Not everyone who needs access to resident information works inside the building. Therapists travel between sites, billing and coding staff work from home, regional nurses and administrators visit several communities, and vendors need occasional access to fix systems. Each of these connections is a potential doorway into your network, and attackers actively scan for weak ones.
Secure remote access is about choosing the right method for each group and applying a consistent set of controls.
Many attacks begin with a remote desktop service exposed to the internet, a VPN without multifactor authentication, or credentials reused from another breached site. Once inside, attackers move to file servers and backups. Closing off these paths is among the most valuable steps an organization can take.
If your EHR and other core tools are web-based, staff may need nothing more than a browser and strong sign-in. This avoids bringing remote devices onto your internal network at all, and is often the simplest model.
A virtual desktop runs on a secure server, and the user sees only the screen. Data stays in the hosted environment, not on the remote device. This is useful for staff handling large amounts of PHI on personal or unmanaged computers, though it adds cost and complexity.
A virtual private network creates an encrypted tunnel into your network. It works well for company-managed laptops, but should require MFA, use current firmware and limit which resources a user can reach.
Avoid it. Opening remote desktop directly to the internet is a frequent source of ransomware incidents.
Multifactor authentication for every remote login
Unique accounts for every person, never shared
Least privilege, so a billing employee cannot reach clinical systems unnecessarily
Device standards, including updated operating systems, endpoint protection, disk encryption and screen locks
Logging and alerts for sign-ins from unusual locations or at unusual times
Session timeouts so abandoned sessions close
Prompt account removal when someone leaves or changes roles
Company-owned, centrally managed laptops are easiest to secure. If personal devices are allowed, set clear policies:
Require a device management or secure container solution
Block saving PHI to local storage where possible
Require current operating system versions and a device passcode
Establish that the organization may wipe work data when the person leaves or the device is lost
Some organizations choose to prohibit personal computers for accessing PHI, which simplifies compliance.
Traveling clinicians often use public Wi-Fi, work in facilities with varying networks and carry tablets between sites. Encourage use of a phone hotspot or VPN on public networks, require encrypted devices and make sure documentation tools work offline when connectivity is poor, with data synchronized securely later.
Vendors who support equipment or software should connect through a controlled method, with unique credentials, MFA where available and logging. Whenever possible, enable their access only when they need it, and disable it afterward. Review the list of vendors with standing access at least annually.
Give remote workers a short guide:
Use a password-protected home router with updated firmware
Keep work on work devices, and do not let family members use them
Lock the screen when stepping away
Do not print PHI at home unless approved, and shred anything printed
Report lost equipment immediately
Include remote access in your HIPAA risk analysis and policies. Keep a list of who has remote access and why, and review it each quarter.
UnityCare IT designs and supports secure remote access for healthcare organizations, from VPN configuration to virtual desktops and device management. If you are not certain who can connect to your network from outside the building, we can help find out.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172