Create a configuration
Once you’ve selected an MDM solution, you’ll need to create a configuration
that’s specifically optimized for the patient use case and that your MDM
solution can install over the air. A configuration will typically contain settings
and restrictions that set up the device in a posture that’s appropriate for patient
use. These settings will help streamline the initial patient experience and
disable features or services that might store personal data or be unnecessary.
Restrictions
The following are examples of restrictions you’re likely to enable so that no
personal information is left on the device. Note: Descriptions may vary by
MDM solution.
Device management: Disallow manual profile installation, disallow configuring
of restrictions, disallow device name changing, disallow account modification,
force Limit Ad Tracking, and disallow pairing with non-Configurator hosts.
Data management: Disallow documents from managed sources in unmanaged
destinations, disallow documents from unmanaged sources in managed
destinations, and enforce AirDrop as an unmanaged destination.
Apps: Disallow the App Store icon on the Home screen, disallow app removal,
disallow in-app purchase, disallow user to trust unmanaged enterprise apps,
and hide specific apps on the Home screen.
Media: Disallow use of Game Center, skip Apple ID password for media
purchases, and restrict media content as needed.
Home screen layout, Lost Mode, and other settings
You can manage how apps, folders, and web clips are arranged on the Home
screen of supervised devices. Enable use of the camera so hospital staff can
scan a patient’s QR code using a secure patient app or add the patient’s photo
to an electronic medical record (EMR) app. To track missing iPad devices, make
sure your MDM supports the features related to Lost Mode, such as a lost
message text, query location of device, and reenable Lost Mode after a reset
or restore. Note that Lost Mode will allow an administrator to query the location
of a lost device even if the user has disabled location services.