Smartphone and Tablet Encryption and Security
Mobile devices including smartphones and tablets are required to be encrypted with an automatic passcode lock if they contain data classified as confidential or sensitive (including PHI and PII).
IMPORTANT: If you have your device configured to connect to your institutional email, keep in mind that confidential or sensitive data contained in messages and attachments you receive would mean that the device must be encrypted and passcode protected.
If you have a phone or tablet that is already configured to connect to your CUMC IT Exchange Email account, passcode and encryption compliance will have been automatically enforced on the device.
Please be sure you are aware of all Encryption and Mobile Device policies and requirements; for instructions on setting passcodes and encryption for most models of smartphones and tablets select the appropriate link for your device below.
iPhone, iPad and iPod Touch Instructions
Apple devices older than the following cannot meet policy requirements and should not be used to access or store confidential and sensitive data. For help in identifying a model please select a link below. The iOS version can be viewed by opening device's Settings, then selecting the General, About and Version links.
- iPhones - 3GS, 4, 4S and 5 running iOS version 4.0 or greater
- iPads - any generation running iOS version 4.0 or greater
- iPod touch - 4G
Perform a backup
See Apple's iOS: How to back up tutorial online to perform a backup to iTunes on your computer before encrypting your device.
- The computer or other media that will store a backup containing confidential or sensitive data must also be properly encrypted with password protection.
- Do not backup to iCloud as Apple does not have a Business Associate Agreement with CUMC to access or store confidential and sensitive data.
Setting a Passcode Lock and Encryption
- Select Settings from the home screen, then General and Passcode Lock.
- Make sure the Simple Passcode option is set to Off; if not tap it to move the slider to the Off setting. At this point a passcode of at least 6 digits is required by CUMC, though we strongly recommend that all strong password requirements are followed.
- Enter your desired passcode lock of at least 6 digits.
- In the Passcode Lock screen, scroll to the bottom to verify that the last button reads Data protection is enabled. This means that data on the device is encrypted.
- Return to the General screen (Settings - General from the home screen).
- Select Auto-Lock.
- Set an auto-lock time of 5 minutes or less.
Your device will now require the passcode you selected in step 3 when the device is turned on, restarted, or upon "wake" after 5 minutes or more of inactivity.
| TOP |
Android Device Instructions
Phones and tablets must be running version Android operating system version 3.0 or higher to meet meet security policies for encrypting and password protecting confidential or sensitive data. If you are using an older device, it can not meet policy requirements, and should not be used to access or store sensitive data.
Setting a Passcode and Auto-Lock IMPORTANT: instructions may vary for some models and Android OS versions. For additional help please refer to your device's manual or the manufacturer's website.
- Select the device's Settings; you may need to select the Menu or Home button first.
- Select the Location & security link.
- Select Change (or Set up) screen lock.
- Choose the Pin or Password (recommended) option to select a passcode. We highly recommend that a Password is used rather than a Pin, and that all strong password requirements are followed.
- Type in your desired password as prompted, then the Back button to save and return to the Location & security settings.
- Make sure that Visible passwords is not checked (tap to de-check if needed).
- Press the Back button to return to the main Settings screen, and select Display.
- Select the Screen timeout link.
- Select an auto-lock time of 10 minutes or less; 2 minutes or less is recommended.
- Tap the Back button to return to your home screen.
The Android device will now require the password you selected in step 4 when turned on, restarted, or after 5 minutes of inactivity.
Setting Encryption
As stated above, instructions for setting encryption may vary based on the model and Android OS version of your device. It is also strongly recommended that you perform a backup of the device before encrypting to avoid possible loss of information; if the backup will contain confidential or sensitive data it must be stored on properly encrypted and password protected computer or media as well. Please refer to its manual or the manufacturer's website if needed.
- Select the device's Settings; you may need to select the Menu or Home button first.
- Select the Location & security link.
- Scroll down to select Data Encryption.
- Tap Encrypt Device Data.
- Select Proceed when prompted. Encryption will begin and the device will reboot when finished.
- Return to Settings - Location & security - Data Encryption, and select Encrypt memory card.
- Select Proceed; encryption on any installed memory card will begin and the device will reboot when finished.
| TOP |
BlackBerry Instructions
BlackBerry devices must be connected to a BlackBerry Enterprise Server (BES) with password and encryption policies enabled. As stated above, any devices that connect to your CUMC IT Exchange Email account will automatically be enforced to comply with password and encryption requirements; it is not necessary to follow the instructions below.
Setting a Passcode and Auto-Lock
- From the BlackBerry's home screen select Options.
- Scroll down to select Security.
- Select Password and set the option to Enabled.
- Select the escape menu, then type in your desire password of at least 6 digits when prompted. We highly recommend choosing a strong password of eight or more characters.
- In the Options - Security - Password settings, set the Number of Password Attempts to 10.
- Set the Lock After time to 5 minutes or less.
- Select the options to enable Handheld Upon Holstering and Prompt on Application Install.
- Make sure that Allow Outgoing Calls While Locked is not checked.
- Press the escape button to save the settings and exit.
Setting EncryptionWhenever setting up device encryption, it is highly recommended that you perform a recent backup of the device to avoid the risk of losing important data. If the backup will contain confidential or sensitive information you must make sure the backup media is also encrypted and password protected.
- From the BlackBerry's home screen select Options.
- Select Security, then Encryption.
- Enable Encrypt and verify that Strength is set to Strong.
- Make sure that Include Contacts and Include Media Files are not checked.
- If your BlackBerry has an SD or other storage card installed, scroll down to Media Card and enable Encrypt.
- Under Mode, choose Device.
- Select the escape menu button to save and quit; if prompted type in your password for the device.
| TOP |
|