A hospice nurse finishes a patient visit. She documents the visit on her iPad in the patient's driveway before driving to her next stop. The iPad — which she also uses personally — contains her agency's EHR access, several weeks of clinical documentation, and email correspondence about patient care. She sets it on the passenger seat.
At the next stop, she leaves the car briefly. When she returns, the passenger window is broken. The iPad is gone.
This scenario is not hypothetical. It is a routine occurrence across hospice and home health settings — and in every case, the response of the hospice agency determines whether this is a manageable security incident or a reportable HIPAA breach.
For hospice agencies whose field staff routinely work with devices in patient homes, community settings, parking lots, and personal vehicles, device security policy is not abstract. It is the practical infrastructure that determines the outcome when the inevitable happens.
The Device Inventory: What's Out There
Before building a device policy, a hospice agency needs to know what devices exist in its environment. This requires an honest inventory:
Agency-owned devices: Laptops, tablets, smartphones provided by the agency to clinical staff. These are easier to manage because the agency has full control — MDM, encryption, remote wipe, patching, app management.
Personal devices used for work (BYOD): Staff members' personal phones, tablets, or laptops used to access the EHR, email, or any agency system. These exist in nearly every hospice agency regardless of whether the policy acknowledges them. The question is whether they are managed.
Shared devices: In some hospice offices, tablets or workstations are shared between multiple staff members. Shared devices require individual user accounts and session management to prevent unauthorized access to other users' records.
Vendor devices: IT vendors, EHR implementation consultants, or billing contractors who connect devices to your network. These are third-party devices that may or may not meet your security standards.
The Three Foundational Device Controls
Control 1: Encryption
Every device that stores or accesses ePHI must be encrypted. For the lost iPad in the scenario above, if device encryption is enabled, the attacker who stole it cannot access the patient data it contains without the device PIN or passcode — even if they connect the iPad to a computer.
- iOS (iPhone, iPad): Encryption is automatic when a passcode is set. Verify that all iOS devices used for work have a passcode set.
- Android: Encryption must be verified in device settings. Modern Android devices (Android 6+) are typically encrypted by default, but this should be confirmed.
- Windows laptops: Enable BitLocker Drive Encryption. Confirm with IT or your MDM platform.
- Mac laptops: Enable FileVault. Confirm with IT or your MDM platform.
Control 2: MDM and Remote Wipe
Mobile Device Management software allows your agency (or your managed security provider) to remotely wipe a device that is lost or stolen — erasing all data before an unauthorized person can access it.
For agency-owned devices, MDM manages the entire device. For personal BYOD devices, MDM manages a secure work container — all agency data, email, and apps live inside the container, which can be wiped independently of the personal device. The nurse's personal photos, contacts, and apps remain untouched; the agency data is erased.

