Medical directors, attending physicians, therapists, pharmacists and consultants do not work from your building every day. They review charts from clinics, hospitals and home offices, often on their own devices. Giving them access is necessary for good care, but each remote connection is also a door into your systems.
Leaving that door unlocked, or handing out a shared remote login, is a common source of breaches. Here is how to provide remote access responsibly.
Start with a list of every outside person who needs remote access. For each, record:
Name and organization
Role and reason for access
Which systems and resident records they need
Whether a signed confidentiality agreement or business associate agreement is in place
An approval owner within your facility, and an end date or review date
Minimum necessary access applies. A pharmacist reviewing medication regimens does not need billing records. A visiting therapist may need only residents on their caseload.
Each person should have their own account. Avoid shared credentials such as a single physician login. Shared accounts make auditing impossible and make it hard to cut off one person's access if they leave. Where possible, use the EHR's built-in role for outside providers.
Remote access should always require a second factor. Passwords alone are not enough when a connection is reachable from the internet. Choose methods that work for busy professionals, such as authenticator apps or security keys, and provide a backup method.
There are several ways to provide remote access, and some are riskier than others.
Web-based EHR portals. If your EHR is cloud-hosted, access through the vendor portal with MFA is often the safest and simplest option.
Virtual private network. A VPN encrypts traffic and connects to your network. It should require MFA, be kept patched, and limit what users can reach once connected.
Virtual desktops. Providers connect to a controlled desktop running inside your environment, so data stays in your systems rather than on their device.
Avoid exposed remote desktop. Opening remote desktop directly to the internet is a well-known entry point for attackers and should be avoided.
Whichever method you choose, restrict access by role and log every session.
If providers use personal computers or tablets, consider:
Requiring up-to-date operating systems and endpoint protection
Requiring screen locks and disk encryption
Prohibiting saving or downloading resident records to local storage unless necessary and protected
Blocking access from devices that fail basic security checks, where your tools support it
Providing guidance on public Wi-Fi, shared family computers and printing
A short written agreement on acceptable device use helps set expectations.
Remote access logs show who connected, when and from where. Review them periodically and set alerts for unusual patterns, such as logins from unexpected countries, repeated failures, or activity in the middle of the night. Many EHR platforms also offer audit reports on which records a user viewed.
Stale accounts are a major risk. Build a process to:
Review outside-provider accounts at least quarterly
Disable accounts when a contract ends or a provider leaves
Reconfirm access needs for anyone who has not logged in recently
Document each review
These practices support the HIPAA Security Rule requirements around workforce security, access management and information system activity review.
Outside professionals are busy, and they may not know your policies. Provide a one-page summary covering how to log in, how to report a lost device or suspicious message, and who to call for help. Make support easy, so they do not resort to workarounds like emailing records.
If a medical director needs urgent access after hours, there should be a documented way to get it quickly and securely. Having a defined process avoids staff improvising by sharing screens or credentials.
Remote access belongs in your HIPAA risk analysis. Note the methods used, controls applied and any gaps. If you rely on third-party practices, confirm they have appropriate safeguards and agreements in place.
UnityCare IT helps healthcare organizations design and manage secure remote access for physicians, therapists and consultants, including VPN, MFA and access reviews. If your current approach relies on shared logins or ad hoc connections, we can help replace it with something safer and easier to manage.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172