HIPAA Tip: Medical Device Security
There is so much focus on security measures as they relate to computers: workstations, laptops, iPads, tablets, and servers, either physically onsite or virtual/cloud based. But what about medical devices/diagnostics that either contain patient data or connect to the organization’s EMR to upload this data?
Medical devices must be treated with the same respect and protection as any other computer used in a healthcare environment that contains electronic Protected Health Information (ePHI). Ensure the following is in place:
- Medical devices need to be logged into with unique user IDs and passwords for all staff accessing the machine. Do not have one universal sign-on with a password that never changes, especially when workforce members terminate their employment (think about never resetting an alarm code!).
- All diagnostic machines/devices must be inventoried, including tools or appliances that are no longer being used but are still stored in the facility (with a hard drive containing ePHI).
- Patching should be completed as soon as possible once new updates are available from the manufacturer/vendor. Never, ever, continue to use an end of life device that is running on the network; these are easy targets for threat actors to gain access into the environment.
From HHS 405(d): Much of Medical Device security can be accomplished by treating the devices as IT equipment. Just as you would for a computer, establish endpoint protections, proper inventory, regular software patching, and implement access management procedures.
Ongoing HIPAA Compliance Support
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.