Care facilities rely on people who are not in the building every day: medical directors, consultant pharmacists, therapy contractors, wound care specialists, agency nurses and outside accountants. Many need to review charts, sign orders or open documents from home or another office. Remote access is practical and often essential, but it is also one of the most common ways attackers get into healthcare networks.
The goal is not to say no. It is to say yes in a way that is controlled, logged and reversible.
Start with a list. For each outside person or group, record:
Who they are and who sponsors them internally
Which systems they need, and at what level
How long they need access
What device they will use
Whether they work for a business associate with a signed agreement
Many facilities discover that access was granted years ago for a project that ended and was never removed.
If the EHR is cloud-hosted, give clinicians access through the vendor's portal with their own login and multi-factor authentication. That is far safer than opening a path into your entire internal network.
When someone must reach internal systems, use a properly configured VPN or remote access gateway with MFA. Keep the software updated. Unpatched remote access appliances are heavily targeted.
Opening remote desktop services directly to the internet is a well-known risk. If you use remote desktop, place it behind a VPN or gateway with MFA, never directly exposed.
Give each user access only to the systems they need. A consultant who reviews medication records does not need access to your accounting share.
Physicians and consultants are busy and may resist. Offer simple options, such as an authenticator app or hardware key, and a quick enrollment session. Explain that it protects their own accounts and their patients. Make it a requirement in the agreement or onboarding policy.
Personal computers may lack current updates or antivirus, and may be shared with family members. Consider:
Requiring an up-to-date operating system and security software
Using managed virtual desktops or browser-based access so no data stays on the device
Prohibiting local downloads of PHI where practical
Requiring screen lock and disk encryption
Offering a loaner device for high-risk roles
Business associate agreements for outside organizations
An acceptable use agreement for individual users
Clear expectations about not sharing credentials with office staff or family
Rules on printing, saving and emailing PHI from home
Log remote logins and alert on unusual locations or times.
Review the list of external accounts quarterly with the sponsor in each department.
Set expiration dates on contractor accounts when you create them.
Disable accounts immediately when engagements end.
Agency nurses and aides often need EHR access quickly. Create a standard process: the agency submits a request, a supervisor approves it, accounts are created with the minimum role and an end date, and access is removed with the assignment. Never share a generic "agency" login.
Could we list every outside person with access today?
Are all remote logins protected by MFA?
Are remote access systems patched?
Do we know which of those accounts are unused?
Could we shut off remote access in minutes during an incident?
UnityCare IT designs secure remote access for healthcare organizations, including MFA, VPN, vendor access controls and regular access reviews. If you have physicians or contractors connecting from outside the building and are not sure how, we can help you assess it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034