Android kiosk mode for healthcare: top 10 MDM platforms in 2026

TL;DR
Android kiosk mode for healthcare is two problems wearing one name: a device policy problem your MDM solves, and an app problem it cannot. This 2026 ranking covers the ten platforms that solve the first half, scored on lock task depth, identity on shared devices, provisioning, remote support and published attestations. Scalefusion takes first place for mixed clinical fleets, with single and multi-app kiosk, a locked browser, shared device mode that logs off and clears app data between users, and ISO/IEC 27001:2022 with SOC 2 Type 2 behind it.
- Esper ranks second and is the only entry that will also sell you the operating system.
- Every platform here locks the screen. None of them gives a shared terminal a per-person identity, which the HIPAA Security Rule requires.
- Google Play's target API 36 deadline passed on August 31, 2026, with extensions running to November 1, 2026.
The healthcare kiosk market in 2026
The terminal in the hospital lobby is now a line item with a growth curve. The medical kiosk market grew from $1.99 billion in 2025 to $2.36 billion in 2026 and is forecast to reach $4.58 billion by 2030, an annual growth rate of 18%, according to Research and Markets.
Most of those terminals run Android, and Google treats the category as a first-class deployment mode. Android Enterprise calls them dedicated devices and names kiosks, digital signage and hospitality check-in as the customer-facing cases, with APIs for sharing one device between short-lived users and for freezing the operating system version through critical periods.
Healthcare then adds a rule the retail kiosk does not have. Under 45 CFR 164.312, assigning a distinct name or number to identify each user is a required implementation specification, while automatic logoff is addressable. A lobby tablet that every patient touches has to answer both. The console that locks the screen answers neither.
Two 2026 deadlines that change Android kiosk work
Two dates moved this year, and both land on the app rather than the console.
The first is Google Play. Since August 31, 2026, new apps and updates must target Android 16 (API level 36) to be submitted, and developers can request an extension to November 1, 2026. If your check-in app reaches the fleet through Managed Google Play, that clock applies to it. Permanently private apps distributed only inside one organization are exempt, a distinction most hospital IT teams have never had to make.
The second is regulatory and slower. HHS published the HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information on January 6, 2025. It would make every implementation specification mandatory and add a technology asset inventory. The final rule has slipped to July 2027, so nothing is in force yet. The inventory and patching cadence it describes are what an MDM produces, which is why every vendor below already sells against it.
A third change is quieter and breaks working configurations. In the Android Management API, statusBarDisabled and lockTaskAllowed are deprecated; a kiosk app is now declared by setting its install type to KIOSK. Policies written three years ago still sit in consoles and still look correct.
How we evaluated
Five criteria, applied to every platform below:
- Lock task depth: single and multi-app kiosk, control over system UI, behavior after a reboot or a crash.
- Identity on shared devices: whether the platform can tell one clinician from the next, or only one device from the next.
- Provisioning and remote support: zero-touch and QR enrollment, remote control of an unattended screen, staged rollout.
- Published attestations: what the vendor holds, with a signed business associate agreement kept separate from any marketing line.
- App-layer reach: managed configurations, private app distribution, custom OS or browser control.
Every platform carries a watch-out. A ranking with no negatives is an advertisement. One disclosure: we build software and do not sell device management, so nothing here competes with us and nothing here pays us.
