Connected Medical and IoT Devices: Build an Inventory First

Walk the halls of a modern care facility and count the things with a network connection. Computers and tablets are the obvious ones. But there are also vital signs monitors, medication dispensing cabinets, infusion pumps, security cameras, door controllers, nurse call panels, thermostats, smart televisions in resident rooms, printers, label makers and time clocks. Many were installed by different vendors, at different times, with little coordination.

These devices often cannot run standard security software, may use old operating systems and sometimes ship with default passwords. Attackers look for them precisely because they are easy to overlook. You cannot protect what you have not counted, so the first step is an inventory.

Why connected devices need special attention

Many are hard to patch, because updates may require vendor involvement, downtime or revalidation

Medical devices can have long lifespans, so software can be years out of date

Default or shared credentials are common

Vendors often have remote access for support

A compromised device can be a foothold into the rest of the network

Some devices affect resident safety directly, so availability matters as much as confidentiality

The HHS 405(d) program's Health Industry Cybersecurity Practices recognizes medical device security as one of its core areas of focus for healthcare organizations of all sizes.

Step 1: Discover what is on the network

Use several methods together.

Review the list of devices that appear on your switches and wireless controllers

Use network discovery tools to identify device types and manufacturers

Walk the facility with a floor plan and check units, nurse stations, therapy areas, kitchens and maintenance rooms

Review purchasing records, vendor contracts and service agreements

Ask department heads what has been installed, including items bought outside of IT

Expect surprises, such as an old device still connected after replacement or a vendor-installed gateway nobody remembered.

Step 2: Record the right details

For each device, collect:

Type, manufacturer and model

Location and the department responsible

Network address and the network zone it sits in

Operating system or firmware version, if known

Whether it stores or transmits PHI

Vendor contact and support status

How remote support works, if at all

Whether it uses default credentials

Whether it is critical to resident safety

A spreadsheet is a fine starting point. Keep it current by adding an inventory step to purchasing and installation procedures.

Step 3: Rank by risk

Give each device a simple rating based on:

How much harm would result if it failed or were manipulated

Whether it holds sensitive data

How exposed it is to the internet or other networks

Whether it can be patched or is past end of support

Focus first on high-impact devices that are exposed or unsupported.

Step 4: Apply practical safeguards

Separate them

Place devices on dedicated network segments, with firewall rules that allow only the traffic they need. A camera system should not be able to reach the EHR.

Change defaults

Replace default usernames and passwords with unique, strong ones, and store them in a secure location. Disable unnecessary services and features.

Limit remote access

Require vendor access to be authenticated, logged and ideally enabled only for scheduled sessions.

Patch where you can

Ask vendors for security update schedules and apply them in coordination with clinical staff. Add patching to maintenance agreements.

Monitor

Watch for unusual traffic from devices, such as an infusion pump suddenly contacting the internet.

Plan for end of life

Track when each device will lose support and budget for replacement. If it must stay in service, document compensating controls.

Step 5: Involve vendors and clinicians

Before making network changes that could affect a medical device, talk to the manufacturer and the clinical engineering or nursing leaders responsible for it. Some devices have strict network requirements. Changes should be scheduled to avoid disrupting care.

When buying new devices, ask security questions up front:

How are security updates delivered, and for how long?

Does the device support unique credentials and encryption?

Is there a software bill of materials, listing components?

How do you handle vulnerability reports?

What network access does the device need?

Document it in your risk analysis

Connected devices that hold or transmit ePHI belong in your HIPAA risk analysis. Your inventory, risk ratings and safeguards give you evidence that you looked at the issue and made reasoned decisions.

Where to start this week

Pick one unit and count every connected device. Compare it with what your network reports. The difference tells you how much work remains. UnityCare IT assists healthcare and senior-living organizations with device discovery, network segmentation and risk ranking, and can help you build an inventory that stays current.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172