Walk through almost any clinic or care community and you will see staff using personal phones. They check schedules, read email, call family members of residents, and sometimes snap a quick photo or send a text about a patient. Banning phones outright is rarely realistic. A clear bring-your-own-device policy, often called BYOD, lets you set boundaries that protect patient information and respect employees' personal property.
Personal phones create several kinds of exposure:
Lost or stolen devices holding email or PHI
Messaging apps that store content outside your control
Photos of residents, wound care or documents that end up in personal photo libraries and cloud backups
Phones with outdated software or no screen lock
Former employees who still have work email on their phones
Family members or friends who borrow a phone that is signed into work apps
The HIPAA Security Rule applies regardless of who owns the device. If ePHI is on it, safeguards for access control, device and media controls and transmission security are relevant.
A workable policy answers a few direct questions.
Many organizations allow work email, calendar and approved messaging apps through a managed container, while prohibiting storage of resident information in the phone's general storage.
Taking photos or video of residents or patients with personal cameras, except as permitted by a specific written procedure and consent policy
Sending PHI through standard text messages or consumer chat apps
Saving work files to personal cloud storage
Using social media to post anything that could identify a resident
Participation can be voluntary. Staff who decline can use organization-owned devices or desktop access instead.
For any personal phone that connects to work resources, require:
A screen lock with a PIN, passcode or biometric
Device encryption, which is enabled by default on most current phones
An operating system version that still receives security updates
No jailbroken or rooted devices
Multi-factor authentication for work accounts
Permission for the organization to remotely remove work data if the phone is lost or the employee leaves
The phrase to emphasize is work data. A well-designed program lets you remove the work container without touching personal photos and messages. Staff are more willing to enroll when they know this.
Mobile application management and similar tools place work email and apps inside a protected area on the phone. Features worth looking for:
Controls to prevent copying text from work apps into personal apps
Ability to block screenshots in sensitive apps
Selective wipe of only the work data
Conditional access that blocks sign-in from devices that do not meet your requirements
If your budget does not allow for this, consider limiting phone access to web-based email with multi-factor authentication, which at least keeps data out of the phone's local storage in many cases.
Employees worry about what the employer can see. Put in writing what you can and cannot access. Typically, management tools can see device type, operating system version and the work apps installed, and cannot read personal messages or browse personal photos. Have your legal counsel review the language, particularly around reimbursement and working time on personal devices, which can raise employment issues in some situations.
Add phone access removal to your offboarding checklist
Require staff to report a lost or stolen phone immediately, with a number to call at any hour
Remove the work container and revoke sessions as soon as a report is received
Document the event for your incident log and HIPAA assessment
Have employees sign an acknowledgment, but also spend a few minutes in a huddle explaining the rules and the reasons. Use real, simple examples: a photo of a wound taken for convenience could automatically sync to a family cloud album.
Revisit the policy annually. New apps, phone features and clinical workflows will change what is practical. If staff routinely want to share images for clinical reasons, look for an approved secure app instead of simply repeating the ban.
UnityCare IT can help you choose and configure mobile management and write a policy that fits how your team really works. If you are unsure what is on your staff's phones today, a short assessment is a good first step.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034