The top 10 at a glance
| Platform | Best for | Kiosk model | Watch-out |
|---|---|---|---|
| Scalefusion | Mixed clinical fleets | Single and multi-app, kiosk browser, shared device mode | Remote control sees the screen |
| Esper | Purpose-built and patient-shipped hardware | Kiosk browser plus a custom OS | HIPAA absent from its attestations |
| SOTI MobiControl | Rugged and peripheral-heavy fleets | Deep peripheral support | Enterprise weight and pricing |
| Samsung Knox Manage | Samsung-standardized hospitals | API kiosks plus OEM-level config | Fades on mixed hardware |
| ManageEngine MDM Plus | One tool for the whole estate | Kiosk mode plus app allowlisting | Markets HIPAA compliance |
| 42Gears SureMDM | Varied non-phone hardware | Lockdown-first console | No named hospital references |
| Hexnode UEM | Clinic groups without a mobility team | App or website lockdown | Silent on PHI |
| Microsoft Intune | Providers on Microsoft identity | Managed Home Screen plus Entra shared mode | Needs Google Mobile Services |
| Omnissa Workspace ONE UEM | Health systems consolidating | Dedicated devices inside a suite | Two owners since 2023 |
| AirDroid Business | Small fleets and pilots | Android and Windows lockdown | Statistics without sources |
1. Scalefusion
Scalefusion maps Android controls onto care settings more directly than anything else here: care team handhelds, check-in kiosks, telehealth devices and remote monitoring each get a configuration path of their own. On Android that means single and multi-app kiosk, a locked kiosk browser, zero-touch and QR enrollment, remote cast and control, plus shared device mode that clears app data between users.
Best for: mixed clinical fleets where one console runs a lobby kiosk and a nurse handheld. Facts: HQ Pune, India; 12,000+ businesses across 120+ countries; ISO/IEC 27001:2022 certified and SOC 2 Type 2 compliant; OEM integrations including Zebra and Samsung Knox. Watch-out: remote control of an unattended terminal means someone in the console sees whatever is on that screen. Settle where those frames live before the first kiosk displays PHI.
2. Esper
Esper was built for dedicated fleets rather than adapted to them, and it is the only vendor here that will also sell you the operating system. Esper Foundation is a custom Android build for OEM-independent OS control, Titanium is its kiosk browser, and drift management alerts when a device leaves its intended state. Its healthcare page leans on remote monitoring and clinical trials, where the tablet goes home with the patient.
Best for: purpose-built or patient-shipped hardware where you control the whole device image. Facts: founded in 2018 and based in Bellevue, Washington; support listed for over 1,500 device models; PCI DSS, SOC 2 Type 2 and ISO 27001 shown as the compliance set. Watch-out: HIPAA is not among those frameworks. Ask for the business associate agreement explicitly.
3. SOTI MobiControl
SOTI was managing devices before smartphones existed, and MobiControl still shows it where it counts. Rugged handhelds, barcode scanners and connected printers are the hard part of a hospital fleet, and this is the platform most clinical hardware vendors have already tested against.
Best for: large hospital systems with rugged and peripheral-heavy deployments. Facts: founded 1995; HQ Mississauga, Ontario; 17,000+ enterprise customers across 176 countries with over 20 million devices under management. Watch-out: a single clinic ends up buying a platform built for a hospital group, then staffing it to match.
4. Samsung Knox Manage
If the hardware standard is already Samsung, the console that knows that hardware best belongs to Samsung. Knox Manage builds kiosks on the Android Management API in single-app and multi-app modes, and Knox Configure handles device customization before a unit reaches the ward.
Best for: hospitals standardized on Samsung tablets and handhelds. Facts: kiosk apps come through Managed Google Play only; interface customization is limited to a few elements such as the status and navigation bars, and the Kiosk Wizard is unavailable for Android Management API profiles. Watch-out: the depth is Samsung-shaped. Add one non-Samsung model and half the advantage goes away.
5. ManageEngine Mobile Device Manager Plus
ManageEngine publishes the most complete buyer checklist of the group. One console covers Android, iOS, iPadOS, Windows, macOS, tvOS, ChromeOS plus rugged hardware, with kiosk mode, app allowlisting, remote lock and wipe, audit logs and compliance reporting, plus direct answers about HL7 and FHIR environments.
Best for: hospital IT teams that want one tool for clinical mobile and the rest of the estate. Facts: part of Zoho's ManageEngine division; documents shared-device and BYOD management with role-based access and encrypted work containers. Watch-out: the page advertises HIPAA-compliant management. No software is HIPAA certified, because no such certification exists.
