Tablets at the nurses' station, smartphones carried by aides, therapists charting on the go: mobile devices are now a normal part of care delivery. They are convenient, fast and easy to lose. A single phone left in a car or a tablet dropped in a hallway can hold email, photos, messages and access to systems that contain protected health information.
Securing mobile devices does not require locking everything down so tightly that staff cannot work. It requires a few clear decisions.
You control the configuration, and they can be wiped or retired. This is the safest option for devices that handle PHI regularly.
Convenient and cheaper, but riskier. If you allow personal phones to access work email or clinical applications, you need rules, and staff need to understand them.
Tablets shared across shifts need individual logins to the applications, and sessions that time out quickly.
Write a policy that states which categories are permitted, for what purposes and under what conditions.
Require a passcode of reasonable length, plus automatic locking after a short idle period. Fingerprint or face unlock is acceptable for convenience when combined with a passcode.
Current iPhones and Android phones encrypt storage once a passcode is set. Confirm through your management tool.
Require supported operating system versions. Devices that can no longer receive updates should not access PHI.
A management platform lets IT enforce settings, push apps, separate work data from personal data, and remotely lock or wipe a lost device. For personal phones, a work profile or app-level management can limit control to work data only, which is easier to explain to staff.
Restrict access to approved email and clinical apps. Avoid storing PHI in personal messaging or cloud services.
Phones often serve as the second factor for other logins, so their security is doubly important.
Staff sometimes take photos of wounds or send text messages about residents because it feels quick. These practices can create HIPAA issues if the images land in personal photo libraries or cloud accounts, or if messages are sent over unsecured channels.
Offer a secure alternative:
A messaging app designed for healthcare with encryption and access controls
A way to attach photos directly to the resident's record
Clear policy on what must never be sent by regular text
Make the secure option easier than the risky one.
Prepare a simple response:
Staff report loss immediately to a named contact, any time of day.
IT locks and, if needed, remotely wipes the device.
Review what data and accounts were on it.
Reset passwords and revoke sessions.
Document the incident and assess whether it is a reportable breach. Encrypted devices with strong passcodes and a documented wipe often reduce risk, but the assessment still needs to be made.
Do not punish people for reporting. The point is speed.
When someone leaves, remove work profiles or wipe facility devices, revoke access tokens and remove them from MDM.
Do not leave tablets unattended on carts or counters.
Use cases or stands that discourage walking away with them.
Store spare devices in locked cabinets.
Keep an inventory with serial numbers and assigned users.
Advise staff not to use open public Wi-Fi for work. Where remote work is needed, use a VPN or secure application connections.
Lock the screen every time you step away
Do not share passcodes
Never install unapproved apps
Report loss immediately
Do not text PHI
Be careful of text message phishing
UnityCare IT helps healthcare organizations select and configure mobile device management, write practical mobile policies and handle lost-device response. If staff are using personal phones for work and you are not sure how to manage the risk, we can help set sensible guardrails.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172