Securing Medical Devices and IoT on the Facility Network

Walk through a modern senior living community and count the connected devices that are not computers: vital signs monitors, infusion pumps, bed sensors, nurse call panels, door locks, cameras, thermostats, smart TVs, tablets for activities, printers and wireless scales. Each one communicates over your network, and many were designed with function in mind rather than security.

These devices are often called the Internet of Things, or IoT, and in healthcare, medical IoT. They are hard to secure because they frequently cannot run security software, may use default passwords and can stay in service for a decade or more. This article outlines practical ways to manage that risk.

Why Connected Devices Are Risky

Default or weak credentials that are never changed after installation

Outdated software that no longer receives updates

Limited visibility, since IT may not know the device exists

Vendor-controlled maintenance, where the manufacturer restricts changes

Unencrypted communication on older devices

Remote access left open for vendor support

Clinical impact, since taking a device offline to fix it may affect care

A compromised camera or smart TV may seem trivial, but attackers use weak devices as a foothold to reach more valuable systems.

Step 1: Build a Device Inventory

You cannot manage what you cannot see. Combine several approaches:

Collect lists from clinical engineering, maintenance and department heads

Review purchasing records and vendor contracts

Use network discovery tools to find what is actually connected

Walk the building and note devices in rooms, closets and ceilings

For each device, record the manufacturer, model, location, owner, software version, how it connects and what data it handles.

Step 2: Change Defaults and Close Unneeded Doors

Change factory passwords on every device that allows it, using unique, strong ones stored in a managed vault

Disable unused services, ports and features

Turn off remote access that is not needed, or restrict it to approved vendor connections

Do not expose devices directly to the internet

Update firmware when the manufacturer provides fixes, coordinating with clinical staff

Step 3: Segment the Network

Isolation is one of the best protections for devices that cannot protect themselves. Place groups of devices in their own network segments, with firewall rules that allow only the traffic they need. For example, a camera system should talk to its recorder and approved viewing stations, and nothing else. Medical devices should reach only their servers and nurse stations. Guest and resident devices should have no path into any of them.

Step 4: Work With Manufacturers and Vendors

Ask each manufacturer:

How and how often do you issue security updates?

How long will this model be supported?

Is there documentation of security features and network requirements?

How do you handle vulnerability reports?

For medical devices, manufacturers often publish security information that describes how the device should be deployed, sometimes called a manufacturer disclosure statement for medical device security. Request it when buying new equipment, and include security requirements in purchase decisions and contracts.

Step 5: Monitor for Unusual Behavior

Even when a device cannot run security software, the network can watch it. Monitoring tools can alert you to:

A new, unknown device connecting

A camera suddenly sending large amounts of data to the internet

Devices communicating with systems they never contacted before

Repeated failed login attempts

Step 6: Plan for End of Life

Devices eventually go out of support. Track end-of-life dates, budget for replacement and isolate unsupported equipment more tightly in the meantime. When retiring a device, wipe stored data, including resident information and network credentials, before disposal.

Do Not Forget Everyday Devices

Smart TVs, streaming sticks, voice assistants and fitness trackers brought in by staff or residents may seem harmless. Put them on a separate guest or resident network and be cautious about devices with cameras or microphones in resident rooms. Consider the privacy implications, and develop clear policies on resident-owned devices.

Include Clinical and Facilities Teams

Security cannot succeed in isolation. Involve nursing leaders, maintenance staff and administrators when buying or installing anything that connects to the network. A simple rule helps: no device joins the network until IT knows about it and has approved how it connects.

Common Mistakes

Installing a device without telling IT

Leaving vendor default passwords in place

Allowing vendors permanent, unmonitored remote access

Placing everything on a single flat network

Assuming a device is safe because it is small or simple

Getting a Handle on It

UnityCare IT can help you discover what is on your network, design segments for medical and building devices and coordinate with your vendors, so connected equipment supports care without becoming an open door.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172