Cloud Security Basics for EMR and File Sharing Tools

Most care organizations now rely on cloud services in some way: a hosted EMR, email in Microsoft 365 or Google Workspace, file sharing through a service like SharePoint or Dropbox, online scheduling or a hosted phone system. These tools can be more reliable and secure than equipment in a back closet. But cloud does not mean someone else handles everything. Understanding where the provider's responsibility ends and yours begins is the first step to using the cloud safely.

The shared responsibility model

Cloud providers are responsible for securing their infrastructure: the data centers, servers, networks and the core platform. You are responsible for how you use it.

Provider: physical security, platform availability, patching of underlying systems, base encryption

You: who has accounts, how they sign in, what permissions they hold, what data is stored, how devices connect, what is shared externally and how you respond to incidents

Most cloud-related breaches stem from customer-side configuration, such as weak passwords, accounts without multi-factor authentication, overly open sharing links or misconfigured storage, instead of failures in the provider's data center.

Business associate agreements and due diligence

If a cloud service stores or transmits PHI on your behalf, the provider is a business associate, and you need a signed business associate agreement. Many providers offer a BAA only on specific plans or with particular settings enabled, so read the terms. Consumer-grade accounts and free tiers generally do not qualify.

Before adopting a service, ask for security documentation, such as a summary of independent audit reports, and review the provider's incident notification commitments and data location practices.

Settings that matter most

Identity and sign-in

Require multi-factor authentication for all users, and especially administrators

Block legacy sign-in methods that cannot use MFA

Use conditional access rules where available, such as limiting sign-ins from unusual locations

Enforce strong passphrases and consider single sign-on

Protect administrator accounts with separate, dedicated credentials

Sharing and permissions

Set default sharing to internal only, and require approval or expiration for external links

Avoid anyone with the link settings for folders containing PHI

Use groups and roles instead of granting access to individuals

Review who has access to shared folders regularly

Limit who can create public links or invite guests

Data protection

Turn on encryption options, and understand who holds the keys

Apply retention policies so records are kept as long as required, and no longer than needed

Use data loss prevention features where available to flag or block sensitive information sent outside the organization

Make sure backups exist for cloud data, since many services provide limited recovery windows and are not a full backup

Logging and alerts

Enable audit logging and retain logs for a meaningful period

Set alerts for suspicious activity such as mass downloads, new forwarding rules or sign-ins from unusual places

Review administrator activity

Device control

Require managed or compliant devices for access to sensitive data

Enforce screen locks and encryption on devices that sync cloud files

Be able to remove cloud data from lost devices

Common pitfalls

Shadow IT. Staff sign up for free file sharing or messaging tools on their own and place PHI there. Offer approved alternatives that are easy to use, and make clear what is prohibited.

Unmanaged admin accounts. Global administrators who use their daily account for everything are high-value targets.

Forgotten accounts. Former employees may retain cloud access after leaving.

Public links that live forever. A link shared for a one-time purpose may stay active for years.

Assuming the cloud is the backup. Deleted or encrypted files can sync across devices.

EMR specifics

If you use a cloud-hosted EMR, such as PointClickCare, take advantage of its security features.

Use role-based permissions, aligned with job functions

Enable multi-factor authentication where available

Review audit logs for unusual access

Remove accounts promptly when staff leave

Understand the vendor's downtime and recovery procedures, and prepare paper downtime forms

Limit which networks or devices can reach the system, if the vendor allows

Review annually

As part of your risk analysis, list each cloud service, what data it holds, who administers it, whether a BAA is in place and which of the settings above are enabled. Revisit when the provider changes features or your use evolves.

A trusted second opinion

UnityCare IT helps healthcare organizations configure and review cloud services such as Microsoft 365 and file sharing platforms. If you want to know how your tenant measures up against the settings above, we can run a configuration review and walk through the results in plain language.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034