Printer Security: The Overlooked Risk in Medical and Dental Practices
Quick quiz: what’s the least-managed computer in your practice? It isn’t the front desk PC. It’s the multifunction printer in the hallway—the one that scans insurance cards, copies referrals, and faxes lab results, and hasn’t had a software update since the day it was installed.
Modern copiers and printers are full computers. They have an operating system, a network connection, a web login page, and, in many models, storage that keeps copies of what passed through. For a medical or dental practice, that’s patient information sitting on a device that almost nobody patches. It belongs on the same list as the items in our 30-minute monthly IT check.
What Makes Printers a Real Security Risk
Three things tend to go wrong, and none of them require a movie-style hacker.
Default Admin Passwords
Many devices ship with a known login that never gets changed, and the settings page is reachable from the office network.
Stored Patient Documents
Some models keep scan, copy, and fax data on an internal drive. When the lease ends and the machine goes back, so might your patient records.
Outdated Firmware
Printer makers publish security fixes, but firmware updates may need to be installed or configured manually.
If your guests or patients share a network with that printer, the exposure grows. A device sitting on the same flat network as your practice management system can become a stepping stone for someone who gets a foothold.
The Scan-to-Email Problem
Scan-to-email is convenient, and it’s often set up with a staff mailbox login saved right on the device. If those credentials are exposed, an attacker who reaches the printer may gain access to the mailbox too.
Treat the printer’s email account like any other account: unique, limited, and monitored.
A Practical Printer Security Checklist
You can tighten most of this in an afternoon.
Change Default Passwords
Change the default admin password and use a unique one for each device.
Keep Firmware Current
Install current firmware and schedule a check every quarter.
Disable Unused Services
Turn off services you don’t use, such as older file-sharing protocols and unnecessary remote administration features.
Separate Printers From Sensitive Systems
Put printers on their own network segment, with access restricted to the users and systems that need them.
Protect Internal Storage
Enable encryption of the internal drive and turn on overwrite or erase features if the model offers them.
Use a Dedicated Scan-to-Email Account
Use a dedicated, limited account for scan-to-email instead of a person’s login.
A good rule of thumb for any practice: if a device holds, sends, or prints patient information, it belongs in your asset list, your patch schedule, and your risk assessment. Printers are routinely left out of all three.
Fax, Guest Access, and the Forgotten Features
Turn Off Features Your Practice Doesn’t Use
Many devices support fax, USB printing, wireless printing, and cloud-print features, some of which may be enabled by default. Each feature adds something to manage.
If your practice doesn’t use direct USB printing or older remote protocols, turn them off. Fewer enabled features means fewer things to maintain and fewer places for patient data to land by accident.
Keep Guest Wi-Fi Separate
Also look at who can reach the printer. A visitor on the waiting room Wi-Fi should never be able to open the scanner’s admin page, let alone print to it.
Restricting access by network and by user is a small change that closes a surprisingly large door.
Don’t Forget the End of the Lease
Wipe Storage Before the Copier Leaves
Before a copier is returned, traded in, or sold, make sure its storage is securely wiped or its drive is removed for secure handling.
Get Written Confirmation
Get written confirmation of the steps taken from the vendor, and keep that record with your device documentation. Patient information needs protection when equipment is retired, too.
Keep a Current Inventory of Your Office Network
Printers are one more reason to keep a current inventory of what’s on your network. If you can’t list your devices, you can’t protect them.
For a related look at the rest of your public-facing setup, see our post on website security.
Have Abuzz Technologies Review Your Office Network
Curious what’s actually sitting on your office network? Call (215) 600-0349 or visit www.abuzztech.com.
Recent Comments