A modern care facility is full of connected devices that no one thinks of as computers. Nurse call stations, door locks, thermostats, cameras, smart televisions, wireless medication carts, vital signs monitors, even refrigerators that log temperatures. Each one has software, an address on your network, and sometimes a default password nobody changed.
These Internet of Things and medical devices are a real security challenge, because they often cannot be patched on your schedule, are managed by vendors, and do not run standard security software. This post offers a practical way to get control of them.
Long lifespans: equipment may stay in service for ten years or more, long after software support ends
Limited patching: updates may require vendor involvement, downtime or revalidation
Default or shared credentials, sometimes printed in manuals found online
Poor visibility: they do not appear on the usual workstation reports
Vendor access: remote support connections may be permanently open
Clinical priority: staff understandably will not accept a device being shut off for security reasons if it affects care
The HHS 405(d) program's Health Industry Cybersecurity Practices (HICP) specifically addresses medical device security as one of its main areas of focus, and the FDA has issued guidance on cybersecurity for manufacturers. Those resources are worth reading for background.
You cannot manage what you cannot see. Combine several sources:
Walk the building with a clipboard or tablet, noting each connected device
Review your network switches and wireless controllers for devices that are connected
Ask department heads and vendors what is installed
Use a network discovery tool, if you have one, to detect devices automatically
For each device record: type, manufacturer, model, location, owner, network address, software version, whether it stores or transmits protected health information, and the vendor contact.
Consider two questions for each device. How much harm could result if it were compromised or unavailable, and how exposed is it? A camera on an isolated network is a lower risk than a device with an open remote connection to the internet. Devices that touch clinical care or ePHI go to the top of the list.
Place connected devices on their own network zones, with strict rules about what they can reach. Most smart TVs and cameras have no reason to talk to your EHR server.
Replace factory passwords with unique, strong ones, stored in a secure password manager. Disable unused services and features.
Allow only the destinations a device genuinely needs, such as a vendor's update server. Block everything else where possible.
Require named accounts, multi-factor authentication and time-limited access for remote support. Avoid always-on remote tools.
Ask manufacturers about update schedules and security notifications, and apply updates in a planned window with clinical staff informed.
If a device can no longer be updated, decide whether to replace it, isolate it more tightly, or accept the risk with documented reasons.
When buying new equipment, ask about security features, how long updates will be provided, how vulnerabilities are reported, and what support access is required. Include these items in purchasing checklists, so they are considered before the equipment is installed.
Watch for new devices appearing, devices communicating to unusual destinations and failed login attempts. Include connected devices in your incident response plan, including how to isolate one safely without interrupting care.
Even a first inventory and a basic network split can significantly reduce risk. UnityCare IT can help discover connected devices, design segmentation and coordinate with equipment vendors so clinical operations stay protected. Contact us to schedule a walk-through.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172