Hardening Checklist for a New Computer Before It Reaches the Floor

A new computer arrives in a box with default settings designed for convenience, not for a facility that handles protected health information. If it goes straight from the box to the nurses' station, it carries every weak default with it. A short, repeatable hardening checklist, applied before any workstation enters service, is one of the most effective and least expensive security measures an organization can adopt.

Hardening simply means reducing the ways a device can be attacked by removing what is unnecessary and tightening what remains. The list below is a practical baseline. Adapt it to your environment and keep it as a written standard.

Before you begin

Use a clean, trusted operating system image or a vendor-provided setup, not whatever came preinstalled with extra trial software. Work on a secured network, and record the device in your asset inventory with its serial number, model, assigned location and owner.

The checklist

1. Operating system and firmware

Install all available operating system updates before first use.

Update the BIOS or firmware to a current vendor release.

Confirm the operating system version is still supported by its vendor.

Enable automatic updates with sensible restart windows outside peak care hours.

2. Disk encryption

Turn on full-disk encryption.

Store recovery keys in a secure, centrally managed location, not on the device.

Enable a secure boot setting if available.

3. Accounts and access

Disable or remove default and built-in accounts that are not needed.

Create a unique administrator account for IT and give daily users standard, non-administrator accounts.

Require strong authentication, with multi-factor authentication for any account that can reach sensitive systems.

Set automatic screen lock after a short idle period.

Join the device to your managed directory so policies apply.

4. Remove what you do not need

Uninstall trial software, games and unnecessary vendor utilities.

Disable unused services and features, such as file sharing if the device does not need it.

Turn off remote access tools unless specifically required, and restrict them if they are.

5. Endpoint protection

Install managed antivirus or endpoint detection software and confirm it reports to your console.

Turn on the built-in firewall and block inbound connections by default.

Enable reputation-based protections the operating system offers.

6. Browser and email

Install your approved browser and set it to update automatically.

Configure a safe default homepage and block risky extensions.

Enable safe-browsing and phishing protection features.

Sign in only to organizational accounts.

7. Peripherals and removable media

Restrict unapproved USB storage.

Disable autorun features.

Install printers and scanners from approved drivers.

8. Network settings

Connect to the correct network segment for the device's role, keeping clinical devices separate from guest traffic.

Disable unneeded wireless features such as automatic connection to open networks.

Set up wired connections for fixed workstations where possible.

9. Logging and monitoring

Enable security event logging.

Confirm the device appears in your patching, backup and monitoring tools.

10. Backup and recovery

Decide whether the device stores any data locally. For most, the answer should be no, with files in protected cloud or server storage.

If local data exists, include it in backups.

Special cases

Shared workstations

Computers on units used by many staff members need quick sign-in, automatic sign-out and restricted settings so a locked-down profile cannot be altered. Never leave a session logged in permanently as a shortcut.

Carts and tablets

Mobile devices need screen locks, remote wipe capability and tracking in case they are lost.

Verify and document

After configuration, run through the checklist a second time or have another person check it. Record the date, the technician and any exceptions. A short sign-off sheet or an entry in your management system creates evidence that your standard was applied, which supports HIPAA documentation requirements.

Keep the standard alive

Review the checklist every six months and after major operating system changes.

Reference recognized guidance, such as the Center for Internet Security benchmarks, when updating it.

Audit a sample of devices each quarter against the standard.

Treat exceptions as temporary and track them.

Standardize with help

UnityCare IT builds and maintains workstation standards for healthcare and senior-living clients, using automated deployment so each machine leaves our bench the same way. If your new computers are currently set up by whoever is available, a written baseline is a good first improvement.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172