Remote access has become a normal part of healthcare operations. Corporate staff work from home, managers check systems after hours, and vendors connect in to support the EHR, phone system or nurse call equipment. Each of those connections is a door into your network, and attackers know which doors are most often left unlocked.
This post gives administrators a plain-English way to review remote access, even if you are not technical. You can use these questions with your IT team or provider.
Begin with an inventory. Common paths include:
A VPN on your firewall
Remote desktop (RDP) to servers or desktops
Remote support tools used by vendors
Cloud services reached through a web browser
Remote management tools used by your IT provider
Old connections set up years ago and forgotten
For each one, record who uses it, why, and who approved it. Any entry nobody can explain should be investigated and probably removed.
A password alone should not be enough to reach your network. This is the single most important check. If a VPN or remote tool allows sign-in without a second factor, treat that as a high priority fix.
VPN appliances and firewalls have been repeatedly targeted through known vulnerabilities, and CISA regularly publishes alerts about them. Confirm that firmware is current, that you receive security notices from the manufacturer, and that someone is responsible for applying updates promptly. Devices that are past end of support should be replaced.
RDP open to the internet is a well-known ransomware entry point. If you must use remote desktop, place it behind a VPN or a secure gateway with MFA, and restrict who can connect.
Review accounts for former employees, former vendors and test users. Remove those who no longer need access, and limit remaining users to the systems they must reach rather than the whole network.
You should be able to see who connected, when and from where. Alerts for logins from unusual countries or at odd hours can catch a stolen credential early.
Vendors that support clinical or building systems often need remote access, and some request permanent, always-on connections. Set clear terms:
Use named accounts for each technician, not shared vendor logins
Enable access only when needed, and turn it off afterwards where practical
Require MFA and restrict the systems each vendor can reach
Confirm that a business associate agreement is in place if the vendor can see protected health information
Ask how they would notify you of a security incident
For staff who work from home:
Use company-managed laptops with encryption and endpoint protection where possible
Avoid saving resident information on personal computers or personal cloud storage
Use a VPN or secure cloud applications rather than sharing files by personal email
Keep home routers updated and protected by strong passwords
Never use public computers or open public Wi-Fi without a VPN
HIPAA's Security Rule does not ban remote work, but it expects the same safeguards to apply wherever ePHI is accessed.
Score yourself yes or no:
We have a current list of all remote access methods.
MFA is required on every one.
Firewall and VPN firmware is current.
No remote desktop is exposed directly to the internet.
Vendor access uses named accounts and is limited.
Former users have been removed in the last quarter.
We review remote access logs on a regular schedule.
Any no is a place to begin.
UnityCare IT can review your remote access setup, test for exposed services and help you replace risky connections with safer options. If you would like a straightforward second opinion, get in touch.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034