Securing Medical and IoT Devices on a Facility Network

A modern care facility is full of connected devices that nobody thinks of as computers: security cameras, smart TVs, door controllers, thermostats, nurse call components, blood pressure monitors, wireless scales and more. Each one is a small computer on your network. Many are installed by vendors, run old software, use default passwords and are never updated. Attackers know this and look for these soft spots.

Here is a practical approach to bringing connected devices under control.

Why these devices are different

Traditional computers get regular updates and have security software. Connected devices often do not.

They may run embedded software the vendor rarely updates.

They may ship with default or hard-coded credentials.

They may not support security agents or logging.

Clinical devices may be subject to regulatory and manufacturer constraints that limit changes.

They may stay in service for ten years or more.

A vulnerable camera or printer can serve as an entry point to the rest of the network, or as a hiding spot for an attacker.

Step 1: Build an inventory

You cannot manage what you cannot see. Find every device by combining:

A walk-through of each unit, kitchen, maintenance area and common space

A scan of the network that lists connected devices and their addresses

A review of purchasing and vendor records

Questions to department heads about what they have added

For each device, record the type, manufacturer, model, location, network address, software version, owner and the vendor contact.

Step 2: Change defaults

The simplest, most effective fix is also the most neglected. Change default usernames and passwords on every device that allows it. Use unique credentials for each device or group, store them in a secured vault and restrict who can see them. Disable unused features and remote management interfaces.

Step 3: Isolate

Place these devices on separate network segments from staff computers and servers holding ePHI. Apply firewall rules that allow only the traffic each device needs. For instance, a camera system needs to talk to its recorder, and the recorder needs a controlled way to reach authorized users, but a camera has no reason to talk to the billing server.

Isolation is especially important for devices that cannot be patched. It reduces the damage if one is compromised.

Step 4: Ask vendors the right questions

When buying or renewing, ask:

How long will this product receive security updates?

How are vulnerabilities reported and fixed?

Does the device support encryption and strong authentication?

What remote access does your company maintain, and how is it secured?

Will you sign a business associate agreement if PHI is involved?

Is there documentation describing the device's security features, such as a manufacturer disclosure statement for medical devices?

Put security expectations in contracts and purchase checklists.

Step 5: Manage updates

Set a schedule to check for firmware updates, and subscribe to vendor security notices. For clinical devices, coordinate with the manufacturer or biomedical staff before applying changes, and test when possible.

Step 6: Monitor

Watch for unusual behavior such as a camera connecting to unfamiliar addresses, a TV sending large amounts of data or a device appearing that was not in your inventory. Network monitoring tools can alert you when a new device connects.

Step 7: Plan for retirement

When a device reaches end of life, plan its replacement. Before disposal, remove or wipe stored data such as video, credentials and Wi-Fi settings.

Include it in your risk analysis

The HIPAA Security Rule applies to ePHI-handling devices, including medical equipment that stores or transmits resident data. Include connected devices in your risk analysis, noting existing safeguards and gaps. The HHS 405(d) Health Industry Cybersecurity Practices also address medical device security as a distinct area.

Getting help

UnityCare IT helps healthcare organizations find, document and isolate connected devices as part of network assessments. If you suspect your facility has devices nobody is managing, we can help you create the inventory and a plan.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172