Much of modern IT support happens without a technician ever walking into your building. A support agent connects remotely, sees your screen and fixes the problem in minutes. For multi-site operators across Oklahoma, Texas and Arkansas, it is often the only practical way to provide fast help.
Remote access also hands someone control of a computer that may hold protected health information. That makes it important to know what safe remote support looks like, and how to tell a legitimate session from a scam.
Speed. No travel time means faster resolution.
Consistency. The same tools and procedures are used across locations.
After-hours help. Issues can be handled at night without a trip to the facility.
Lower cost. Many problems do not need an on-site visit.
Some work still needs hands on equipment, such as replacing a failed switch, running cable or swapping a printer.
Your IT provider should use a professional remote support platform with encryption, logging and access controls. Free consumer tools with shared passwords are not appropriate for healthcare environments.
Before a technician connects, you should be able to verify that they are who they say they are. A good provider has a consistent process, such as a ticket number, a call from a known number or an invitation sent from the helpdesk system you recognize.
For attended sessions, the user should have to approve the connection, and should be able to see what is happening and end it at any time. The technician should explain what they are doing.
Technicians should have individual accounts, with multi-factor authentication, rather than a single shared login. Sessions should be recorded or logged so you can see who connected, when and for what reason. Access rights should be limited to what the job requires.
Because a technician might see resident information on a screen, a provider that supports healthcare should sign a business associate agreement and train its staff on privacy. Where possible, staff should close charts before a session begins. Technicians should avoid viewing PHI beyond what is needed to solve the problem.
Some tools permit connection to a device without anyone present, which is useful for patching and overnight work. This should be controlled with strong authentication, restricted by role, and documented.
Criminals pose as tech support to gain access to computers. Warning signs include:
An unsolicited call or pop-up claiming your computer has a virus and you must call a number immediately.
A caller who asks you to install software or visit a website to allow them to connect when you did not request help.
A request for passwords, verification codes or payment by gift card.
Pressure to act quickly or to keep the call secret.
Teach staff a simple rule: if you did not request help, do not allow access. Hang up, and call the helpdesk number you already know. Report the attempt. If someone did let a caller in, disconnect the computer from the network, call IT right away and change passwords from a different device.
Which tools do you use for remote access, and how are they secured?
Do technicians use individual accounts with MFA?
Are sessions logged, and can we view the logs?
How do we verify a technician is legitimate?
Do you have a business associate agreement with us?
How do you handle remote access to servers and network equipment?
Staff may allow remote access only for support requests they or their manager initiated through the official channel.
Vendors who need remote access to systems must go through IT.
Remote tools not approved by IT are not to be installed.
UnityCare IT provides remote and on-site helpdesk support for healthcare and senior living organizations, using logged and secured tools. We are happy to explain exactly how our support sessions work and how you can confirm they are genuine.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172