Remote access is a fact of life in healthcare. A medical director reviews charts from home, a billing specialist works remotely, a software vendor needs to troubleshoot a server. Each of these connections extends your network beyond the walls of the facility, and attackers constantly probe for weakly protected remote access. Exposed remote desktop services and poorly secured vendor connections are among the commonly cited ways into healthcare networks.
Here is how to offer remote access with sensible safeguards.
Start with a list of everyone who connects remotely, including:
Staff who work from home or travel
Physicians and contracted clinicians
Your IT provider
EHR, phone, camera and equipment vendors
Accountants and consultants
For each, record what they access, how they connect, how often and who approves it. Remove anyone who does not truly need it. The HIPAA minimum necessary standard suggests granting only what is required.
Opening a remote desktop port on your firewall is dangerous. Attackers scan for these continuously. If remote desktop is needed, place it behind a VPN or a secure gateway.
A virtual private network creates an encrypted tunnel into your network. Newer access tools can restrict users to specific applications instead of the whole network. Choose a solution that fits your size and keep it updated, since VPN appliances themselves are frequent targets of attack.
If the EHR is cloud-based, clinicians may only need a browser with multifactor authentication, which reduces the need for network-level access.
Every remote connection should require a second factor. Passwords alone are too easily stolen or guessed. This applies to staff, clinicians, IT providers and vendors without exception.
A protected connection from an infected personal laptop is still a risk.
Require up-to-date operating systems and security software.
Use disk encryption on devices holding PHI.
Prefer organization-managed devices for staff with broad access.
If personal devices are allowed, set clear rules and consider tools that separate work data from personal data.
Prohibit saving PHI to personal storage, and block it technically where you can.
Vendors are a common weak link. Put these controls in place:
Require a business associate agreement when PHI may be accessible.
Give each vendor technician an individual account, not a shared password.
Enable access only when needed, for example approving each session or using time-limited accounts.
Restrict vendor access to the specific systems they support.
Record sessions or at least log activity.
Ask vendors how they secure their own remote tools and employee devices.
Disable accounts promptly when a project ends.
Turn on logging for remote sign-ins, and review for patterns such as logins from unusual locations, repeated failures or access at odd hours. Set alerts for new administrator logins and impossible travel.
A short policy should state who may use remote access, required security measures, rules for personal devices, expectations in public places and consequences for violations. Staff need to know, for example, not to work with PHI on public Wi-Fi without a VPN, and to avoid screen exposure in public.
At least annually, and after any staffing change, review remote access accounts. Remove old users, close unused firewall rules and confirm that software is updated. Include remote access in your HIPAA risk analysis.
UnityCare IT designs and monitors secure remote access for healthcare organizations, including vendor access controls and multifactor authentication. If you are unsure who can reach your network from outside, we can help you find out and tighten it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034