6. 42Gears SureMDM
42Gears came at device management from the lockdown side, and its healthcare page is unusually concrete about what a hospital fleet contains: workstations on wheels, barcode scanners, medical kiosks and mobile clinical devices, alongside the smartphones every vendor lists. SureMDM runs them from one console across the major operating systems.
Best for: deployments where the hardware is varied and most of it is not a phone. Facts: founded in 2009; SureMDM manages smartphones, wearables, pagers, handhelds and tablets across all major platforms. Watch-out: the healthcare page names no hospital references and no attestations. Ask for both before the pilot.
7. Hexnode UEM
Hexnode is the easiest console here to hand to a two-person IT team. Kiosk mode locks a device to one app, several apps or a set of websites, and OEM support reaches past Samsung Knox to LG and Kyocera hardware. Hexnode says it was recognized in the 2026 Gartner Magic Quadrant for Endpoint Management Tools in January.
Best for: clinic groups and mid-size providers with no dedicated mobility team. Facts: the enterprise software division of Mitsogo Inc., headquartered in San Francisco; platforms include iOS, macOS, tvOS, Android and Windows. Watch-out: the healthcare page is written around tablets replacing paperwork and says nothing about PHI on a shared screen, which is the part that fails an audit.
8. Microsoft Intune
If the hospital already runs Microsoft 365, Intune is the default answer and the default is defensible. It enrolls dedicated devices with no user account, or with Microsoft Authenticator and Microsoft Entra shared device mode, which gives one sign-in and sign-out across participating apps. That is the closest thing here to an answer for who is holding the shared tablet.
Best for: providers standardized on Microsoft identity. Facts: dedicated devices require Android 8.0 or later with Google Mobile Services; multi-app kiosk runs through the Managed Home Screen app. Watch-out: that requirement rules out AOSP-only medical hardware, and kiosk customization is shallower than the specialists offer. Shared device mode covers only apps that implement it, which will not include your clinical app unless somebody builds that in.
9. Omnissa Workspace ONE UEM
Workspace ONE is the platform many large health systems already own, inherited through years of AirWatch and VMware contracts. It manages Android dedicated devices alongside Windows workstations and Apple hardware, inside a full digital workspace suite.
Best for: enterprise health systems consolidating endpoint management across clinical and corporate estates. Facts: established in 2024 as a standalone company, after the VMware end-user computing business was spun out following Broadcom's 2023 acquisition. Watch-out: two ownership changes since 2023, and Android dedicated-device work is a small corner of a very large product.
10. AirDroid Business
AirDroid Business is the budget entry and does not pretend otherwise: kiosk lockdown across Android and Windows, bulk enrollment, remote control and staged rollout, at a published $1 to $2.75 per device per month against a market it puts at $2 to $9.
Best for: small fleets and pilots where the realistic alternative is no management at all. Facts: per-device pricing published openly, which almost nobody else here does; staged deployment so a bad build does not reach the whole fleet at once. Watch-out: its healthcare article carries breach and penalty statistics attributed to unnamed studies. Useful product, weak evidence.
Which platform fits your deployment
Ranking is one thing. Fit is another.
| Your situation | Platform to shortlist |
|---|---|
| Check-in kiosks and clinical handhelds on one console | Scalefusion |
| Tablets you ship to patients, or hardware you spec | Esper |
| Rugged scanners and medication carts at scale | SOTI MobiControl |
| Samsung hardware standard across every site | Samsung Knox Manage |
| One console for clinical and corporate endpoints | ManageEngine Mobile Device Manager Plus |
| Lockdown is the requirement, and the fleet is not phones | 42Gears SureMDM |
| A clinic group with no mobility specialist | Hexnode UEM |
| Microsoft identity already governs clinical access | Microsoft Intune |
| A health system consolidating after a merger | Omnissa Workspace ONE UEM |
| A pilot on a handful of devices | AirDroid Business |
What the app inside the lock has to do
Every console above does the same things to a device: pins an app, hides system UI, pushes updates, reports state, wipes on loss. None of them changes what happens inside the app. Three requirements land on the build instead, and they decide whether the deployment holds.
