Mobile Devices on the Floor: Securing Tablets and Phones

Tablets at the nurses' station, smartphones carried by aides, therapists charting on the go: mobile devices are now a normal part of care delivery. They are convenient, fast and easy to lose. A single phone left in a car or a tablet dropped in a hallway can hold email, photos, messages and access to systems that contain protected health information.

Securing mobile devices does not require locking everything down so tightly that staff cannot work. It requires a few clear decisions.

Decide Which Devices Are Allowed

Facility-owned devices

You control the configuration, and they can be wiped or retired. This is the safest option for devices that handle PHI regularly.

Personal devices (bring your own device)

Convenient and cheaper, but riskier. If you allow personal phones to access work email or clinical applications, you need rules, and staff need to understand them.

Shared devices

Tablets shared across shifts need individual logins to the applications, and sessions that time out quickly.

Write a policy that states which categories are permitted, for what purposes and under what conditions.

Baseline Controls

Passcodes and biometrics

Require a passcode of reasonable length, plus automatic locking after a short idle period. Fingerprint or face unlock is acceptable for convenience when combined with a passcode.

Encryption

Current iPhones and Android phones encrypt storage once a passcode is set. Confirm through your management tool.

Operating system updates

Require supported operating system versions. Devices that can no longer receive updates should not access PHI.

Mobile device management (MDM)

A management platform lets IT enforce settings, push apps, separate work data from personal data, and remotely lock or wipe a lost device. For personal phones, a work profile or app-level management can limit control to work data only, which is easier to explain to staff.

Approved apps only

Restrict access to approved email and clinical apps. Avoid storing PHI in personal messaging or cloud services.

Multi-factor authentication

Phones often serve as the second factor for other logins, so their security is doubly important.

The Photo and Text Problem

Staff sometimes take photos of wounds or send text messages about residents because it feels quick. These practices can create HIPAA issues if the images land in personal photo libraries or cloud accounts, or if messages are sent over unsecured channels.

Offer a secure alternative:

A messaging app designed for healthcare with encryption and access controls

A way to attach photos directly to the resident's record

Clear policy on what must never be sent by regular text

Make the secure option easier than the risky one.

Lost or Stolen Devices

Prepare a simple response:

Staff report loss immediately to a named contact, any time of day.

IT locks and, if needed, remotely wipes the device.

Review what data and accounts were on it.

Reset passwords and revoke sessions.

Document the incident and assess whether it is a reportable breach. Encrypted devices with strong passcodes and a documented wipe often reduce risk, but the assessment still needs to be made.

Do not punish people for reporting. The point is speed.

Handling Departures

When someone leaves, remove work profiles or wipe facility devices, revoke access tokens and remove them from MDM.

Physical Practices

Do not leave tablets unattended on carts or counters.

Use cases or stands that discourage walking away with them.

Store spare devices in locked cabinets.

Keep an inventory with serial numbers and assigned users.

Wi-Fi and Public Networks

Advise staff not to use open public Wi-Fi for work. Where remote work is needed, use a VPN or secure application connections.

Training Points for Staff

Lock the screen every time you step away

Do not share passcodes

Never install unapproved apps

Report loss immediately

Do not text PHI

Be careful of text message phishing

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations select and configure mobile device management, write practical mobile policies and handle lost-device response. If staff are using personal phones for work and you are not sure how to manage the risk, we can help set sensible guardrails.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172