Bring Your Own Device (BYOD)

BYOD stands for “Bring Your Own Device.” It is a mobile industry term that refers to the use of an employee’s personal device – such as a smartphone, tablet or laptop – for work purposes.

Unmanaged systems represent a primary threat to our network and PHI or PII data. 

Our BYOD policy provides a way to more safely accommodate staff and students who prefer to use their own personal devices to remotely access the UNM Health and Health Sciences network and data.  Many healthcare organizations prohibit BYOD entirely.  In our case, remote access from personal devices has been part of the culture for many years.  This practice accelerated rapidly due to Covid measures, increasing the number of people working and learning remotely.  Our policy is a compromise to permit access but only from personal devices that meet industry-wide security standards.  These are the key risks that our BYOD policy addresses:

  • Theft of an unencrypted personal device containing Confidential or Restricted data (Disk encryption required with password/PIN required)
  • Connection of a personal device that has been compromised due to a system vulnerability, allowing lateral movement across the network to sensitive data (Require anti-virus agent and supported operating system that receives security updates)
  • Access of a compromised personal device directly to PHI and PII (Require anti-virus agent and supported operating system that receives security updates)