Most practices think of the office copier as furniture — something the front desk uses to scan insurance cards and print referral letters. In reality, it’s a networked computer with its own hard drive, its own firmware, and often its own set of unpatched vulnerabilities. And that hard drive has been quietly keeping a copy of nearly everything that’s passed through it.
What’s actually on that hard drive
Modern multifunction printers and copiers store an image of every document they scan, copy, print, or fax. When those documents include patient records, insurance forms, or referral letters, that hard drive is holding electronic PHI — the same category of data your Security Rule risk analysis is supposed to cover. Most practices never think to include it.
The moment this becomes a real problem is usually when the device leaves the building: a lease return, a trade-in, or a disposal. If the drive isn’t wiped first, years of scanned patient documents can walk out the door with the machine.
The patching blind spot
Printers and copiers are routinely left out of regular patch cycles. Only about 36% of organizations apply firmware updates to printers promptly, which leaves known vulnerabilities exposed for months or years at a time. Meanwhile, these devices usually sit on the same flat network as the EHR, front-desk workstations, and everything else — so a compromised printer isn’t an isolated problem, it’s a foothold.
The everyday risks nobody notices
- Print jobs sitting unattended in output trays where anyone walking by can see patient information.
- Unsecured network protocols that expose print traffic — including scanned document content — to anyone monitoring the network.
- Default admin credentials on the printer’s web management console, left unchanged since installation.
- Hard drives that retain cached jobs well after a service visit, a lease return, or a device swap.
Why this counts as a HIPAA problem
Regulatory pressure on this exact gap is increasing. HIPAA, PCI-DSS, and a growing number of state privacy laws now explicitly address document and device security, and organizations face real penalties for breaches that trace back to unsecured print infrastructure rather than a laptop or server. A risk analysis that skips the copier isn’t complete — and it’s an easy thing for an auditor to ask about directly.
What to actually do about it
- Inventory every networked printer, copier, and MFP the same way you’d inventory a laptop or server.
- Put these devices on their own segmented network, separate from the EHR and staff workstations.
- Apply firmware updates on a set schedule instead of leaving them for “whenever.”
- Turn on hard-drive encryption and enable automatic overwrite of stored jobs where the device supports it.
- Change default admin passwords on every device’s web management interface.
- Wipe or physically destroy the hard drive before any device is returned, traded in, or disposed of.
Where ACS fits in
Most practices have never included their printers and copiers in a device inventory or a HIPAA risk analysis. That’s exactly the kind of gap we look for during a free IT and HIPAA assessment — we’ll show you where these overlooked devices actually stand and what it would take to close the gap.


