Medical Devices and IoT: The Forgotten Computers on Your Network

Your imaging machine, your printer, and the smart TV in the waiting room are all computers. Most of them were never set up with security in mind.

Nurse reviewing patient information on a tablet

The Devices Nobody Thinks About

Count the computers in your practice and you will probably count the desktops and laptops. Now count again, and include everything with a processor and a network cable. The digital X-ray or pano machine. The ultrasound. The multifunction printer that scans, copies, and faxes. The smart TV looping a slideshow in the waiting room. The thermostat you adjust from your phone. The security cameras. The VoIP desk phones. The tablet signed in as a guest at the front.

A typical small clinic in Rockport or Portland has a dozen or more of these, and almost nobody inventories them — which means nobody updates them, nobody changed their passwords, and nobody thought about what happens if one of them gets compromised. If a device stores or transmits patient information, HIPAA’s Security Rule covers it just like a workstation. And even the ones that do not touch patient data can be a doorway: a compromised camera or TV on the same network as your EHR is a foothold an attacker can use to move sideways.

Why These Devices Are Risky

Three traits make medical and IoT devices different from a normal office computer, and all three work against you.

First, they run old software for a long time. An imaging workstation might run an operating system the vendor certified a decade ago, and the vendor forbids you from updating it yourself because that would void the service contract. Second, they ship with default passwords — admin/admin, or a vendor-wide service password — and those defaults often survive installation because changing them is nobody’s assigned job. Third, vendors remote into them. Your imaging company, your phone vendor, your camera installer may all have remote access for support, which is convenient until you ask who else could use that same door.

You also cannot protect them the way you protect a laptop. There is no antivirus to install on a thermostat. Nobody is patching the waiting-room TV. That is normal — the answer is not to treat them like workstations, it is to contain them, which brings us to the fix.

Segmentation in Plain English: Separate Lanes

Think of your network like a road. Right now, most small clinics have one road: the EHR server, the front-desk computers, the X-ray machine, the smart TV, and the patient Wi-Fi are all driving in the same lane. If one vehicle crashes, everything behind it piles up.

Segmentation just means building separate lanes. One lane for staff computers and the EHR. One lane for medical devices and equipment. One lane for guests — patients on their phones in the waiting room should never be on the same network as your charts, full stop. A compromised TV in the guest lane cannot reach the EHR in the staff lane, because the lanes do not connect.

This is not exotic equipment. Any competent business-grade router or firewall can do it, and most clinics already own hardware capable of it — it was just never configured. If your “guest Wi-Fi” is the same Wi-Fi your staff uses, that is the first lane to split, and it is usually an afternoon’s work.

What to Ask Your Equipment Vendors

You bought the imaging machine; the vendor installed it and left. Somewhere in between, security fell through the cracks. These questions put it back on the table — in writing, by email:

  • Was the default administrator password changed at installation, and what is our current admin login?
  • Who is responsible for software updates on this device — us or you — and how often do they happen?
  • Do you have remote access to this device for support? How is that access secured, and can we turn it off when you are not using it?
  • Is this device still supported, or is it end-of-life? What is the plan if a security flaw is found in it?
  • Does the device store patient images or data locally, and is that storage encrypted?

Ask the same of your printer/copier vendor — especially about the hard drive inside the machine and what happens to it when the lease ends and the machine goes back. That drive may hold years of scanned intake forms.

What to Do Monday Morning

Walk the office and list every device with a screen, a network cable, or a Wi-Fi connection — medical or not. Then do three quick things: change any password still set to the factory default (check the TV, the thermostat, the cameras, the printer’s web page), confirm patients’ phones are on an isolated guest network and not your staff Wi-Fi, and email your imaging vendor the five questions above.

You will not fix every device in a morning. But you will know what you have, you will have closed the default-password door, and your guests will be in their own lane. That is more device security than most clinics your size have ever had.

Not sure where your practice stands?

Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.

Call (361) 704-1373 or request yours online.

Request your assessment →

Not ready to book? Start with the checklist.

Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.

Your download link appears right after you submit. Prefer to talk? Call (361) 704-1373, Mon–Fri 8am–5pm CT.

Frequently asked questions

Do HIPAA rules really cover our X-ray machine?

If it stores or transmits electronic protected health information — patient images tied to names, for example — then yes, the Security Rule applies to it just like a workstation. Even devices that never touch patient data matter, because they share your network.

Can a printer actually be a security risk?

Yes, two ways. Many multifunction printers keep copies of everything they scan, copy, or fax on an internal hard drive. And any network-connected printer with a default password is a potential foothold into the rest of your network.

Should we even offer Wi-Fi to patients?

You can, and patients expect it — but put it on an isolated guest network that cannot reach your staff computers or EHR. The waiting-room TV and thermostat belong on a separate lane too, not the staff network.

Who is responsible for updating the imaging machine — us or the vendor?

Often the vendor, because service contracts forbid you from touching the software. But “the vendor handles it” is only an answer if you have verified it. Ask them in writing how often updates happen and what happens when the device goes end-of-life.

What is network segmentation, in one sentence?

Separate lanes: staff computers and the EHR in one, medical devices in another, guests in a third — so a problem in one lane cannot reach the others.