A modern care facility is full of devices that nobody thinks of as computers. Vital signs monitors, infusion pumps, medication carts, nurse call systems, door locks, cameras, thermostats, resident TVs and even smart speakers connect to the network. Many were installed by vendors, run old software, and cannot be patched the way a laptop can.
Each one is a potential doorway. Attackers do not care whether a device is clinical or decorative if it gives them a foothold.
You cannot protect what you cannot see. Build an inventory that records:
Device type, make, and model
Location and the department that owns it
How it connects: wired, Wi-Fi, cellular
What it talks to, such as a server, a vendor cloud, or other devices
Whether it stores or transmits resident information
Who supports it: your IT team, the manufacturer or a third-party vendor
Operating system and software version, if known
Ask department heads, facilities and maintenance staff as well as IT. Therapy, dietary, laundry and building systems often include connected equipment that IT never heard about. Network scans can help find devices that show up on the network without being on anyone's list.
This inventory also supports HIPAA risk analysis, which expects you to identify where electronic protected health information lives and flows.
If a device cannot be hardened, limit what it can reach. Network segmentation puts devices into separate zones and controls the traffic between them.
Place medical and building devices on their own network segments, separate from office computers and guest Wi-Fi.
Allow only the connections each device needs, such as to a specific server on a specific port.
Block internet access for devices that do not require it, or restrict it to the vendor's required addresses.
Keep resident-owned gadgets and guest devices on a separate internet-only network.
Work with vendors before changing anything. Some clinical devices break if network rules are too strict, so test during a planned window and keep a rollback plan.
Many devices depend on the manufacturer for updates, and some vendors restrict customers from installing patches themselves. That makes vendor management part of security.
Ask each vendor:
How are security updates delivered, and how often?
Does the device have remote access for support? How is it secured, and can we turn it off when not in use?
What default passwords exist, and can we change them?
What is the product's expected support lifetime?
How do you notify customers of vulnerabilities?
Put security expectations in contracts and purchasing requirements for new devices. The FDA has issued guidance on cybersecurity for medical devices, and manufacturers' documentation often describes recommended network configuration.
Even on specialized equipment, a few steps matter:
Change factory default passwords and disable unused accounts
Turn off services and ports that are not needed
Update firmware when the vendor provides it, after testing
Replace devices that are no longer supported when practical, or isolate them tightly until you can
Physically secure ports and devices in public areas
If a device begins sending unusual traffic or stops responding, you want to notice. Network monitoring tools can flag new devices joining the network, unusual connections and devices talking to places they never did before.
Also decide in advance what happens if a device must be disconnected quickly. For critical care equipment, clinical leaders should be involved: what is the manual fallback, and who decides?
Staff and residents sometimes bring in convenient gadgets: personal tablets, streaming sticks, smart speakers, fitness trackers or cameras. Without a policy, these end up on the staff network. A simple rule, with a guest network that works well enough that people do not need workarounds, prevents most of this.
Build and maintain a device inventory.
Create separate network segments for devices, staff and guests.
Restrict device traffic to what is needed.
Change default credentials and close remote access you do not need.
Ask vendors about patching and support lifetimes.
Plan replacement for unsupported equipment.
Monitor for new or unusual devices.
UnityCare IT helps care organizations map their connected devices, design segmentation and coordinate with equipment vendors. If you are unsure how many devices are on your network, an inventory is a good first step and we can help with it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172