pretending the phones are not there. Here is how to write one that protects residents and respects staff.

Start by deciding what is allowed

Ask what staff actually need to do from their phones:

Receive schedule changes and shift alerts

Use multi-factor authentication apps

Access email or a messaging platform

Use a clinical communication app

Take photos or video for clinical documentation

Check non-sensitive tools such as training portals

Then decide for each task whether it will be allowed, allowed with conditions or prohibited. Photos of residents are often the most sensitive of these, and many organizations prohibit using personal cameras and provide a managed device or approved app instead.

The risks to address

Lost or stolen phones with resident information on them

Personal messaging apps that are not designed for protected health information

Unsecured backups to personal cloud accounts

Malicious apps and unsafe Wi-Fi

Family members or friends using the phone

Former employees who still have access after leaving

Photos that sync automatically to personal photo libraries

What a good policy includes

Scope and eligibility

Who may use a personal device for work, and which roles may access which systems from it.

Minimum security requirements

A passcode or biometric lock, with automatic screen lock

Device encryption, which is on by default for modern phones when a passcode is set

Operating system kept up to date

No jailbroken or rooted devices

Only approved apps for work data

Remote lock and wipe capability for work data

Approved tools

Name the specific apps staff may use for messaging, email and clinical communication. Explain that regular text messages and consumer chat apps are not approved for resident information unless configured with appropriate protections. HIPAA does not ban texting, but you need reasonable safeguards, a risk analysis and policies that govern it.

Separation of work and personal data

Use mobile application management or a work profile so work apps and data are separated from personal ones. This lets you remove work data from a phone without touching personal photos and messages, which also makes staff more comfortable agreeing to the policy.

Privacy for employees

Be clear about what you can and cannot see. Typically, an organization can see that a device is enrolled, its operating system and whether it meets requirements. It should not read personal messages or see personal photos. Stating that plainly builds trust.

Lost or stolen devices

Require staff to report a lost phone immediately, to a defined number or email, at any hour. Explain what will happen: the work profile or accounts will be wiped or disabled, and the incident will be assessed under your breach procedures.

Offboarding

State that work data and access are removed when employment ends, and that staff must not keep resident information on personal devices.

Photography and recording

Spell out the rules for photographing residents, equipment or documents. Reference resident privacy and consent requirements, and name the approved method for clinical photos.

Provide alternatives

Not every employee has a smartphone, and not everyone wants work apps on their personal one. Offer a facility-owned device pool or hardware tokens for MFA, so the policy never becomes a condition that excludes people or pushes them into workarounds. Consider whether you will reimburse any costs.

Rolling it out

Draft the policy with input from nursing, HR, compliance and IT.

Have legal counsel review it, particularly for employment matters.

Pilot with one department.

Train staff in plain language, using examples such as, "Do not text a resident's name and condition through a regular messaging app."

Collect signed acknowledgments.

Review annually and after incidents.

Enforcement

Policies that are never applied lose force. Define what happens when someone violates the rules, and apply the consequences consistently. Focus first on coaching and fixing the underlying need that led to the workaround.

Getting started with UnityCare IT

We help organizations set up mobile device management, choose secure messaging tools and draft practical BYOD policies for clinical teams. If you are not sure how staff currently use personal phones, a short survey and review is a good first step, and we can help you design it.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172