Phones and tablets have become part of daily clinical work. Staff use them to check schedules, message coworkers, take photos for wound documentation, view the electronic health record or receive nurse call alerts. Some devices belong to the facility, while many belong to employees. Without a clear policy, protected health information can end up in text threads, personal photo galleries and unlocked devices that nobody can wipe.
A mobile device policy does not need to be long. It needs to be clear, and it needs to be followed.
There are three common arrangements.
The facility buys and manages the devices. This offers the most control and the cleanest separation of personal and work data, but it costs more and requires inventory and support.
Staff use personal phones for work. It is less expensive, but you have less control and must respect employee privacy. A BYOD policy must be especially clear about what the organization can and cannot do.
Shared facility devices for clinical tasks, with limited BYOD access to things like email or scheduling through protected apps.
Require a screen lock with a passcode or biometric, automatic locking after a short idle time, current operating system updates, and device encryption, which is on by default for most modern phones when a passcode is set.
Define which apps may access or store protected information. Consumer messaging apps, personal cloud storage and social media should not be used for resident information unless they are specifically approved and covered by appropriate agreements.
This is a major risk area in care settings. Resident photos can cause privacy violations and dignity concerns, even when taken with good intentions. Many organizations prohibit taking photos of residents on personal devices, and provide an approved, managed app for clinical documentation where needed.
Ordinary text messages are not secure. If clinicians need to text about residents, provide a secure messaging platform with encryption, access controls and message retention.
Advise staff against accessing work data on unknown public networks, and discourage using unknown public charging stations.
Mobile device management, or MDM, software lets IT apply the policy technically. Depending on the arrangement, it can enforce passcodes, separate work apps from personal data, push updates and remotely remove work data. For BYOD, choose approaches that manage only the work container, not the whole phone, so employees are comfortable enrolling.
A lost phone with resident information can be a reportable event if the data is unprotected. Your policy should say:
Staff must report a lost or stolen device immediately, at any hour
IT will remotely lock or wipe the work data as soon as possible
The privacy officer will assess the incident, including whether encryption protected the data
Reporting promptly will not result in punishment
When an employee leaves, work accounts and apps must be removed from personal devices on the last day. MDM makes this reliable. Without it, you depend on the honor system.
For BYOD, explain exactly what you can see and what you cannot. Typically, the organization can see that a device is enrolled and manage work apps, but not read personal messages or photos. Clear statements build trust and increase participation.
Have staff read and sign the policy at hire and when it changes. Walk through it in orientation, with real examples such as what to do if a family member asks you to text a photo of their loved one.
Technology and workflows change. Review your policy yearly, and after any related incident.
UnityCare IT can help you choose a device management approach, set up secure messaging and draft a policy that fits your culture and your compliance obligations.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172