Physicians reviewing orders from home, a director of nursing checking a schedule on a weekend, a vendor fixing a billing problem: remote access is a normal part of healthcare operations. How it is set up makes the difference between a convenience and an open door.
One setup deserves special attention. Remote Desktop Protocol (RDP) exposed directly to the internet, often by forwarding a port on the firewall, has long been a common way for ransomware operators to gain entry. Attackers constantly scan the internet for it, then guess or buy stolen passwords. If your facility still has this configuration, fixing it should be near the top of your list.
It is visible to anyone on the internet, so it is probed constantly
Passwords alone often protect it, and passwords get stolen or guessed
Successful login can give an attacker a full desktop inside your network
Logs are often not monitored, so attacks go unnoticed
CISA and other agencies have repeatedly warned about exposed remote services. If you are unsure whether you have this exposure, ask your IT provider to scan your public internet addresses.
A virtual private network creates an encrypted tunnel from the user's device to your network. Combined with MFA, it means a stolen password alone is not enough. Keep the VPN appliance or software patched, because vulnerabilities in VPN products are regularly exploited. Limit what VPN users can reach rather than giving them the whole network.
Instead of exposing individual computers, users sign in through a gateway or access service that checks identity, device health and permissions before connecting them to a specific application or desktop. This approach tends to give finer control and better logging than a traditional VPN.
When your EMR and other key systems are web-based, many remote access needs disappear. Staff sign in with their own accounts and MFA through a browser. This is one reason cloud systems are attractive for facilities with limited IT staff.
Virtual desktop solutions keep data on servers instead of on the remote device, which reduces the risk if a personal computer or laptop is lost or infected.
Require MFA for all remote access, without exceptions for executives or physicians.
Use unique accounts. Never share a remote login among staff or vendors.
Limit access by role. A billing clerk does not need access to the servers.
Keep software patched, including VPN devices, gateways and firewalls.
Turn on logging and review it, or have someone review it for you. Alert on repeated failed logins and logins from unusual locations.
Lock out repeated failures to slow password guessing.
Restrict by geography if staff only work from the United States.
Use device checks where possible, so only managed and updated devices connect.
Vendors who support your clinical and building systems often ask for permanent remote access. Treat them like any other remote user.
Give each vendor technician a named account
Enable access only when needed, if the system allows it
Require MFA
Review which vendors have access every quarter
Remove access when the contract ends
Many significant breaches have come through a vendor's connection rather than the organization's own staff.
Staff and physicians often want to use their own computers and phones. If you allow it, set clear expectations: up-to-date operating systems, screen locks, encryption, no saving resident data locally, and the right to remove work access if a device is lost. HIPAA's Security Rule expects safeguards for devices that access ePHI, whether or not you own them.
Ask your IT provider:
Is RDP or any other remote administration tool reachable directly from the internet?
Is MFA required for every remote login?
When was our VPN or gateway last patched?
Which vendors have remote access, and is each account named and necessary?
Who reviews remote access logs, and how often?
If any answer is "I am not sure," that is useful information in itself.
UnityCare IT helps healthcare organizations replace exposed remote access with MFA-protected alternatives and manage vendor connections. We can start with a simple exposure check of your internet-facing systems and go from there.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172