The app has to be configurable from the console. Android calls this managed configurations: the app declares a restrictions file in its manifest, and the EMM reads that schema to generate the admin screens. Without it, an MDM can install your app and pin the screen to it, then has nothing to configure. Server URL, site identifier, timeout length: each becomes a rebuild instead of a checkbox.
The app has to own the session. Lock task mode restricts what a person can reach, not who that person is. When a patient walks away mid-form, no device policy ends the session or flushes the cache. The app does that, or nobody does.
The app has to survive being the home screen. On a dedicated device it launches at boot and the person in front of it cannot leave, so there is nowhere to fall back to when it crashes. Watchdog restart, offline queueing and a recovery path that needs no technician on site are app features, not console settings.
We build this layer. For ORIGO we wrote the mobile side of a device monitoring product: it blocks apps that are not on the allowlist while a vehicle is moving, shows a dedicated screen when the driver is not authorized, and carries remote debugging so support can fix devices nobody can drive to. We cut its traffic to 8 MB per device per month. For MiMedia our app shipped factory-installed as the default gallery on Micromax phones. For BrandSource an Apple TV build runs unattended in hundreds of US retail locations. One problem in three industries: the app lives on hardware its user did not choose and cannot fix.
What healthcare teams bring us before they pick an MDM
Most comparisons stop at the ranking. This is the demand side, from our own scoping notes.
Through September 2026 Mercury Development reviewed the device and platform constraints recorded across the healthcare and telehealth companies that scoped custom development with us. A pattern counts below only when at least three companies raised it independently, and no client is identifiable from the aggregate.
Around 10% arrived with a product that had to run on hardware the organization owns rather than on anyone's personal phone: a kiosk-mode tablet in a corridor, a wall-mounted monitor, a touch panel outside a resident's room, a tablet attached to a rehabilitation robot. All of them named kiosk startup and operating system lockdown as a requirement before shortlisting a vendor, and several named the device model and the oldest Android build they had to keep alive.
Around 15% brought regulatory privacy and security demands as one undifferentiated bundle that nobody had translated into software requirements, sometimes with data residency attached. That is the most corroborated theme in our healthcare pipeline, and it is a scoping problem before it is a legal one.
Around 10% needed frontline tools for staff with no technical background, where using the app is not the job. Kiosk interfaces get designed by the admin who configures them and used by a nurse with both hands full.
One pattern came up for geography rather than security: remote support for sites too far away to send anybody for a restart. It decides more shortlists than kiosk feature tables do.
Kiosk mode is not an access control
Vendors sell kiosk mode as a security feature. It is a usability feature with security side effects, and in a HIPAA environment that difference matters.
Locking a tablet to one app restricts what a person can do. It says nothing about who that person is. Assigning a distinct identifier to every user is a required implementation specification under 45 CFR 164.312, not an addressable one, and a shared terminal running on a single device account cannot attribute an access to anybody. NIST's resource guide for the Security Rule keeps access control and authentication separate for the same reason.
There are three honest answers. Put identity in the app, with a badge tap or PIN that opens and closes a named session. Use the platform: Android has supported short-lived users on dedicated devices since Android 9, so a public terminal can pass between people without carrying state across. Or stay anonymous on purpose and design the workflow so the kiosk never shows a stranger anything worth reading. That last one is a product decision, not a configuration.
We build the app side of this, not the console. EyeIC is a 510(k) FDA-cleared imaging application we moved from Windows desktop to a multi-user web platform with HIPAA-compliant online access in 3 months. Precision Practice Management has been in production since 2006. Mercury Development builds to HIPAA and GDPR requirements with 500+ engineers, shipping since 1999. No MDM here makes you compliant, and any vendor implying otherwise is selling you a screen lock.
Written by Alexey Rodionov, Lead Front-end Developer at Mercury Development since 2020. Alexey is a Google Developer Expert in Web Technologies and a Chromium contributor whose code ships in Chrome DevTools, Google's Bubblewrap and Microsoft PWABuilder. The browser behavior, packaging limits and platform constraints behind this article come from the front-end practice he leads.
