Medical and IoT Devices on Your Network: Finding the Weak Spots

A modern care facility is full of connected devices that no one thinks of as computers. Nurse call stations, door locks, thermostats, cameras, smart televisions, wireless medication carts, vital signs monitors, even refrigerators that log temperatures. Each one has software, an address on your network, and sometimes a default password nobody changed.

These Internet of Things and medical devices are a real security challenge, because they often cannot be patched on your schedule, are managed by vendors, and do not run standard security software. This post offers a practical way to get control of them.

Why these devices are risky

Long lifespans: equipment may stay in service for ten years or more, long after software support ends

Limited patching: updates may require vendor involvement, downtime or revalidation

Default or shared credentials, sometimes printed in manuals found online

Poor visibility: they do not appear on the usual workstation reports

Vendor access: remote support connections may be permanently open

Clinical priority: staff understandably will not accept a device being shut off for security reasons if it affects care

The HHS 405(d) program's Health Industry Cybersecurity Practices (HICP) specifically addresses medical device security as one of its main areas of focus, and the FDA has issued guidance on cybersecurity for manufacturers. Those resources are worth reading for background.

Step 1: Build an inventory

You cannot manage what you cannot see. Combine several sources:

Walk the building with a clipboard or tablet, noting each connected device

Review your network switches and wireless controllers for devices that are connected

Ask department heads and vendors what is installed

Use a network discovery tool, if you have one, to detect devices automatically

For each device record: type, manufacturer, model, location, owner, network address, software version, whether it stores or transmits protected health information, and the vendor contact.

Step 2: Rank by risk

Consider two questions for each device. How much harm could result if it were compromised or unavailable, and how exposed is it? A camera on an isolated network is a lower risk than a device with an open remote connection to the internet. Devices that touch clinical care or ePHI go to the top of the list.

Step 3: Reduce the exposure

Segment

Place connected devices on their own network zones, with strict rules about what they can reach. Most smart TVs and cameras have no reason to talk to your EHR server.

Change defaults

Replace factory passwords with unique, strong ones, stored in a secure password manager. Disable unused services and features.

Limit internet access

Allow only the destinations a device genuinely needs, such as a vendor's update server. Block everything else where possible.

Control vendor access

Require named accounts, multi-factor authentication and time-limited access for remote support. Avoid always-on remote tools.

Patch when you can

Ask manufacturers about update schedules and security notifications, and apply updates in a planned window with clinical staff informed.

Plan for end of life

If a device can no longer be updated, decide whether to replace it, isolate it more tightly, or accept the risk with documented reasons.

Step 4: Write it into contracts

When buying new equipment, ask about security features, how long updates will be provided, how vulnerabilities are reported, and what support access is required. Include these items in purchasing checklists, so they are considered before the equipment is installed.

Step 5: Monitor and respond

Watch for new devices appearing, devices communicating to unusual destinations and failed login attempts. Include connected devices in your incident response plan, including how to isolate one safely without interrupting care.

Starting where you are

Even a first inventory and a basic network split can significantly reduce risk. UnityCare IT can help discover connected devices, design segmentation and coordinate with equipment vendors so clinical operations stay protected. Contact us to schedule a walk-through.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172