Walk through a modern senior living community and count the connected devices that are not computers: vital signs monitors, infusion pumps, bed sensors, nurse call panels, door locks, cameras, thermostats, smart TVs, tablets for activities, printers and wireless scales. Each one communicates over your network, and many were designed with function in mind rather than security.
These devices are often called the Internet of Things, or IoT, and in healthcare, medical IoT. They are hard to secure because they frequently cannot run security software, may use default passwords and can stay in service for a decade or more. This article outlines practical ways to manage that risk.
Default or weak credentials that are never changed after installation
Outdated software that no longer receives updates
Limited visibility, since IT may not know the device exists
Vendor-controlled maintenance, where the manufacturer restricts changes
Unencrypted communication on older devices
Remote access left open for vendor support
Clinical impact, since taking a device offline to fix it may affect care
A compromised camera or smart TV may seem trivial, but attackers use weak devices as a foothold to reach more valuable systems.
You cannot manage what you cannot see. Combine several approaches:
Collect lists from clinical engineering, maintenance and department heads
Review purchasing records and vendor contracts
Use network discovery tools to find what is actually connected
Walk the building and note devices in rooms, closets and ceilings
For each device, record the manufacturer, model, location, owner, software version, how it connects and what data it handles.
Change factory passwords on every device that allows it, using unique, strong ones stored in a managed vault
Disable unused services, ports and features
Turn off remote access that is not needed, or restrict it to approved vendor connections
Do not expose devices directly to the internet
Update firmware when the manufacturer provides fixes, coordinating with clinical staff
Isolation is one of the best protections for devices that cannot protect themselves. Place groups of devices in their own network segments, with firewall rules that allow only the traffic they need. For example, a camera system should talk to its recorder and approved viewing stations, and nothing else. Medical devices should reach only their servers and nurse stations. Guest and resident devices should have no path into any of them.
Ask each manufacturer:
How and how often do you issue security updates?
How long will this model be supported?
Is there documentation of security features and network requirements?
How do you handle vulnerability reports?
For medical devices, manufacturers often publish security information that describes how the device should be deployed, sometimes called a manufacturer disclosure statement for medical device security. Request it when buying new equipment, and include security requirements in purchase decisions and contracts.
Even when a device cannot run security software, the network can watch it. Monitoring tools can alert you to:
A new, unknown device connecting
A camera suddenly sending large amounts of data to the internet
Devices communicating with systems they never contacted before
Repeated failed login attempts
Devices eventually go out of support. Track end-of-life dates, budget for replacement and isolate unsupported equipment more tightly in the meantime. When retiring a device, wipe stored data, including resident information and network credentials, before disposal.
Smart TVs, streaming sticks, voice assistants and fitness trackers brought in by staff or residents may seem harmless. Put them on a separate guest or resident network and be cautious about devices with cameras or microphones in resident rooms. Consider the privacy implications, and develop clear policies on resident-owned devices.
Security cannot succeed in isolation. Involve nursing leaders, maintenance staff and administrators when buying or installing anything that connects to the network. A simple rule helps: no device joins the network until IT knows about it and has approved how it connects.
Installing a device without telling IT
Leaving vendor default passwords in place
Allowing vendors permanent, unmonitored remote access
Placing everything on a single flat network
Assuming a device is safe because it is small or simple
UnityCare IT can help you discover what is on your network, design segments for medical and building devices and coordinate with your vendors, so connected equipment supports care without becoming an open door.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172