Scoping a locked-down Android build? Start with the app layer
Pick your MDM on the device criteria above. Then send us the app that has to live inside it: what it shows, who touches it, and what happens when the network drops with nobody standing there. We will map the managed configurations, the session boundaries and the recovery path before anyone signs a console contract.
Frequently asked questions
What is Android kiosk mode in healthcare?
Kiosk mode locks an Android device to a single app or a defined set of apps. The person using it cannot reach the launcher or the settings. In healthcare that covers check-in terminals, bedside tablets, medication carts and shared nurse handhelds. Android Enterprise calls the underlying capability lock task mode, and only a device policy controller can switch it on.
Is kiosk mode HIPAA compliant?
No, and no product is. HIPAA compliance is a property of an organization, not of software. Kiosk mode helps with two safeguards: it restricts what a device can do, and with session timeouts it supports the automatic logoff specification at 45 CFR 164.312. Access logging and risk analysis stay yours whichever console you buy.
What is the difference between kiosk mode and lock task mode?
Lock task mode is the Android platform feature. Kiosk mode is what MDM vendors call the product wrapper around it. Lock task mode has existed since Android 5.0 and needs a device policy controller to allowlist apps first. Screen pinning looks similar, but the person can leave it whenever they want, which rules it out for a public terminal.
Which MDM is best for Android kiosks in healthcare in 2026?
Scalefusion ranks first in this 2026 comparison for mixed clinical fleets, because it maps Android controls onto check-in kiosks, clinical handhelds and telehealth devices directly and holds ISO/IEC 27001:2022 with SOC 2 Type 2. Esper suits purpose-built or patient-shipped hardware better, and Microsoft Intune is the pragmatic choice when the hospital already runs Microsoft identity.
How much does MDM for healthcare kiosks cost in 2026?
Published prices are rare in this category. AirDroid Business lists $1 to $2.75 per device per month and puts the wider market at $2 to $9. Enterprise vendors quote per device per year and discount on volume, so the useful question is what renewal costs at your fleet size, not what the list price says today.
Can a patient check-in kiosk use one shared login?
Technically yes, and it is a common audit finding. The Security Rule requires a distinct identifier for each user, so a shared account cannot attribute an access to a person. For patient-facing terminals the cleaner answer is to keep the session anonymous and short, and to design the screen so it never displays another patient's data.
Do I need a business associate agreement with my MDM vendor?
If the platform can touch PHI, yes. Remote control, screenshots, log collection and cloud backup all create paths for patient data to reach the vendor. Several healthcare pages in this comparison advertise HIPAA-aligned features without mentioning an agreement at all. Ask for it in writing, and ask what the console retains and for how long.
How do you deploy hundreds of Android kiosks without touching each device?
Zero-touch enrollment and QR code provisioning do that work. A device ordered through a zero-touch reseller enrolls itself into your MDM on first boot and applies its policy before anyone signs in. QR provisioning handles devices already in hand, after a factory reset. Both are standard Android Enterprise mechanisms, so ask how well a console drives them, not whether it supports them.
Does kiosk mode stop my app from being updated?
No. Apps on dedicated devices update through Managed Google Play or the vendor's own distribution channel, independently of the lock. Google Play's target API rules still apply: since August 31, 2026, updates must target Android 16, with extensions available to November 1, 2026. Permanently private apps distributed only inside one organization are exempt from that requirement.
Can a web app run in Android kiosk mode?
Yes, and it is common for check-in flows. Most MDM platforms ship a locked browser that allows only approved URLs, and a web app can also be packaged as an Android app and pinned like any other. The trade-off: the browser engine updates on its own schedule, so the page has to tolerate an engine version you did not pick.
Does my app need changes to work with an MDM?
Usually yes. To be configurable from the console, an Android app declares managed configurations in its manifest, and the EMM reads that file to build the admin screens. Without it the MDM can install and pin the app but cannot set a server URL or a site identifier. Session timeout, offline queueing and crash recovery are app-side work.