Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Mobile Device Security

Essential Security Practices for Smartphones and Tablets in Healthcare

Welcome to this week’s HIPAA Tip Tuesday! Mobile devices have become essential tools in healthcare, but they also represent significant security risks when not properly protected. In this guide, Dawn Meglino walks through a real-world scenario of mobile device compromise and shares critical steps to protect patient data on your phones and tablets.

TL;DR – Mobile Device Security Essentials:

  • Use strong, unique passcodes (not birthdays or 1-2-3-4)
  • Apply software updates immediately to fix security vulnerabilities
  • Disconnect Wi-Fi and Bluetooth when not actively using them
  • Install remote wipe software to delete data if device is lost or stolen
  • Reset passwords immediately if you suspect compromise

The Mobile Device Security Risk

Think about all the things you do on your cell phone – emails, banking, shopping, connecting to work systems and applications: EMR, scheduling, billing, dictation – so many areas containing sensitive information and ePHI.

When was the last time you reset your passcode (and please don’t tell me it’s your birthday or 1-2-3-4)?

A Real-World Scenario: How Mobile Device Theft Leads to Data Breach

Here’s a scenario: your phone is stolen or lost. The thief cracks your passcode because it’s that easy. From there, they move on to your online bank account, or worse, the EMR for the organization. Once there the hacker clicks “reset password” rather than attempting to figure it out and goes into your email and resets the password for the account and voila! Time to access data or move money out of one bank account to their own.

Four Critical Mobile Security Steps

Secure Passcodes and Password Resets

Make passcodes secure and reset all passcodes or passwords in the event you believe someone may have attempted to compromise your account.

Apply Software Updates Immediately

Always allow/apply updates to systems and software to fix vulnerabilities and improve security – do not ignore these or put them off when they are released.

Disconnect Unused Connections

Disconnect Wi-Fi and Bluetooth when not actively using them. This reduces the risk of unauthorized access to your device and data by disallowing access.

Enable Remote Wipe Capability

Install an app from an MDM provider or your IT company to enable remote wipe software on your device, deleting sensitive data and preventing a data breach should the device become lost or stolen.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.