Phones and tablets are now part of daily care. Nurses photograph wound progress, therapists use tablets in rooms, physicians check results from their phones and administrators read email on the go. These devices speed up communication, but they also carry protected health information outside the building, where they can be lost, stolen or compromised.
A good mobile device policy balances usability and protection. Below are the key decisions to make and put in writing.
The organization buys, configures and manages the device. This gives the most control. You can enforce encryption, install approved apps, wipe the device remotely and restrict personal use. The tradeoffs are cost and the need to track and support the equipment.
Staff use personal phones for work. This is cheaper and convenient, but harder to secure. If you allow it, consider limiting what can happen on personal devices, such as using only approved apps in a managed container, and be clear about what you can and cannot do to the device, including remote wipe of work data.
Many organizations issue shared tablets for clinical documentation and allow personal phones for email and scheduling through a managed app. Choose a model, communicate it plainly and apply it consistently.
For any device that can access PHI, require:
A screen lock with a passcode or biometric, with a short inactivity timeout
Device encryption, which is on by default for most modern phones when a passcode is set
Up-to-date operating system versions, and a rule that outdated devices lose access
Mobile device management or mobile application management software to enforce settings
The ability to remotely lock or wipe a lost device, or at minimum the work data
Multi-factor authentication for apps that touch PHI
Prohibition on jailbroken or rooted devices
Provide approved apps for messaging, photos and documentation, and say which are not allowed
Do not store PHI in personal photo galleries, notes apps or unmanaged cloud storage
Disable automatic backup of work data to personal cloud accounts
Use apps that capture photos directly into the medical record without saving them to the device camera roll
Restrict copy and paste between managed and personal apps where practical
Resident photos deserve special attention. Staff should know when consent is required and that photos for non-treatment purposes, such as social media, have separate rules and need proper authorization.
Standard text messages are not encrypted in a way that meets many organizations' security expectations, and they sit on carriers' systems and personal phones. Offer an approved secure messaging platform with message expiration, access controls and audit logs, and set rules about what can be sent. The HIPAA Security Rule does not ban texting, but it requires reasonable safeguards, and many facilities choose to prohibit unprotected texting of resident information.
The first hour matters.
Staff must report lost or stolen devices immediately, without fear of blame
IT can lock or wipe the device and revoke access tokens
Document whether the device was encrypted and protected by a passcode, which helps determine whether a breach notification obligation exists
Update the device inventory and log the incident
When staff leave, remove work apps and data from personal devices, collect facility-owned equipment and disable accounts the same day. Include this step in your offboarding checklist.
Train staff to recognize phishing by text message and fake app update notices
Use only official app stores, and block sideloading
Be careful on public Wi-Fi, and consider always-on VPN for sensitive work
Keep Bluetooth off when not needed in public areas
Keep the written policy to a few pages. Include it in orientation, require signed acknowledgment and review it annually. Test understanding with scenarios, such as what to do if a resident's family asks for a photo or a physician sends a message by personal text.
Periodically review the list of enrolled devices, remove inactive ones and confirm compliance with minimum requirements. Include mobile devices in your HIPAA risk analysis.
UnityCare IT helps healthcare organizations select and deploy mobile device management, set up secure messaging and write practical policies for clinical staff. If you are deciding between owned devices and bring-your-own, we can help you weigh the options.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034