Mobile Device Management: Enrolling Phones and Tablets Step by Step

Phones and tablets are now part of daily work in senior living and healthcare. Nurses use tablets for charting, managers carry phones with email and the EHR app, and maintenance staff photograph work orders. Each of those devices can hold resident information or sign in to systems that do. If one is lost, stolen or left behind, you need a way to protect the data without driving to the device.

Mobile device management, or MDM, is the tool that does this. This walkthrough covers the basics for facility-owned devices and what to decide before you begin.

What MDM does

MDM software lets IT configure and control devices remotely. Typical capabilities include:

Enforcing passcodes and screen lock.

Requiring encryption.

Installing, blocking and removing apps.

Pushing Wi-Fi and email settings.

Locating, locking or erasing a lost device.

Reporting what is installed and whether the device is up to date.

Features vary by product and by device platform, so confirm what your tool supports.

Before you enroll: decisions to make

Ownership model. This guide assumes facility-owned devices. Personal phones used for work raise privacy questions and need a separate, lighter policy.

Who gets a device. List roles and units, and decide whether devices are assigned to a person or shared on a shift or cart.

Standard settings. Define passcode length, lock timeout, allowed apps and what happens if a device falls out of compliance.

Acceptable use policy. Staff should know what is permitted, what is monitored and what happens if a device is lost.

Inventory. Record serial numbers, device types and assignments.

Step-by-step enrollment

Step 1: Prepare your accounts

Set up your MDM administrator accounts with multi-factor authentication. Apple and Google platforms offer business enrollment programs that tie devices to your organization when you buy them, which makes automatic setup possible. Ask your reseller or IT provider whether your devices can be registered this way.

Step 2: Create configuration profiles

Build a baseline profile that includes:

A required passcode and short auto-lock.

Encryption turned on.

Corporate Wi-Fi settings.

Email and calendar configuration.

Restrictions you want, such as disabling backups to personal cloud accounts.

Create variations for different groups, such as nurse tablets versus manager phones.

Step 3: Define app control

Decide which apps are required and which are blocked. Push required apps automatically, such as the EHR app, secure messaging and your authenticator. Allow an approved list of other tools, and block or limit the app store for the rest. For shared tablets, consider a locked mode that runs only approved apps.

Step 4: Enroll devices

For each device:

Power it on and connect to a network.

Follow the enrollment prompts, or scan the enrollment code your IT team provides.

Confirm that the profiles and apps install.

Sign in with the user's work account and complete multi-factor setup.

Verify the device appears in the MDM console with the correct owner.

Do the first few devices as a pilot with a small group, and gather feedback before wider rollout.

Step 5: Test remote lock and wipe

Before relying on it, test it. Use a spare device to confirm that remote lock works, and that a wipe returns the device to its original state. Know the difference between wiping the whole device, which is appropriate for a facility-owned phone, and removing only company data, which is more appropriate for personal devices.

Step 6: Train staff

Explain what the tools do, how to report a lost device immediately and what not to do, such as removing the management profile. Fast reporting matters more than any setting.

Day-to-day management

Review compliance reports, and follow up on devices that have not checked in.

Keep operating systems and apps updated.

Collect and wipe devices when staff leave, and reassign them.

Retire old devices securely.

Keep the inventory current.

Lost or stolen device checklist

Staff member reports the loss to their supervisor and IT.

IT locks the device and tries to locate it.

If it cannot be recovered quickly, wipe it.

Change passwords and revoke sessions for the associated account.

Document the incident, since it may count in your risk analysis and, if unencrypted protected information was involved, may require breach assessment.

UnityCare IT helps healthcare and senior-living providers choose, deploy and manage MDM for facility-owned phones and tablets across Oklahoma, Texas and Arkansas. We can run the pilot with you and keep policies current after rollout.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172