Walk the halls of a modern care facility and count the things with a network connection. Computers and tablets are the obvious ones. But there are also vital signs monitors, medication dispensing cabinets, infusion pumps, security cameras, door controllers, nurse call panels, thermostats, smart televisions in resident rooms, printers, label makers and time clocks. Many were installed by different vendors, at different times, with little coordination.
These devices often cannot run standard security software, may use old operating systems and sometimes ship with default passwords. Attackers look for them precisely because they are easy to overlook. You cannot protect what you have not counted, so the first step is an inventory.
Many are hard to patch, because updates may require vendor involvement, downtime or revalidation
Medical devices can have long lifespans, so software can be years out of date
Default or shared credentials are common
Vendors often have remote access for support
A compromised device can be a foothold into the rest of the network
Some devices affect resident safety directly, so availability matters as much as confidentiality
The HHS 405(d) program's Health Industry Cybersecurity Practices recognizes medical device security as one of its core areas of focus for healthcare organizations of all sizes.
Use several methods together.
Review the list of devices that appear on your switches and wireless controllers
Use network discovery tools to identify device types and manufacturers
Walk the facility with a floor plan and check units, nurse stations, therapy areas, kitchens and maintenance rooms
Review purchasing records, vendor contracts and service agreements
Ask department heads what has been installed, including items bought outside of IT
Expect surprises, such as an old device still connected after replacement or a vendor-installed gateway nobody remembered.
For each device, collect:
Type, manufacturer and model
Location and the department responsible
Network address and the network zone it sits in
Operating system or firmware version, if known
Whether it stores or transmits PHI
Vendor contact and support status
How remote support works, if at all
Whether it uses default credentials
Whether it is critical to resident safety
A spreadsheet is a fine starting point. Keep it current by adding an inventory step to purchasing and installation procedures.
Give each device a simple rating based on:
How much harm would result if it failed or were manipulated
Whether it holds sensitive data
How exposed it is to the internet or other networks
Whether it can be patched or is past end of support
Focus first on high-impact devices that are exposed or unsupported.
Place devices on dedicated network segments, with firewall rules that allow only the traffic they need. A camera system should not be able to reach the EHR.
Replace default usernames and passwords with unique, strong ones, and store them in a secure location. Disable unnecessary services and features.
Require vendor access to be authenticated, logged and ideally enabled only for scheduled sessions.
Ask vendors for security update schedules and apply them in coordination with clinical staff. Add patching to maintenance agreements.
Watch for unusual traffic from devices, such as an infusion pump suddenly contacting the internet.
Track when each device will lose support and budget for replacement. If it must stay in service, document compensating controls.
Before making network changes that could affect a medical device, talk to the manufacturer and the clinical engineering or nursing leaders responsible for it. Some devices have strict network requirements. Changes should be scheduled to avoid disrupting care.
When buying new devices, ask security questions up front:
How are security updates delivered, and for how long?
Does the device support unique credentials and encryption?
Is there a software bill of materials, listing components?
How do you handle vulnerability reports?
What network access does the device need?
Connected devices that hold or transmit ePHI belong in your HIPAA risk analysis. Your inventory, risk ratings and safeguards give you evidence that you looked at the issue and made reasoned decisions.
Pick one unit and count every connected device. Compare it with what your network reports. The difference tells you how much work remains. UnityCare IT assists healthcare and senior-living organizations with device discovery, network segmentation and risk ranking, and can help you build an inventory that stays current.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172