The organization must determine what kind of people (workforce members, visitors, etc.) are allowed to use foreign devices.
HIPAA Security Rules 164.310(d)(1): Device and Media Controls: Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility, and the movement of these items within the facility.
Start with Fluid Attacks
We are a proud corporate member of the OWASP Foundation