Is Your Remote Access Safe? A Plain-English VPN and RDP Review

Remote access has become a normal part of healthcare operations. Corporate staff work from home, managers check systems after hours, and vendors connect in to support the EHR, phone system or nurse call equipment. Each of those connections is a door into your network, and attackers know which doors are most often left unlocked.

This post gives administrators a plain-English way to review remote access, even if you are not technical. You can use these questions with your IT team or provider.

Know what is open

List every way in

Begin with an inventory. Common paths include:

A VPN on your firewall

Remote desktop (RDP) to servers or desktops

Remote support tools used by vendors

Cloud services reached through a web browser

Remote management tools used by your IT provider

Old connections set up years ago and forgotten

For each one, record who uses it, why, and who approved it. Any entry nobody can explain should be investigated and probably removed.

Questions for each connection

Is multi-factor authentication required?

A password alone should not be enough to reach your network. This is the single most important check. If a VPN or remote tool allows sign-in without a second factor, treat that as a high priority fix.

Is the software up to date?

VPN appliances and firewalls have been repeatedly targeted through known vulnerabilities, and CISA regularly publishes alerts about them. Confirm that firmware is current, that you receive security notices from the manufacturer, and that someone is responsible for applying updates promptly. Devices that are past end of support should be replaced.

Is remote desktop exposed directly to the internet?

RDP open to the internet is a well-known ransomware entry point. If you must use remote desktop, place it behind a VPN or a secure gateway with MFA, and restrict who can connect.

Who has access, and do they still need it?

Review accounts for former employees, former vendors and test users. Remove those who no longer need access, and limit remaining users to the systems they must reach rather than the whole network.

Are sessions logged and monitored?

You should be able to see who connected, when and from where. Alerts for logins from unusual countries or at odd hours can catch a stolen credential early.

Vendor and third-party access

Vendors that support clinical or building systems often need remote access, and some request permanent, always-on connections. Set clear terms:

Use named accounts for each technician, not shared vendor logins

Enable access only when needed, and turn it off afterwards where practical

Require MFA and restrict the systems each vendor can reach

Confirm that a business associate agreement is in place if the vendor can see protected health information

Ask how they would notify you of a security incident

Remote work practices

For staff who work from home:

Use company-managed laptops with encryption and endpoint protection where possible

Avoid saving resident information on personal computers or personal cloud storage

Use a VPN or secure cloud applications rather than sharing files by personal email

Keep home routers updated and protected by strong passwords

Never use public computers or open public Wi-Fi without a VPN

HIPAA's Security Rule does not ban remote work, but it expects the same safeguards to apply wherever ePHI is accessed.

Quick scorecard

Score yourself yes or no:

We have a current list of all remote access methods.

MFA is required on every one.

Firewall and VPN firmware is current.

No remote desktop is exposed directly to the internet.

Vendor access uses named accounts and is limited.

Former users have been removed in the last quarter.

We review remote access logs on a regular schedule.

Any no is a place to begin.

Next steps

UnityCare IT can review your remote access setup, test for exposed services and help you replace risky connections with safer options. If you would like a straightforward second opinion, get in touch.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034