Walk down any hallway and you will see staff checking phones. Some of that is personal, and some of it is work: a quick text to a coworker, a photo of a skin condition for a nurse practitioner, a calendar check, a scheduling app, a call to a family member. Whether or not your organization has approved it, personal phones are already part of your operations.
A bring-your-own-device (BYOD) policy lets you set sensible rules instead of pretending the phones are not there. Here is how to write one that protects residents and respects staff.
Ask what staff actually need to do from their phones:
Receive schedule changes and shift alerts
Use multi-factor authentication apps
Access email or a messaging platform
Use a clinical communication app
Take photos or video for clinical documentation
Check non-sensitive tools such as training portals
Then decide for each task whether it will be allowed, allowed with conditions or prohibited. Photos of residents are often the most sensitive of these, and many organizations prohibit using personal cameras and provide a managed device or approved app instead.
Lost or stolen phones with resident information on them
Personal messaging apps that are not designed for protected health information
Unsecured backups to personal cloud accounts
Malicious apps and unsafe Wi-Fi
Family members or friends using the phone
Former employees who still have access after leaving
Photos that sync automatically to personal photo libraries
Who may use a personal device for work, and which roles may access which systems from it.
A passcode or biometric lock, with automatic screen lock
Device encryption, which is on by default for modern phones when a passcode is set
Operating system kept up to date
No jailbroken or rooted devices
Only approved apps for work data
Remote lock and wipe capability for work data
Name the specific apps staff may use for messaging, email and clinical communication. Explain that regular text messages and consumer chat apps are not approved for resident information unless configured with appropriate protections. HIPAA does not ban texting, but you need reasonable safeguards, a risk analysis and policies that govern it.
Use mobile application management or a work profile so work apps and data are separated from personal ones. This lets you remove work data from a phone without touching personal photos and messages, which also makes staff more comfortable agreeing to the policy.
Be clear about what you can and cannot see. Typically, an organization can see that a device is enrolled, its operating system and whether it meets requirements. It should not read personal messages or see personal photos. Stating that plainly builds trust.
Require staff to report a lost phone immediately, to a defined number or email, at any hour. Explain what will happen: the work profile or accounts will be wiped or disabled, and the incident will be assessed under your breach procedures.
State that work data and access are removed when employment ends, and that staff must not keep resident information on personal devices.
Spell out the rules for photographing residents, equipment or documents. Reference resident privacy and consent requirements, and name the approved method for clinical photos.
Not every employee has a smartphone, and not everyone wants work apps on their personal one. Offer a facility-owned device pool or hardware tokens for MFA, so the policy never becomes a condition that excludes people or pushes them into workarounds. Consider whether you will reimburse any costs.
Draft the policy with input from nursing, HR, compliance and IT.
Have legal counsel review it, particularly for employment matters.
Pilot with one department.
Train staff in plain language, using examples such as, "Do not text a resident's name and condition through a regular messaging app."
Collect signed acknowledgments.
Review annually and after incidents.
Policies that are never applied lose force. Define what happens when someone violates the rules, and apply the consequences consistently. Focus first on coaching and fixing the underlying need that led to the workaround.
We help organizations set up mobile device management, choose secure messaging tools and draft practical BYOD policies for clinical teams. If you are not sure how staff currently use personal phones, a short survey and review is a good first step, and we can help you design it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172