Not every member of your care team works inside the building. Therapists travel between locations, home health nurses chart in clients' homes, medical directors review records from the office, and billing staff sometimes work remotely. Every one of these connections is a path to protected health information, and each outside the walls of your facility is harder to control.
This guide describes practical ways to give mobile staff what they need while protecting the data.
Start by asking what each role actually needs.
A traveling therapist may need the EHR, scheduling and documentation tools.
A medical director might need read access to charts and orders.
A remote biller needs billing software and perhaps shared drives.
An administrator may need email and file access when traveling.
Grant only what each role requires. This principle, often called least privilege, reduces damage if an account is stolen.
If your EHR is cloud-hosted, staff may log in through a secure website. Require multi-factor authentication, enforce strong passwords and review session timeout settings.
A VPN creates an encrypted tunnel between a device and your network. It is common for reaching internal file shares or systems. Use a VPN that supports MFA, keep the VPN software patched and review who has access regularly. VPN appliances are frequent targets, so apply updates promptly.
Staff connect to a desktop running in your environment or the cloud, and data stays there instead of on the personal device. This can be a good fit for remote billing or for staff using personal computers. Never expose remote desktop directly to the internet without protection.
Do not open ports on the firewall for convenience.
Do not let staff forward charts to personal email.
Do not use consumer file sharing for PHI without a business agreement and controls.
Decide which devices may connect.
Facility-owned laptops and tablets offer the most control. Enable full-disk encryption, automatic updates, endpoint protection and the ability to lock or wipe remotely.
Personal devices (BYOD) require a written policy covering minimum security settings, what the facility can manage, and what happens if the device is lost or the employee leaves. Consider limiting personal devices to web-based access with no local storage.
For any device:
Require a screen lock and a PIN or biometric.
Keep the operating system and apps updated.
Encrypt storage.
Install protection software where appropriate.
Ensure it can be remotely wiped if lost.
Staff work in homes, cars, coffee shops and client residences. Give simple guidance:
Avoid public Wi-Fi for PHI unless using a VPN or secure application
Use a privacy screen in public places
Do not leave devices unattended in vehicles
Make sure family members cannot see screens or use work devices
Lock the screen whenever stepping away
Do not print PHI at home unless necessary, and shred it properly
Turn on logging for remote logins. Review alerts for sign-ins from unusual locations or at odd hours, multiple failed attempts or logins from two distant places in a short period. Many email and identity platforms can block risky sign-ins automatically.
When someone leaves or changes roles, remove access the same day.
Maintain a list of every device that holds or can reach PHI.
Make reporting lost devices simple and non-punitive. Staff should know whom to call at any hour.
Test your ability to remotely lock or wipe a device.
A short remote access policy should cover who is eligible, approved methods and devices, security requirements, acceptable locations and consequences. Have employees acknowledge it. Training is important too, as most remote access incidents involve stolen credentials or simple carelessness rather than sophisticated attacks.
[ ] MFA required on every remote path
[ ] VPN and gateway software up to date
[ ] Encryption on all devices that store PHI
[ ] Role-based access limited to what is needed
[ ] Lost device procedure tested
[ ] Access removed promptly at termination
[ ] Remote access reviewed at least quarterly
UnityCare IT sets up and supports secure remote access for healthcare organizations, including VPNs, device management and staff guidance. If your therapists and home health staff are working from personal laptops with no controls, we can help improve that.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172