Most care organizations now rely on cloud services in some way: a hosted EMR, email in Microsoft 365 or Google Workspace, file sharing through a service like SharePoint or Dropbox, online scheduling or a hosted phone system. These tools can be more reliable and secure than equipment in a back closet. But cloud does not mean someone else handles everything. Understanding where the provider's responsibility ends and yours begins is the first step to using the cloud safely.
Cloud providers are responsible for securing their infrastructure: the data centers, servers, networks and the core platform. You are responsible for how you use it.
Provider: physical security, platform availability, patching of underlying systems, base encryption
You: who has accounts, how they sign in, what permissions they hold, what data is stored, how devices connect, what is shared externally and how you respond to incidents
Most cloud-related breaches stem from customer-side configuration, such as weak passwords, accounts without multi-factor authentication, overly open sharing links or misconfigured storage, instead of failures in the provider's data center.
If a cloud service stores or transmits PHI on your behalf, the provider is a business associate, and you need a signed business associate agreement. Many providers offer a BAA only on specific plans or with particular settings enabled, so read the terms. Consumer-grade accounts and free tiers generally do not qualify.
Before adopting a service, ask for security documentation, such as a summary of independent audit reports, and review the provider's incident notification commitments and data location practices.
Require multi-factor authentication for all users, and especially administrators
Block legacy sign-in methods that cannot use MFA
Use conditional access rules where available, such as limiting sign-ins from unusual locations
Enforce strong passphrases and consider single sign-on
Protect administrator accounts with separate, dedicated credentials
Set default sharing to internal only, and require approval or expiration for external links
Avoid anyone with the link settings for folders containing PHI
Use groups and roles instead of granting access to individuals
Review who has access to shared folders regularly
Limit who can create public links or invite guests
Turn on encryption options, and understand who holds the keys
Apply retention policies so records are kept as long as required, and no longer than needed
Use data loss prevention features where available to flag or block sensitive information sent outside the organization
Make sure backups exist for cloud data, since many services provide limited recovery windows and are not a full backup
Enable audit logging and retain logs for a meaningful period
Set alerts for suspicious activity such as mass downloads, new forwarding rules or sign-ins from unusual places
Review administrator activity
Require managed or compliant devices for access to sensitive data
Enforce screen locks and encryption on devices that sync cloud files
Be able to remove cloud data from lost devices
Shadow IT. Staff sign up for free file sharing or messaging tools on their own and place PHI there. Offer approved alternatives that are easy to use, and make clear what is prohibited.
Unmanaged admin accounts. Global administrators who use their daily account for everything are high-value targets.
Forgotten accounts. Former employees may retain cloud access after leaving.
Public links that live forever. A link shared for a one-time purpose may stay active for years.
Assuming the cloud is the backup. Deleted or encrypted files can sync across devices.
If you use a cloud-hosted EMR, such as PointClickCare, take advantage of its security features.
Use role-based permissions, aligned with job functions
Enable multi-factor authentication where available
Review audit logs for unusual access
Remove accounts promptly when staff leave
Understand the vendor's downtime and recovery procedures, and prepare paper downtime forms
Limit which networks or devices can reach the system, if the vendor allows
As part of your risk analysis, list each cloud service, what data it holds, who administers it, whether a BAA is in place and which of the settings above are enabled. Revisit when the provider changes features or your use evolves.
UnityCare IT helps healthcare organizations configure and review cloud services such as Microsoft 365 and file sharing platforms. If you want to know how your tenant measures up against the settings above, we can run a configuration review and walk through the results in plain language.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034